WebsiteMasterebsiteMasterWebsiteMaster
  • Product
  • How it works
  • Demo
  • FAQ
WebsiteMasterebsiteMasterWebsiteMaster

One clear view of search, traffic, and the next SEO action.

Product
  • Features
  • How it works
  • Dashboard
Resources
  • Try demo
  • FAQ
Legal
  • Cookie policy & settings
  • Privacy Policy
  • Terms of Service
  • Data & Permissions
  • Data Deletion
© 2026 WebsiteMaster. All Rights Reserved.

Data & Permissions

What WebsiteMaster reads, what it cannot do, and how authorization works

2026/07/24

Why authorization is required

WebsiteMaster can only build a report from data you authorize us to read. Product login creates your WebsiteMaster account; Google and Bing authorization are separate, optional data connections.

You may connect at least one source. Google authorization requests read-only Search Console and Google Analytics permissions together. Bing Webmaster authorization is a separate read-only connection.

The Google connection requests exactly these two scopes:

  • https://www.googleapis.com/auth/webmasters.readonly
  • https://www.googleapis.com/auth/analytics.readonly

Data we read

  • Google Search Console: search clicks, impressions, CTR, average position, queries, pages, countries and devices.
  • Google Analytics 4: active users, views, sessions, engagement, key events, channels and landing pages for the selected website.
  • Bing Webmaster: search clicks, impressions, CTR, Bing average position, queries and pages.

We use the data only to discover resources you can access, match resources you confirm, and display or export cached reports for selected websites. We do not use provider reporting data for advertising or generalized model training.

What we cannot access or do

We do not request permission to publish content, edit your website, submit indexing requests, modify Analytics configuration, manage ads, access payment data or read email content. WebsiteMaster never changes your Google or Bing account.

Storage and control

OAuth credentials are encrypted on the server. The browser receives only a session cookie, not provider access tokens. Reports are cached rather than real-time; each source shows its coverage and last successful sync.

You choose which discovered resources become WebsiteMaster sites. You can disconnect a source at any time. Disconnecting removes local credentials and cached reports for that source; Bing authorization should also be removed from Bing Webmaster Tools because Bing does not document a remote revocation API.

See our Privacy Policy, Cookie Policy, and Data Deletion for details.