Privacy & transparency
Privacy policy
Your Google data is used to provide the traffic analysis and reporting you request.
Effective date: 4 October 2026 · 中文说明
1. Who operates the service
hyperseo is operated by hyper.hu, an individual developer. HyperAtlas is its analysis module. HyperDataService (HDS), available at gs.kieapi.com, provides Google authorization and read-only data access. For privacy, support or deletion requests, contact huliqiong1124@gmail.com.
2. What we access
With your consent, HDS requests analytics.readonly for Google Analytics 4 or webmasters.readonly for Google Search Console. These are separate authorizations. They do not grant write or user-management access.
- Resource information: accessible GA account/property IDs and names; GSC site identifiers and your access level. Resource discovery can include multiple properties accessible to the consenting Google account, not just the website currently being analyzed.
- GA4 traffic reports: aggregate users, sessions, page views and engagement, grouped by allowed traffic dimensions such as source/medium, channel, landing page, country, device and date.
- GSC search reports: queries, pages, dates, countries, devices and search appearance, with clicks, impressions, click-through rate and average position.
- Connection and operation records: organization and connection identifiers, authorization scopes, connection status, timestamps and security/audit events needed to operate the service.
- Authorization credentials: Google-issued access and refresh tokens needed for authorized requests. We do not request your Google password.
The GA4 API uses a closed allowlist for metrics, dimensions and filters. It does not offer conversions, revenue, purchases, age, gender, interests, transaction IDs or custom fields. It also excludes full page URLs and GA4 page/landing-page query-string fields. Website paths, page titles and search queries may themselves contain sensitive text supplied by a site; do not place personal data or secrets in them. These reports are not guaranteed to be anonymous.
3. How the data is used
We use authorized data to discover resources, return requested reports and analyze traffic composition in HyperAtlas. HDS performs Google API calls on our servers. Our internal traffic-analysis processing is carried out on our own servers; we do not send Google report data to an external AI model provider for that internal analysis.
Google user data is not used to train or improve generalized AI/ML models, for advertising targeting, for sale, or for purposes unrelated to the user-facing traffic features described here. Human access is limited to your consented support requests and cases permitted by Google's Limited Use requirements, such as security investigations or legal obligations.
4. API access and recipients
Google receives the API requests needed to deliver the service. When you use an API or MCP integration, report results are returned to the authenticated caller within the authorized organization and access scope. Google access and refresh tokens are not returned to API callers.
An integration or client you choose can process and store the results it receives under its own terms. In particular, choosing an external AI client to consume an API/MCP response is different from our internal server-side analysis. Review that client's privacy settings before connecting it. We do not make retention or onward-sharing guarantees for independently controlled client copies.
5. Storage, protection and retention
- Google refresh tokens are encrypted at rest on the server. Access tokens are held temporarily for API calls. HTTPS protects network transport, and API authentication and organization checks restrict access.
- HDS report responses are cached for up to 300 seconds. Disconnecting locally blocks further report access for that connection even if a cache entry has not yet expired. Google-side revocation may not be detected until a cached response expires or a fresh request is made.
- Connection/resource metadata and audit records are retained for service operation and troubleshooting. They currently have no automatic time-based purge; disconnecting alone does not delete these records.
- Saved HyperAtlas reports and evidence are separate from HDS's short-lived cache and can remain available until deletion is requested. There is no service-wide automatic deletion deadline for these historical records.
- Backups are separate from the live database. Disconnecting does not erase backup copies. A deletion request must cover retained records and backups explicitly; we will explain the applicable scope and handling rather than promise immediate deletion of every copy.
These public pages do not use analytics cookies, third-party tracking scripts or external fonts. Our authorization/API service processes requests and security records as described above.
6. Your choices and deletion
You can stop future access by disconnecting through your authorized integration or removing the app's access in your Google account. You can request deletion of stored connection data, reports and evidence by email. We verify your authority over the requested organization/resources before deleting data. Do not send passwords, API keys or Google tokens. See the disconnect and data deletion instructions for the distinction between stopping access and deleting retained records.
7. Google API Limited Use
hyperseo's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. This policy is a data-handling commitment, not a statement that Google has verified or endorsed the application.
8. Changes and contact
We will publish changes here with an updated effective date. A change to data uses or access that requires new consent will not be treated as covered by an old authorization. Contact huliqiong1124@gmail.com with privacy questions.
中文说明
hyperseo 由 hyper.hu(个人开发者)运营,HyperAtlas 为分析模块,HDS 为 Google 授权和只读取数后端。联系邮箱:huliqiong1124@gmail.com。
用户分别授权 GA4/GSC 后,服务会发现并保存该 Google 账号可访问的资源标识,再按请求查询流量组成和搜索表现。GA4 指标、维度及筛选条件受白名单限制,不开放转化、收入、购买、年龄、性别、兴趣、交易编号或自定义字段;Google 的只读权限本身比这些应用字段限制更宽。网页路径、标题、搜索词仍可能包含站点提供的敏感文本,不能把报表一概视为匿名数据。
内部流量分析仅在自有服务器进行,不向外部 AI 模型服务商发送报表用于内部分析。Google 用户数据不用于训练或改进通用 AI/ML 模型、广告定向、出售或与这里列出的流量功能无关的用途。用户主动使用 API/MCP 时,结果会返回给有权限的调用方;用户自行选择的客户端可能进一步处理和保存这些结果,其规则需单独查看。Google Token 不返回给调用方。
刷新凭证在服务端加密保存;HDS 查询缓存最长 300 秒。连接元数据、审计及已保存的 HyperAtlas 报告和证据没有统一的自动清除时限。断开会停止对应连接的取数、删除本地凭证并停用绑定,但不会自动删除所有历史记录或备份。请通过邮箱提交并核验删除请求;我们会说明处理范围及完成情况,不承诺断开即清除所有副本。详情见数据删除说明。
本页不使用追踪脚本、分析 Cookie 或外部字体。Google API 数据使用和传输遵循上述 Google 用户数据政策及 Limited Use 要求;此声明不等于已通过 Google 审核。