Privacy Policy

Last updated: September 25, 2026

CrawlRaven (“we”, “us”) is an SEO analytics product that helps you understand your websites’ search performance. This policy explains what data we collect, why, and what control you have over it. The short version: we only read the data you connect, we show it only to you and your account members, and we never sell it or use it for advertising.

Information you provide

When you sign in with Google we receive your name, email address, and profile picture to create your account. New plan purchases are processed by Creem. Dodo Payments remains available for historical receipts. We receive your email address and the product purchased, never your card details.

Google user data we access

With your consent, CrawlRaven accesses the following Google data, read-only, on your behalf:

  • Google Search Console (scope: webmasters.readonly): your property list and search analytics (queries, pages, clicks, impressions, positions, countries, devices) for the properties your Google account can access.
  • Google Analytics 4 (scope: analytics.readonly): the Analytics accounts and GA4 properties your Google account can access, property details for the property you link, and live aggregate reports such as active users, sessions, key events, event counts, landing pages, source/medium, countries, devices, and content groups. CrawlRaven does not persist GA4 report rows.

We use this data solely to provide CrawlRaven features to you: dashboards, trends, keyword tracking, SEO opportunity detection, traffic-outcome reporting, and the bounded reports you explicitly request through an authorized MCP client. We never modify anything in your Google account, and we never access Google data of anyone who has not connected their own account.

Limited Use disclosure

CrawlRaven’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, and do not allow humans to read it except with your explicit permission for support, for security purposes, or to comply with law. We do not use Google user data to train machine learning or artificial intelligence models.

How we store and protect data

Search Console reports are requested from Google when needed and may be temporarily cached on Cloudflare to load reports faster and avoid repeated requests to Google. We store compact website performance totals and product data such as targets, annotations, opportunities, and your actions in our PostgreSQL database, hosted on Hetzner and reached through Cloudflare Hyperdrive. Current reporting does not use a permanently stored query-by-page performance history. GA4 reports are requested directly from Google when the dashboard or an authorized MCP tool needs them, and GA4 report rows are not permanently stored. For a GA4 connection, we retain the selected property ID and name, the authorized Google account email, granted scopes, and an encrypted OAuth refresh token. Google OAuth refresh tokens are encrypted at rest with AES-256-GCM; access tokens are short-lived and never stored. All traffic is encrypted in transit with TLS. Access to production systems is restricted to the operators of CrawlRaven.

Sharing

We share data only with the infrastructure providers needed to run the service (Cloudflare and Hetzner for hosting, Creem for new payments and affiliate attribution, Dodo Payments for historical billing records, and DataFast for revenue attribution), each acting under their own security commitments. We do not sell personal data or Google user data to anyone, and we do not share it with advertisers or data brokers. DataFast receives signed-out marketing attribution events and payment metadata; it does not receive authenticated product activity or the Google user data connected to your account.

When you authorize an MCP client and ask it to use a tool, CrawlRaven sends the approved result to that client. The client and its model provider process the result under their own policies. Connect only clients you trust with the Search Console, linked GA4, and CrawlRaven planning data covered by the scopes you approve. We do not send this account data to a client without an authorized tool request.

Retention and deletion

Temporarily cached Search Console reports expire automatically. We retain compact website performance totals and saved product data, including targets, annotations, opportunities, and your actions, while your CrawlRaven account remains active. We retain GA4 connection information while your account remains active or until the connection is deleted or replaced. MCP grants and refresh credentials expire after 90 days and can be revoked sooner from MCP connections.

If you explicitly authorize an MCP client to Manage annotations, it may submit a proposed manual note change. Planning does not change data. CrawlRaven holds the proposal for a short approval window and applies it only after the same authorizing user reviews and approves it in CrawlRaven. We retain content-free audit metadata about the client, action, affected resource versions, and outcome for security and accountability; short-lived approval credentials and proposal content are removed on the documented expiry schedule. MCP can archive and restore manual notes but cannot permanently delete them.

You can disconnect Google access at any time from your Google Account permissions, which immediately prevents further data access. To delete your account and its associated data, email us and we will complete the deletion within 30 days, except where retention is required by law.

Cookies

We use session cookies required to keep you signed in and first-party preference cookies for interface choices. Short-lived HttpOnly cookies protect manual annotation approval sessions and are not exposed to the MCP client. On signed-out pages, DataFast uses a first-party visitor cookie to connect a marketing source with a later checkout and payment. We do not use DataFast to track authenticated product activity. We do not use these cookies for personalized advertising or sell the information they contain.

When you arrive through an affiliate link, we store Creem's signed referral token in a first-party cookie named cr_creem_ref. This cookie is used for affiliate attribution, not authentication. It is shared across crawlraven.com and app.crawlraven.com so it can survive signup and login. At checkout, we include the token in the Creem checkout URL so Creem can determine whether a referring partner should receive commission. This does not send your connected Search Console or Google Analytics data to Creem.

The affiliate cookie lasts for up to 90 days from capture. Ordinary visits do not extend that period; a new referral may replace it and start a new period. In production it is Secure and HttpOnly, so it is sent over HTTPS and unavailable to page JavaScript. You can remove it using your browser's site-data settings. Clearing all site data may also sign you out. Removing this cookie prevents us from forwarding that stored referral on future checkouts; it does not undo attribution Creem has already recorded. Creem decides attribution under its program settings; our cookie lifetime does not guarantee commission eligibility.

Changes and contact

If this policy changes materially we will note it here with a new date. Questions or deletion requests: hello@crawlraven.com.