SignalDesk
Privacy Policy
Effective Sep 26, 2026
This Privacy Policy explains how SignalDesk (“SignalDesk”, “we”, “us”), available at signal-desk.online, collects, uses, stores, and shares information when you use the service. By using SignalDesk, you agree to the practices described here.
Information we collect
Google account information
When you sign in with Google, we receive your name, email address, and profile image, and OAuth tokens that let SignalDesk access Google on your behalf. We request read-only access to Google Search Console (webmasters.readonly) and Google Analytics (analytics.readonly). SignalDesk cannot change anything in your Google accounts.
Search Console and Google Analytics data
For the properties you connect to a project, we import and store reporting data such as daily clicks, impressions, click-through rate, and average position by page and search query (Search Console), and daily sessions, engaged sessions, key events, and revenue by landing page and channel (Google Analytics). We also store the list of properties you choose and their basic settings, such as name, time zone, and currency.
AI provider API keys
If you add an API key for OpenAI, Anthropic, or Google Gemini, we store it encrypted. After you save it, we show only its last few characters.
Analyses
When you run an analysis or ask a question, we store the question, the period and sources analyzed, the compact summary of calculated metrics sent to the AI model, the model's answer, and usage details such as token counts.
Technical information
We keep server logs of events such as sign-ins, data imports, analysis runs, and errors, together with standard request information (for example, time and IP address) recorded by our hosting provider. Logs never contain your Google tokens or API keys.
How we use information
- To sign you in and keep your session secure.
- To import, store, and calculate the analytics shown in your projects.
- To prepare analysis summaries and send them to the AI provider you choose.
- To operate, secure, troubleshoot, and improve the service.
- To contact you about your account or important changes to the service.
We do not sell your information, and we do not use it for advertising.
Google API Services
SignalDesk's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we use Google user data only to provide and improve the user-facing features of SignalDesk; we do not transfer it to others except as needed to provide those features (for example, to the AI provider you select), to comply with law, or as part of a merger or acquisition with your notice; we do not use it for advertising; and we do not allow humans to read it unless you give us permission, it is necessary for security purposes or to comply with law, or it is aggregated and anonymized for internal operations.
How information is shared
- AI providers you choose. When you run an analysis, SignalDesk sends a compact summary of calculated metrics for that project and period (and your question, if you asked one) to the provider you select, using your own API key. The AI model does not access Google or our database directly. The provider handles that data under its own terms and privacy policy.
- Service providers. We use infrastructure providers to host the application and database (for example, Vercel and Neon). They process data on our behalf to run the service.
- Google. We send requests to Google's APIs to sign you in and read the data you authorized.
- Legal reasons. We may disclose information if required by law or to protect the rights, safety, or security of SignalDesk, our users, or others.
Data retention and deletion
- Imported analytics data and saved analyses are kept while the project exists.
- Deleting a project deletes its imported data, sync history, and saved analyses. Switching or disconnecting a property deletes the data imported from it.
- Removing an AI API key in AI settings deletes it immediately.
- You can revoke SignalDesk's access to your Google account at any time at myaccount.google.com/permissions. Imports stop once access is revoked.
- To delete your account and all associated data, contact us at contact@signal-desk.online. Backups and logs are removed on their normal rotation schedule.
Security
Data is encrypted in transit. Google tokens are stored only on the server and are never sent to your browser. AI API keys are encrypted with AES-256-GCM before they are stored. Access to project data is checked against your account on every request. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Cookies and local storage
We use a session cookie to keep you signed in and browser local storage to remember your light or dark theme. We do not use advertising or third-party tracking cookies.
Your choices and rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, or to object to or restrict certain processing. Contact us at contact@signal-desk.online to make a request. We may need to verify your identity before acting on it.
International transfers
Our service providers may process information in countries other than yours. Where required, we rely on appropriate safeguards for such transfers.
Children
SignalDesk is not directed to children under 16, and we do not knowingly collect information from them.
Changes to this policy
We may update this policy from time to time. We will change the effective date above and, for material changes, notify you through the service or by email.
Contact
Questions about this policy or your data: contact@signal-desk.online. See also our Terms of Service.