Policy
Privacy Policy
This policy explains how the private Game Sites Analytics utility accesses, uses, stores, and protects Google user data.
1. What this utility is
Game Sites Analytics is a private, internally used analytics utility operated by an individual for websites that individual manages. It is not a public SaaS product and does not offer public user accounts.
2. Google data accessed
The utility requests only these Google OAuth scopes:
https://www.googleapis.com/auth/analytics.readonly— used to read Google Analytics 4 analytics, reporting, and configuration-related data made available by the relevant read-only APIs for accounts and properties the authorizing user can access.https://www.googleapis.com/auth/webmasters.readonly— used to read Google Search Console data for verified sites and properties the authorizing user can access.
These permissions do not provide access to Gmail, Google Drive files, or the entire Google Account.
3. Purpose and read-only use
Google data is used for private site analytics, historical comparison, reporting, release monitoring, and operational review. The utility uses read-only permissions and does not modify Google Search Console or Google Analytics data or settings.
4. Processing and storage
The current Runner retrieves authorized data from Google APIs and processes it locally on an operator-controlled Windows computer. It creates local raw API snapshots, derived reports, event snapshots, weekly snapshots, and diagnostic records.
The current automated Runner has no code path or dependency that sends raw Google Analytics or Search Console data to a third-party AI or model API. If that architecture changes, this policy will be updated before the changed processing is used.
5. OAuth credentials
OAuth client credentials are stored outside source-code repositories. The OAuth token is stored locally on the operator-controlled Windows computer. Credential contents are not committed to Git, included in generated reports, or intentionally shared with third parties.
We do not claim that local credential files are encrypted at rest.
6. Sharing, sale, and advertising
Google user data is not sold, used for advertising, publicly disclosed, or shared for unrelated purposes. The current Runner retrieves authorized data from Google APIs and processes it locally. It also retrieves public publisher or store pages to verify release information; those requests do not transmit Google analytics datasets to those pages.
This public website contains no Google Analytics, Google Tag Manager, advertising code, tracking pixels, cookies set by the site code, or other third-party front-end scripts. Vercel will host the site and may process standard request metadata and operational logs under its own terms. Optional Vercel Analytics is disabled.
7. Retention and deletion
OAuth credentials, raw snapshots, derived reports, event snapshots, weekly snapshots, and diagnostics are retained only as long as necessary for private site analytics, security, troubleshooting, and historical comparison. Retention may differ by record type and operational purpose.
The operator may stop collection and remove local credentials or analytics records when they are no longer needed, subject to preserving records needed for security, integrity, or audit review. This policy does not promise a fixed automatic deletion schedule that the current Runner does not enforce.
8. Security
Reasonable safeguards include keeping credentials outside source repositories, excluding credential values from reports, limiting access to the operator-controlled computer and account, using HTTPS for Google API requests, and scanning project outputs for credential-shaped values. No method of storage or transmission can be guaranteed to be completely secure.
9. User control and revocation
The authorizing user can stop using the utility, remove the local OAuth token, and revoke the app's Google Account access through Google's third-party connections page. Revoking access stops future API access but does not automatically delete local records already created by the utility.
Requests concerning local records can be sent to the contact address below.
10. Google API Services User Data Policy
Game Sites Analytics' use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide or improve the functionality described in this policy.
11. Changes to this policy
This policy may be updated when the utility's data access, processing, storage, hosting, or legal obligations change. The effective and last-updated dates will be revised before materially changed processing is used.
12. Contact
Privacy questions or local-record requests: privacy@gamesitesanalytics.xyz.