Privacy policy

Last updated 12 September 2026

This policy explains, in plain language, exactly what QueryWatch reads from your Google account, where it goes, and how to get rid of it. It is short on purpose.

Who we are

QueryWatch is an iPhone app for reading your own Google Search Console data. It is built and operated by Melih Toksari, an independent software developer, who is the data controller for the purposes of the UK and EU GDPR. You can reach a human at[email protected].

QueryWatch is an independent app. It is not affiliated with, endorsed by, or sponsored by Google LLC.

The short version

  • The app talks to Google directly from your iPhone. Your Search Console data is requested by the app, shown to you, and cached on the device. In the default configuration it never passes through a server we run.
  • Your Google refresh token stays in the iPhone Keychain unless you turn on push alerts. Push alerts have to be computed while your phone is asleep, so enabling them — and only enabling them — copies that token to our alert relay. This is explained in the app before you switch it on, and it is reversible in one tap.
  • We never sell your data, never use it for advertising, and never use it to train any AI or machine-learning model.
  • You can delete everything yourself, from inside the app or fromthe public deletion page, without emailing anyone.

What Google user data the app accesses

When you sign in with Google, QueryWatch asks for the read-only Search Console scope (https://www.googleapis.com/auth/webmasters.readonly). Sign-in happens in a system browser sheet using OAuth 2.0 with PKCE — never in an embedded web view — so your Google password is typed into Google's own page and is never visible to the app.

With that permission the app reads four things, and nothing else:

DataGoogle APIWhat it is used for
Your list of verified properties, including your permission level on eachsites.listShowing the property list and letting you group, tag, favourite and hide properties
Search performance data — clicks, impressions, CTR and average position, broken down by date, query, page, country and devicesearchanalytics.queryEvery chart, table, delta, widget, striking-distance view, change investigation and export in the app
URL inspection results — index status, coverage state, crawl and canonical informationurlInspection.index.inspectThe URL inspection screen and, for Pro users, watched-URL indexing alerts
Sitemap listings — paths, submission dates, error and warning countssitemaps.listThe sitemaps screen and, for Pro users, sitemap error alerts

The app does not read your email, your contacts, your Drive, your Analytics, your Ads account, or anything else in your Google account. It cannot: the token it holds only opens Search Console.

The one write permission, and when it is asked for

Submitting or deleting a sitemap needs the full https://www.googleapis.com/auth/webmastersscope. QueryWatch does not request it at sign-in. It is asked for incrementally, the first time a Pro subscriber actually taps “Submit sitemap”, and if you never use that feature it is never requested. The app performs no other write of any kind to your Search Console account.

Where your data is stored

On your iPhone — always

  • Your Google refresh token is stored in the iOS Keychain with thekSecAttrAccessibleAfterFirstUnlock protection class and iCloud Keychain sync switched off, so it does not leave the device through a backup or another of your devices. The short-lived access token is held in memory only and is never written to disk.
  • A local cache (SQLite) of the Search Console responses you have already looked at, so the app opens instantly and works offline. Entries expire after six hours and are refreshed in the background.
  • Things you create in the app — client tags and colours, favourites, hidden properties, watchlist saves, alert rules, saved change investigations — which live only on the device unless alerts are on.
  • A small shared store for widgets, holding the handful of numbers a home-screen or Lock Screen widget needs to draw itself.

Deleting the app from your iPhone deletes all of the above. If you have push alerts on, see the next section — the relay row is separate and should be deleted too.

On our alert relay — only if you turn on push alerts

This is the one case where your Google refresh token leaves your device. Push alerts exist to reach you when the app is closed, which means something has to check Search Console on a schedule while your phone is asleep. That cannot be done on the device, so it is done on a server.

Push alerts are a Pro feature, they are off by default, and enabling them shows a consent screen that says exactly what follows before anything is sent. When you enable them, QueryWatch stores one row for you on our relay. The relay is our own server, in Germany — a virtual machine we rent from Hetzner and administer ourselves. It is not a third-party backend service: the software and the database are ours, no vendor account has access to them, and your data is processed inside the EU.

  • Your Google refresh token, encrypted with libsodium before it is written. The encryption key is held in a file on the server and never in the database, so a copy of the database on its own cannot be decrypted. The token is decrypted in memory only, for the moment a scheduled check runs.
  • Your device's push token and platform, so a notification can be delivered.
  • An anonymous subscriber id from RevenueCat, used to check that your Pro subscription is still active. It is not your email address and not your Google account id.
  • Your alert rules, watchlist entries and watched URLs, because those are what the scheduled check evaluates.
  • Alert events — the evidence snapshot behind each alert that fired: the metric, the observed value, the baseline it was compared against, the dates, the threshold that was hit, and the top contributing pages or queries at that moment. This is what makes an alert still make sense a week later.

The relay reads the last seven complete days of performance data for your properties every six hours, compares them against your rules, and sends a notification through Apple's APNs (or Google's FCM on Android) when a rule fires. Row-level security means a row can only ever be read or deleted by the account that created it. No human at QueryWatch reads your Search Console data; the only case where that could ever happen is if you send us a screenshot or a file yourself to get support.

Turn alerts off and the row and every side table are deleted immediately — not flagged, not soft-deleted, not queued. If your Pro subscription lapses, the relay stops processing you at once and the row is deleted after 30 days.

Other data the app handles

Product analytics

QueryWatch records anonymous usage events through Google Analytics 4, using the Firebase Analytics SDK — which screen was opened, whether sign-in succeeded, whether an alert was opened, which paywall was shown. These events carry no personal information: property identifiers are salted SHA-256 hashes, and no site URL, email address, query, page or name is ever included. Ad personalisation and Google Signals are switched off, no advertising identifier is requested, and there are no advertising SDKs in the app — so there is no App Tracking Transparency prompt, because there is nothing to track you with. Signing out or deleting your data resets the analytics identifier, which starts you over as a new, unconnected install.

Be aware of what this means: these analytics events go to Google, and Google processes them on its own infrastructure, which is not limited to the EEA. That is separate from your Search Console data and separate from the alert relay, neither of which passes through Google Analytics. If you would rather send nothing at all, you can use the app without signing in, in Demo Mode.

Subscriptions

Purchases are handled by Apple and mediated by RevenueCat, which tells the app whether your Pro entitlement is active. Neither QueryWatch nor RevenueCat ever sees your card details — Apple handles payment and shares only the subscription status.

Crash and diagnostic information

When the app crashes, Firebase Crashlytics sends us a report so the bug can be found and fixed. A report contains the stack trace, your device model, OS version and the app version, plus a small amount of context we attach deliberately: which screen you were on, whether you were on the free or Pro tier, whether Demo Mode was on, and how many properties you have. It never contains a site URL, a query, a page, your email address or your Google token.

You can turn this off. Settings → Privacy & data → Send crash reports; it is on by default, and switching it off also discards anything queued but not yet sent. Crashlytics is a Google service, so like the product analytics above, these reports are processed by Google outside the EEA — separately from your Search Console data and from the alert relay.

Separately, if you have opted in to sharing analytics with app developers in your iOS settings, Apple may also send us aggregate crash reports. That is Apple's own mechanism, controlled from your device's Privacy settings, and it contains no Search Console data.

This website

querywatch.app is a set of static pages on Cloudflare Pages. It sets no cookies, runs no tracking pixels, embeds no chat widget, and shows no cookie banner because it has nothing to ask you about. Aggregate, cookie-free page-view counts may be collected through Cloudflare Web Analytics, which does not fingerprint visitors or build a profile across sites. If you email us or join the waitlist, we hold your email address for that purpose and nothing else.

Who your data is shared with

We do not sell your data, rent it, trade it, or share it for advertising. The complete list of companies that touch any of it, and the only reason each one does:

ServiceWhat it receivesWhen
Google (Search Console API)Your requests for your own dataWhenever the app or the relay fetches data
Hetzner Online GmbH — hosting onlyNothing is shared with Hetzner for their own purposes. They rent us the machine in Germany on which our relay runs, so the encrypted data described above physically sits there.Only while push alerts are switched on
Apple (APNs) / Google (FCM)The notification text and your device's push tokenOnly when an alert fires
RevenueCatAn anonymous subscriber id and your subscription statusWhen you purchase, restore, or the app checks entitlement
Google (Analytics 4 / Firebase)Anonymous product events with hashed property identifiers, and an app-instance id that is not linked to your identity. Processed by Google outside the EEA.While you use the app
Google (Firebase Crashlytics)A crash report: stack trace, device model, OS and app version, and the limited context described above. No site URL, query, page, email or token. Processed by Google outside the EEA.Only when the app crashes, and only while crash reporting is switched on
CloudflareStandard web request data for this websiteWhen you visit querywatch.app

We may also disclose data if we are legally required to, or to investigate abuse of the service — but we have no mechanism for browsing your Search Console data and no intention of building one.

Google API Services Limited Use commitment

QueryWatch's use and transfer of information received from Google APIs to any other app will adhere to theGoogle API Services User Data Policy, including theLimited Use requirements.

Concretely, that means we commit that data obtained through Google APIs is:

  • used only to provide or improve the features you can see in QueryWatch;
  • never transferred to anyone except as needed to run those features (the list above), to comply with the law, or as part of a merger or acquisition — and in that last case only with notice and your consent;
  • never used for serving advertising of any kind, including retargeting or personalised advertising;
  • never used to develop, improve or train generalised or non-personalised artificial intelligence or machine-learning models;
  • never read by a human, except with your explicit permission for a specific support request, where it is necessary for security purposes such as investigating abuse, or where the law requires it.

How long we keep things

  • Cached Search Console data on your device: six hours, then refreshed. Cleared completely when you sign out or delete the app.
  • Your relay row, if alerts are on: for as long as alerts stay on. Deleted immediately when you turn them off, and automatically 30 days after a Pro subscription lapses.
  • Alert events: kept with your relay row so your alert history stays readable, and deleted with it.
  • Anonymous analytics events: retained in aggregate. They contain nothing that identifies you or your sites.
  • Support emails: kept while the conversation is useful, then deleted.

Where your data is processed

With push alerts off — the default — nothing of yours is processed anywhere but on your own phone. The app talks to Google directly and we hold no row about you.

With push alerts on, the single row described above is processed on our relay server inGermany. That machine is rented from Hetzner and administered by us; it is not a managed backend product, and no vendor account can read it. For users and visitors in the EU, the EEA and the UK this means your data stays inside the EEA. Melih Toksari, who administers the server, is resident in Türkiye and accesses it from there.

Your rights, and how to actually use them

Under the UK and EU GDPR you have the right to access, correct, export, restrict and delete your personal data, and to object to processing. Most of these you can exercise yourself, immediately, without asking us:

  • Access and export: the data is your own Search Console data, and the app exports any view you are looking at as CSV. Google's own export is always available too.
  • Withdraw consent: revoke QueryWatch's access from yourGoogle account permissions pageat any time. The app's access stops the moment you do.
  • Delete: follow the deletion instructions. They work without an account, without logging in, and without contacting us.

If you would rather have a person handle it, email[email protected] and we will action it within 30 days. You also have the right to complain to your local data protection authority.

If you are in California, we do not sell or share personal information as the CCPA/CPRA defines those terms, and we do not offer financial incentives for data. The rights above apply to you too.

Children

QueryWatch is a professional tool for people who run websites. It is not directed at children under 13 and we do not knowingly collect their data.

Changes to this policy

If this policy changes in a way that affects what we do with your data, we will update the date at the top of this page and, for anything material, say so in the app before the change takes effect. The relevant version is always the one published here.

Contact

Questions about any of this, or about a specific request, go to[email protected]. A person reads it.