Before you connect, here is exactly what we ask for
This page comes before the connect button. For each channel it lists the permission we request, the API methods we call with it, how long we keep what we receive, and how you take it back.
These are read-only permissions for the diagnostic. If you contract the improvement programme we ask separately for the write permissions.
Bing Webmaster Tools (in preparation)
Bing and Copilot surfaces in the Panorama diagnostic, plus URL and sitemap submission once you contract the improvement programme
Ways to connect
- Connect with your Bing account — Clicks on your side 1
- Add us as a user in Bing — Clicks on your side 2
- Import from Search Console — Clicks on your side 0
Permission requested
Webmaster.read
We read how your site stands in the Bing index — which queries show it, which pages are indexed, and what the crawler could not reach. Copilot answers draw on this index, which is why the report leans on it.
Methods called with it: GetUserSites, GetSiteRoles, GetQueryStats, GetPageStats, GetUrlTrafficInfo, GetCrawlStats, GetCrawlIssues
Permission we do not request
(API key sharing)— A Bing API key is one per account and reaches every verified site on it. We do not take yours.
How to revoke
- Revoke the app in your Bing settings
- Disconnect in the dashboard — we remove the user role
- Remove us in Search Console and the Bing side unwinds too
Google Search Console
Search performance in the Panorama diagnostic, plus sitemap submission once you contract the improvement programme
Ways to connect
- Connect with your Google account — Clicks on your side 1
- Add us as a user in Search Console — Clicks on your side 2
Permission requested
https://www.googleapis.com/auth/webmasters.readonly
We read the search performance of the one property you pick — which queries showed it, how often it was seen and clicked, which page, at what average position. It lets us compare before and after using your own numbers.
Methods called with it: sites.list, searchAnalytics.query, sitemaps.list, urlInspection.index.inspect
Permission we do not request
https://www.googleapis.com/auth/siteverification— This one can change who owns the property. It would let us touch the ownership of your asset, so we do not ask for it.https://www.googleapis.com/auth/indexing— Google limits this to job postings and broadcast events. Selling general indexing on the back of it would be a false claim.
How to revoke
- Disconnect in the dashboard — we erase the stored grant and ask Google to revoke it as well
- You can also revoke it yourself in your Google account
Google Analytics 4
Traffic and conversion in the Panorama diagnostic, the T0 order signal, and configuration fixes in the improvement programme
Ways to connect
- Connect with your Google account — Clicks on your side 1
- Add us as a viewer in Analytics — Clicks on your side 2
Permission requested
https://www.googleapis.com/auth/analytics.readonly
We read the aggregate numbers of the one property you pick — where visits came from, which page they landed on, how many sessions, and how many of the conversions you marked as key events. We also read the property settings, because that is usually where a missing conversion hides.
Methods called with it: accountSummaries.list, properties.get, dataStreams.list, keyEvents.list, customDimensions.list, customMetrics.list, properties.getDataRetentionSettings, googleAdsLinks.list, runReport, batchRunReports
Permission we do not request
https://www.googleapis.com/auth/analytics— Full control. The read-only scope covers the whole diagnostic, so there is no reason to ask for it.https://www.googleapis.com/auth/analytics.manage.users.readonly— The name says read-only, but what it reads is the list of people with access — other individuals' personal data, with no place in your report.
How to revoke
- Disconnect in the dashboard — we erase the stored grant and ask Google to revoke it as well
- You can also remove us in Analytics access management
Google Tag Manager (in preparation)
The measurement audit in the Panorama diagnostic, plus tag fixes in the improvement programme
Ways to connect
- Add us as a container user — Clicks on your side 2
- Connect with your Google account — Clicks on your side 1
- Take the install snippet — Clicks on your side 0
Permission requested
https://www.googleapis.com/auth/tagmanager.readonly
We read the tags, triggers and variables in the container you pick. This is where a missing conversion or a tag firing twice shows up. The install snippet comes through the same permission.
Methods called with it: accounts.list, containers.list, workspaces.list, tags.list, triggers.list, variables.list, containers.snippet
Permission we do not request
https://www.googleapis.com/auth/tagmanager.delete.containers— This deletes containers. Nothing we sell needs it.https://www.googleapis.com/auth/tagmanager.manage.accounts— Account-level administration. Reading one container does not require the whole account.
How to revoke
- Disconnect in the dashboard — we erase the stored grant and ask Google to revoke it as well
- You can also remove us in Tag Manager user management
Meta Ads
Paid traffic in the Panorama diagnostic
Ways to connect
- Facebook Login for Business — Clicks on your side 1
Permission requested
ads_read
We read the aggregate performance of the ad account you pick — impressions, clicks, spend and conversions by campaign and placement. It cannot create or change an ad.
Methods called with it: me/adaccounts, act_{id}/insights
Permission we do not request
ads_management— This creates and changes ads. The diagnosis reads only, so we leave this one with you.business_management— It opens the whole business — people, partners, assets. Other individuals' personal data comes with it.
How to revoke
- Remove the app in your Facebook settings
- Disconnect in the dashboard — we destroy the stored token
Order and payment signal (in preparation)
Revenue attribution in the Panorama diagnostic, and outcome verification in the improvement programme
Ways to connect
- Comes through Analytics — Clicks on your side 0
- Receive payment webhooks — Clicks on your side 1
- Upload a file or type it in — Clicks on your side 1
Permission requested
(no OAuth scope)
There is no account permission here. We use the numbers Analytics already sends, share one key for payment notifications, or take a file. We never touch the payment provider account.
Methods called with it: order_ingest.verify_standard_webhook, order_ingest.record_signals
Permission we do not request
(payment provider credentials)— We do not take payment provider API keys. Taking them would put us next to your money, and nothing we sell needs that.(card data and buyer identity)— Order id, time, amount, currency and status are enough to attribute revenue. Where a buyer must be distinguished, we take a hash, never the original.
How to revoke
- Rotate the key in the dashboard — later notifications are all rejected
- You can also delete the endpoint in your payment system
Naver Search Ads (in preparation)
Paid search traffic in the Panorama diagnostic, and campaign work once you hand us ad operations
Ways to connect
- Issue an API licence in your Search Ads account — Clicks on your side 3
- Add our account as a member of your ad account — Clicks on your side 2
Permission requested
(API licence: read)
We read the campaign structure and results in your Search Ads account — which keywords spent, what got clicked. It cannot switch a campaign on or off, and cannot change a bid.
Methods called with it: GET /ncc/campaigns, GET /keywordstool
Permission we do not request
(bizmoney top-up and payment method)— We do not take the top-up seat. We decide the budget with you; the hand that actually loads the money stays yours.
How to revoke
- Delete the API licence in your Search Ads account
- Disconnect in the dashboard — we destroy the stored key
LINE
Social operations on the Japanese surface — account verification and post-history reconciliation
Ways to connect
- Connect with your LINE account — Clicks on your side 1
Permission requested
profile
We confirm which account you handed us — the display name and the account id, two lines. It does not reach your friend list or any conversation.
Methods called with it: GET /v2/profileopenid
This is the standard check that the person connecting owns the account. Without it, someone could attach an account that is not theirs to our dashboard.
Methods called with it: POST /oauth2/v2.1/token
Permission we do not request
(Messaging API channel access token)— That key sends messages from your official account. If you contract broadcast operations we take it through a separate handover — a login consent does not carry it at all.
How to revoke
- Remove the linked app in your LINE settings
- Disconnect on the connections screen — we destroy the stored token
Google Ads (in preparation)
Paid search and display in the Panorama diagnostic, and execution once you hand us ad operations
Ways to connect
- Connect with your Google account — Clicks on your side 1
- Accept our manager account link request — Clicks on your side 2
Permission requested
https://www.googleapis.com/auth/adwords
We read the aggregate performance of the ad account you pick — impressions, clicks, cost and conversions by campaign. The scope also carries write, but the diagnostic calls read methods only and every call is written to the access log.
Methods called with it: customers:listAccessibleCustomers, googleAds:searchStream
Permission we do not request
(payment method and billing settings)— We do not touch the card or the billing setup. We decide the budget with you; the payment method stays on your screen.
How to revoke
- Revoke the app in your Google account security settings
- Disconnect in the dashboard — we destroy the stored token
- Unlink the manager account and that path closes too
Microsoft Advertising (in preparation)
Paid Bing and Copilot surfaces in the Panorama diagnostic, and execution once you hand us ad operations
Ways to connect
- Accept our agency client link request — Clicks on your side 2
- Connect with your Microsoft account — Clicks on your side 1
Permission requested
https://ads.microsoft.com/msads.manage
We read which ad accounts hang off your sign-in and then the results of the one you pick. The provider offers no read-only scope on this rail, so the name says manage — but the diagnostic calls exactly the three read operations listed beside this line.
Methods called with it: GetUser, GetAccountsInfo, SearchAccounts
Permission we do not request
(billing and payment details)— We do not touch billing or payment. A client link opens campaign management only — account ownership and billing stay with you.
How to revoke
- Remove the agency link in Microsoft Advertising
- Disconnect in the dashboard — we destroy the stored token
How long we keep it
- Raw payloads: 30days
- Access log: 365days
About this consent
Lawful basis and withdrawal
The screen names the basis for processing and states that withdrawal is one click, no harder than granting was. The revoke button sits on the same screen as the grant button.
Processor role and sub-processors
We act on your instruction. Every sub-processor that touches your data to generate commentary is named on the consent screen before you grant.
Google API Services User Data Policy
Data received through Google scopes is used only to provide the feature you asked for, is never sold, and never trains a general model. This holds regardless of where you are.
How we handle and store what we receive is set out in the trust centre. Read the trust centre on retention and handling