Page Lens

Page Lens Privacy Policy

Effective date: 4 June 2026 (Last updated: 5 June 2026).


This Privacy Policy describes how Page Lens (the Extension), developed by the Page Lens Team, collects, uses, stores, and protects information when you use the Extension. Installing or using it means you agree to these practices.

The Extension is a Google Chrome browser extension displaying Google Search Console performance data as a sidebar overlay. It is built privacy-first: your Search Console data stays on your device. Requests go directly from your browser to Google, with results cached locally. Beyond Google, the Extension talks to a single service of our own: an integrity service that records when your free trial began and, once you activate a license, which Google account a license key belongs to. It stores your trial start timestamp, an opaque Google account identifier, and (for license holders) your license key, but never any Google Search Console data. Purchases are handled by Dodo Payments on a separate checkout page; the Extension itself never connects to Dodo.


1. Information the Extension Accesses

1.1 Google Search Console Data

When activated, the Extension fetches:

  • Page-level performance metrics: clicks, impressions, CTR, average search position
  • Top search queries driving traffic
  • Page indexing status

Data comes directly from Google's servers via your authenticated account, cached locally in your browser, never sent to us or third parties.

1.2 Page URL

The Extension reads your current page's URL to query Search Console API for page-specific data. This URL goes only to Google's API; it is not collected, logged, or transmitted to us or third parties.

To render the sidebar on demand, the Extension runs a small content script on the pages you open. It reads the page URL only when you activate the sidebar, and never reads, stores, or transmits the page's content.

1.3 Google Search Console Property List

The Extension retrieves web properties (domains/URL prefixes) from your Search Console account, determining whether your current page belongs to a verified property. This list is cached locally.

1.4 Google Account Identifier (Trial and License Anchoring)

To run the free trial fairly and to tie a paid license to one account, the Extension sends your Google access token to our integrity service, which verifies it with Google and obtains a stable, opaque Google account identifier. The service uses this identifier to anchor your trial start and, if you activate a license, to bind that license key to your account. The data stored server-side is this opaque identifier, your trial start timestamp, and (for license holders) your license key; the access token itself is never stored. No name, email, profile data, or Search Console data is collected for this purpose. Other than Google's own APIs, this is the only place your access token is sent. See the Third-Party Services and Data Storage sections for how it is handled and retained.


2. Information the Extension Does Not Collect

The Extension does not collect, record, or transmit:

  • Personal details such as your name, email address, phone number, or physical address
  • Browsing history, or any record of the pages you visit (the current page's URL is sent only to Google to run that page's query, as described under Page URL above)
  • Analytics, telemetry, or usage tracking
  • Cookies or tracking identifiers
  • Web page content

The only data we store on our servers is the opaque Google account identifier described under Google Account Identifier above, your trial start timestamp, and (if you activate a license) your license key bound to that identifier. None of it is linked to your name or email. We use no analytics SDK or tracking pixel, and we keep no server-side logs or profiles of your browsing or Search Console activity.


3. Google Account Authentication

The Extension uses Google OAuth 2.0 via Chrome's built-in chrome.identity API. Chrome and Google manage this entirely; the Extension never sees, stores, or accesses your Google password.

OAuth scopes requested:

ScopePurpose
openidProvides a stable, opaque Google account identifier used to anchor your free trial and bind your license to your account, as described under Google Account Identifier above. No name, email, or profile data is requested or stored.
webmasters.readonlyRead-only access to your Search Console performance and inspection data (metrics, queries, indexing status)

The Extension never writes, modifies, or deletes Search Console data.

When you choose Disconnect Google account inside the Extension, it sends your access token once to Google's OAuth revocation endpoint (accounts.google.com) to invalidate the grant, then clears the locally cached token. This is a Google endpoint and remains within the "Google's own APIs" exception described under Google Account Identifier above.

Revoke access anytime via your Google Account Permissions page.


4. Google API Services User Data Policy

Page Lens complies with the Google API Services User Data Policy, including Limited Use requirements:

  1. Google user data is used only to provide user-facing features (displaying Search Console data as overlay)
  2. Google user data is not transferred to third parties except for core functionality, legal compliance, or explicit user consent
  3. Google user data is not used for advertising, retargeting, or personalized ads
  4. No human reads Google user data unless: (a) explicit user consent, (b) security purposes, or (c) legal compliance

5. Data Storage

Search Console data and cached API responses are stored locally using Chrome's extension storage APIs.

Storage MechanismContentsSynced Across Devices
chrome.storage.syncLicense key, sidebar widthYes (across signed-in browsers)
chrome.storage.localCached API responses, property listNo (current device only)

Your free-trial start timestamp is not stored on your device. It is held server-side by our integrity service, keyed to your opaque Google account identifier, so the trial can't be reset by clearing local data. The same service also stores, against that identifier, the license key you've activated, so a key can be tied to one Google account and can't be shared. On your device the license key string is kept in chrome.storage.sync; whether it's valid and whose it is are checked with the server, never stored locally.

Cached data follows a time-to-live (TTL) policy and auto-refreshes upon expiration.


6. Data Security

Communication between the Extension and Google's APIs, and between the Extension and our integrity service, uses HTTPS encryption, as does our integrity service's server-side call to Dodo Payments when it validates a license. Locally stored data is protected by Chrome's extension storage security model, isolating extension data from other extensions and web pages.


7. Third-Party Services

ServicePurposeData Shared
Google Search Console APIFetch performance metrics, queries, indexing statusCurrent page URL and OAuth token (Chrome-managed). Governed by Google's Privacy Policy
Chrome Identity APIAuthenticate via OAuth 2.0Managed by Chrome/Google; Extension doesn't access credentials
Page Lens integrity serviceVerify your Google identity, record your free-trial start, and bind a license key to your accountYour Google access token (sent over HTTPS, verified with Google, never stored). The opaque Google account identifier, trial start timestamp, and (for license holders) the license key are stored. No Search Console, browsing, or profile data
Dodo PaymentsProcess your purchase (on Dodo's own checkout page) and confirm a license key is valid (server-side, at our integrity service's request)Payment and purchase details you enter on Dodo's checkout page; your license key, which our integrity service passes to Dodo to confirm it's valid. The Extension never connects to Dodo directly, and no Search Console or browsing data is shared. Governed by Dodo Payments' Privacy Policy

No analytics SDKs, tracking pixels, or third-party data collection tools are used.

Because every web request carries it, our integrity service (like Google) receives your device's IP address. Our integrity service uses it only to handle the request; we do not store it or retain it in our own logs (our hosting provider may process it transiently at the network edge under its own policies). Dodo Payments receives your IP only when you open its checkout page to make a purchase (not during the Extension's normal use), and handles any IP data under its own privacy policy.


8. Chrome Extension Permissions

PermissionPurpose
activeTabOpen and toggle the sidebar on the current tab when you click the extension icon
identityAuthenticate via Chrome's OAuth flow
storageCache API responses and persist user preferences
alarmsSchedule periodic license revalidation and deferred data fetches
scriptingInject the sidebar UI into the current page

The Extension also declares host access to Google Search Console (searchconsole.googleapis.com) and our integrity service (trials.pagelens.workers.dev) so it can make these HTTPS requests. It declares no host access to Dodo Payments, because it never connects to Dodo directly.


9. Data Retention and Deletion

  • Uninstalling deletes locally cached data in chrome.storage.local (API responses, property list). Data in chrome.storage.sync (license key, sidebar width) may persist in your Google account after uninstall
  • Cached API responses auto-refresh when exceeding TTL
  • Our integrity service retains your opaque Google account identifier, your trial start timestamp, and (if you've activated a license) your license key bound to that identifier, to enforce the one-time free trial and the one-account-per-license rule. This record holds no Search Console data, name, email, or browsing information, and persists independently of uninstalling the Extension
  • Revoking access through Google Account Permissions revokes the OAuth token

Search Console data is never stored on our servers. Dodo Payments remains the authority on whether a license is valid and handles your payment-card details; our integrity service stores the license key only to bind it to your Google account.


10. Children's Privacy

The Extension is not directed at children under 13 (or applicable age of digital consent in your jurisdiction). We don't knowingly collect personal information from children.


11. Your Rights

Because we store no Search Console or browsing data on our servers, your data rights are exercised largely through local browser control. The one exception is your server-side record (your trial start and, for license holders, your license binding), which you can ask us to delete:

  • Access: Locally stored data is viewable in your browser's extension storage via Chrome developer tools; for the server-side record, you can request a copy by email
  • Deletion: Uninstall the Extension to clear local data, then email us at the address in the Contact section below to delete your server-side record
  • Revocation: Use Disconnect Google account within the extension to revoke its Google access and clear locally cached data, or revoke access anytime via your Google Account Permissions page

12. Changes to This Policy

This Privacy Policy may be updated periodically. Material changes will update the "Last updated" date at the top.


13. Governing Law

This Privacy Policy is governed by the laws of India. Disputes are subject to exclusive jurisdiction of Indian courts.


14. Contact

Questions or concerns regarding this policy or the Extension's data practices:

Page Lens Team Email: [email protected]