Is my data safe? Yes — and here's why.
Connecting Google Search Console to a tool you just found is a fair thing to be cautious about. So we built TrustSERP to ask for the least access possible, and to make everything reversible. No fine print below — this is the whole story.
Can you change or break my site?
No — and not by policy, by permission. The only scope we request is webmasters.readonly. Google physically does not grant us the ability to edit settings, submit or remove sitemaps, request indexing, or change a single thing in your Search Console. We can read the numbers. That's the entire surface area.
Can you see or sell my keywords?
What we keep are aggregate totals — total clicks, impressions, and how many keywords rank in the top 3 / 10 / 100. To count those rankings we do read the keyword list from Google, but the query strings are discarded the instant they're counted — never written to our database, never displayed, never sold. Only the count survives. We don't run third-party ads or share your numbers with anyone outside the infrastructure that runs the service.
Who are you, and how do I get out?
TrustSERP is a verification layer for SEO — you connect your own data, we prove it's real, and in return you get a public proof page and a high-authority backlink. Everything is reversible: disconnect Search Console or delete your account and all data in one click, anytime, from settings. You can also revoke access directly from your Google account permissions.
How it's protected
Refresh token encrypted at rest
The Google refresh token — the one credential that keeps your connection alive — is sealed with AES-256-GCM before it ever touches our database. Only the ciphertext is stored; the plaintext is never persisted. The encryption key lives outside the database in a separate secret, so even an attacker holding a full copy of the database gets unreadable bytes. GCM is authenticated, so any tampering with the stored value is detected and rejected on read.
Encrypted in transit
Every request runs over TLS. Data moves between you, Google, and TrustSERP encrypted end to end.
Keywords are never stored
When we pull from Search Console, the keyword strings come back, get counted, and are dropped in the same breath — never written to a row, a log, or a cache. We keep only rolled-up totals and trends. There is no keyword database to leak, subpoena, or sell, because one never exists.
Yours to revoke
Disconnect or delete at any time. Deletion removes your tokens and your data from our systems. No retention games.
Read-only by scope
We request the read-only Search Console scope and nothing more. Google itself enforces it — we physically cannot edit settings, submit sitemaps, or change anything on your property, even if we wanted to.
No third-party sharing
Your data is never sold, rented, or handed to advertisers or data brokers. The only parties that ever touch it are Google (the source) and the infrastructure we run on — listed in full in the Privacy Policy.
Want the full legal detail — every data type, every sub-processor, your GDPR/CCPA rights? It's all in the Privacy Policy.
Connect with confidence
Read-only. Reversible. Your keywords never leave Google. Get your verified record in under two minutes.
Connect Search Console →