glimana is an SEO analytics tool. For the sites you add to it, it collects data from Google Search Console, Google Analytics 4, and its own crawler. This page explains what that data is, why we process it, and how long we keep it. If you live in Türkiye, also read the KVKK notice.
1. What we collect about your account
When you create an account and use the panel, we store:
- Name and email address — for sign-in, notifications and support.
- Password — never in plain text, only as a one-way hash (bcrypt). We cannot read it.
- Interface language and time zone — so dates and times are shown correctly.
- Two-factor secret — only if you turn 2FA on; stored encrypted.
- Email verification time, last sign-in time, and whether the account is active.
- Workspace records: name, type, currency, members and their roles; if you invite someone, that person's email address and role.
- API keys — only the prefix and a hash; the key itself is never stored.
We do not take payments, so we collect no card or billing details.
2. Google data we access
Connecting a Google account is optional; if you never connect one, none of this section applies to you. When you do connect, we ask Google for these permissions — all of them read-only:
openidandemail— reads the email address of the connected Google account. We use it only as the label of the connection, so you can tell two connected accounts apart.webmasters.readonly— reads Search Console data. We never ask for write access, and this scope cannot modify, unverify or delete anything.analytics.readonly— reads Google Analytics 4 reports.
What we read from Search Console
Performance data for your own properties only: daily clicks, impressions and average position, broken down by query, page, country, device, search type (web, Discover, Google News, image, video) and search appearance. On first connection we backfill as far as Search Console itself allows (up to 16 months); after that we refresh daily, re-reading the last 5 days. Search Console never gives us individual users or visitor identifiers — Google aggregates it before we see it.
What we read from Analytics 4
Aggregated daily metrics: sessions, engaged sessions, users, conversions, revenue and average engagement time, at page and site level, split by traffic channel (organic search, direct, referral, social, other). On first connection we backfill up to 400 days, then refresh the last 3 days daily. We do not read visitor-level identifiers, cookie IDs, user IDs, or event-level records.
PageSpeed Insights and Chrome UX Report
We send URLs of your own site to Google's PageSpeed Insights and CrUX APIs to get performance measurements. These calls carry no personal data and no OAuth token; they use a server-side API key.
How tokens are stored
The Google access token and refresh token are stored encrypted in our database (Laravel
encrypted casts, AES encryption with the application key). Tokens are never displayed in the
interface, never written to logs, and never sent anywhere except Google's own endpoints.
What we never do
- We do not sell your Google data, use it for advertising, or pass it to ad networks.
- We do not share it with third parties — not for marketing, not for enrichment, not for anything.
- We do not train AI or machine-learning models on it.
- No human reads it unless you explicitly ask us to, for support.
- We change nothing in your Google account; the scopes we request do not permit it.
How to revoke access
- Disconnect the Google account from the Connectors page in the panel.
- Or revoke it from your Google account: myaccount.google.com/permissions → glimana → remove access.
- After revoking, we can no longer fetch new data. To have the already-fetched data deleted too, delete the site or workspace in the panel, or email support@glimana.com — we delete it within 30 days.
3. Our own crawler
glimana crawls the sites you add to your account. The crawler identifies itself as
GlimanaBot/1.0, obeys robots.txt, makes 4 requests per second by default,
downloads at most 5 MB per page, and gives up if a page does not answer within 15 seconds.
It crawls only sites added to your account.
For each page we store: URL, HTTP status, content type, indexability, canonical URL, redirects, click depth, internal and external link counts, word count, title, meta description, H1, page language, schema types, hreflang, Open Graph tags, robots directives, a similarity hash (simhash), response timings, and a gzipped copy of the HTML.
The crawler fills in no forms, signs in nowhere, and enters no protected area. If your pages publish personal data (an author name, a contact detail), that text ends up in the stored HTML copy — that copy is deleted after 45 days.
4. Technical logs and cookies
Server logs record the requested URL, time, browser type and IP address, for security and debugging. The full list of cookies and their lifetimes is on the Cookies page. There are no advertising or analytics cookies on the marketing site or in the panel, and we use no third-party trackers.
5. How long we keep it
| Data | Retention |
|---|---|
| Search Console — daily query × page breakdown | 16 months |
| Search Console — page, query, site and appearance series | 36 months |
| Analytics 4 — daily page and site series | 36 months |
| PageSpeed runs | 12 months |
| Crawled page snapshots and stored HTML copies | 45 days |
| Account and workspace records | while the account exists |
When you delete your account the record is first deactivated, then permanently removed. HTML copies written to disk by the crawler are removed by a weekly cleanup job according to the window above.
6. Who else sees it
We do not sell data. Only these parties are involved in running the service:
- Google LLC — the source of the data; Search Console, Analytics 4, PageSpeed Insights and CrUX APIs.
- Our hosting provider — Namecheap, Inc. (USA); our servers are in a data centre in the United Kingdom (servers, database, backups).
- If you set up a notification channel, only the channel you chose (email, Telegram, Slack or your own webhook). Those settings are stored encrypted and used for nothing but notifications.
If anything else ever becomes necessary (a lawful request, for example) we will tell you first, unless the law forbids it.
7. Security
- All traffic runs over HTTPS.
- Passwords are one-way hashed; tokens and notification settings are stored encrypted.
- Optional two-factor authentication (TOTP).
- Each workspace's data is separated at query level; one workspace cannot read another's.
8. Your rights
You can ask what we hold, correct it, delete it, export it, or object to processing. Email support@glimana.com and we will answer within 30 days at the latest. For data subjects in Türkiye, rights under Article 11 of Law No. 6698 and the application procedure are on the KVKK page.
9. Children
glimana is not designed for anyone under 18, and we do not knowingly collect data from them.
10. Changes
If we update this text we change the date at the top of the page. If what we collect or why we collect it changes, we email the address on your account.