What we process
- Account details: your email and a sign-in identity, handled by WorkOS.
- Google connection: your Google account identifier and email, the read-only Search Console permission you approved, and encrypted access credentials needed to keep the connection working.
- Property list: the Search Console properties your Google account can read and the local show/hide preference you set.
- Search performance data you ask your assistant for. It is fetched from Google when requested and returned to the assistant you chose (for example ChatGPT, Codex or Claude). We keep it only in a short-lived cache (15 minutes) to avoid repeat calls, and we do not keep a performance archive.
- Billing: subscription status and identifiers. Payment details are handled by Polar and never reach QuerySail.
- Operational logs: request ID, tool name, outcome, latency and error category, kept for about 30 days. We do not routinely store raw search queries from your data in logs.
- Usage counters per account to enforce fair-use limits.
- Cookies and hosting logs: when you sign in, the site sets a session cookie that keeps you signed in. We use no analytics or advertising cookies and load nothing from third-party trackers. Our hosting provider (Vercel) records request details such as IP address and user agent in its own infrastructure logs.
What we do not do
- We do not collect your assistant conversations or transcripts.
- We do not use your Google data to train models, and QuerySail does not call a model with your data.
- We do not sell your data or use it for advertising.
- We never write to your Google account. QuerySail requests read-only Search Console access.
QuerySail's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Who else handles data
We use WorkOS (sign-in), Google (Search Console data), Polar (payments), Vercel (website hosting) and Convex (database and backend). Data you ask for is returned to the assistant host you connect, which has its own privacy terms.
Your controls
- Disconnect Google in Account → Connections. Stored credentials are deleted immediately and we ask Google to revoke the token. Cached data for that connection is purged, and a report that was still being fetched when you disconnected is not stored.
- Revoke plugin access in Account → Settings. This stops the assistant from reading your data without touching your Google connection.
- Hide a property from the assistant in Account → Connections.
- Export your account metadata in Account → Settings.
- Delete your account in Account → Settings. Access stops immediately. Your Google credentials are deleted and we ask Google to revoke the token, your connections and other account data are removed promptly and in any case within seven days, your sign-in is deleted from WorkOS, and active subscriptions are cancelled. If WorkOS or our payment provider is unreachable, we keep only your account ID and subscription ID, plus your sign-in ID until WorkOS confirms its deletion (and the deletion record described under Retention), and keep retrying until those steps succeed.
Retention
- Short-lived cache: 15 minutes. Expired entries are never served and are removed by a cleanup that runs every 15 minutes.
- Operational logs: about 30 days.
- Usage counters: about 3 days.
- After deletion: backups roll off on the hosting providers' backup schedules. Billing records are retained by Polar where the law requires.
- To stop repeated free trials we keep one-way hashes of the email address (ignoring any +tag) and the Google account that used a trial, together with the date and an opaque identifier of the account that used it, without any other account data.
- Deletion records: an opaque account ID and the status of each cleanup step, for about 30 days after the deletion finishes.
- From the moment you delete your account until 24 hours after cleanup finishes, we keep a one-way hash of your sign-in ID, so a session that was already open cannot quietly recreate the account.
Detection of Google permission changes
If you remove a property's access or revoke QuerySail in your Google account, QuerySail notices within about 15 minutes at most and stops serving that data, including from cache.
Contact
Questions or requests: support@querysail.com.