Privacy Policy
Last updated: September 24, 2026
Badass Console is a web app that analyzes your Google Search Console data. This policy explains what data we access, why, how long we keep it, and how you can remove it.
Who we are
The service is operated by RAWWWR Marek Foltański, ul. Inżynierska 49/21, 53-228 Wrocław, Poland, tax ID (NIP) 9730861104, REGON 382333688("we", "us"). We are the data controller for the personal data described below. You can reach us at contact@badassconsole.com.
Data we access from Google
When you sign in with Google, we ask for the following permissions:
- Basic profile (openid, email, profile). Your name, email address and profile picture, used to create your account and identify you when you sign in.
- Search Console, read-only (webmasters.readonly). The list of Search Console properties you have access to and their search performance data (queries, pages, clicks, impressions, CTR, position), URL inspection results and sitemaps.
Access to Search Console is read-only. We cannot change settings, submit sitemaps, remove URLs or modify anything in your Search Console account. You can decline the Search Console permission on the Google consent screen; you can still sign in, but the analysis modules will not have data to show.
How we use Google data
We use data received from Google APIs only to provide the features you use in the app:
- Showing your Search Console performance data in dashboards, tables and charts.
- Grouping queries and pages into the segments you define.
- Showing daily positions for the keywords you choose to track.
- Detecting queries where more than one of your pages ranks (cannibalization), and pages that grow or decay.
- Creating client reports when you explicitly generate one.
We do not use Google user data for advertising, we do not sell it, and we do not use it to build profiles or to train artificial intelligence or machine learning models.
Google API Services: Limited Use
Badass Console's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular:
- We use Google user data only to provide and improve user-facing features that are visible in the app.
- We do not transfer Google user data to third parties, except as needed to run the service (see Service providers), to comply with the law, or as part of a merger or acquisition with notice to you.
- We do not use or transfer Google user data for serving ads, including retargeting or personalized ads.
- We do not allow humans to read Google user data, unless you give us permission for specific messages (for example when you ask for support), it is necessary for security purposes such as investigating abuse, or it is required by law.
What we store and for how long
- Account data: your name, email address, profile picture URL and the date you signed up. Kept until you delete your account.
- Google OAuth tokens: the access and refresh tokens Google issues when you grant access, and the list of granted permissions. Used only to request your Search Console data on your behalf. Deleted when you revoke access or delete your account.
- Your app settings: the Search Console properties you import as projects, your segment rules, tracked keywords and tags. Kept until you delete them or your account.
- Search Console data (cache): performance data is fetched live from the Search Console API and cached temporarily to keep the app fast, for up to 4 hours. We do not keep a permanent copy of your Search Console data.
- Client reports: when you create a report, a snapshot of the numbers it shows is stored so the report link keeps showing what you shared. Kept until you delete the report, the project or your account.
- Session data: a session record in our database and a session cookie in your browser, needed to keep you signed in. Deleted when you sign out or the session expires.
Data is encrypted in transit (HTTPS/TLS) and stored with providers that encrypt it at rest. Access to production systems is limited to the operator.
Revoking access and deleting your data
- Revoke Google access:in the app, go to Settings and use "Revoke access". We revoke the tokens with Google and sign you out. You can also remove access at any time in your Google Account permissions.
- Delete your account:in Settings, use "Delete account". We revoke Google access and permanently delete your account together with all projects, segments, tracked keywords and reports. Cached Search Console data expires within 4 hours.
- You can also ask us to delete your data by writing to contact@badassconsole.com.
Your rights
We process your data to provide the service you signed up for (performance of a contract, Art. 6(1)(b) GDPR) and to keep it secure (our legitimate interest, Art. 6(1)(f) GDPR). You have the right to access, correct, delete and export your data, to restrict or object to processing, and to lodge a complaint with a supervisory authority (in Poland: the President of the Personal Data Protection Office, UODO). To exercise your rights, contact us at contact@badassconsole.com.
Children
The service is intended for professionals and is not directed at children under 16.
Changes to this policy
If we change this policy, we will update the date at the top of this page. If the changes affect how we use Google user data, we will notify you and ask for your consent where required. See also our Terms of Service.