Account
Security and privacy basics
What SERPclimber can read, when it may change your site, how secrets are stored, and how outside access is controlled.
SERPclimber is built to read a lot and change little. This page summarizes what it can access, what it stores, and when it may change your site.
Data access
- Google Search Console and Analytics — read-only access, granted through Google's consent screen. SERPclimber stores daily performance rows and summaries so Performance, Reports, and the assistant can answer without re-fetching everything.
- Cloudflare — read-only access to zone analytics, through Cloudflare's consent screen or a token scoped to Zone:Read and Analytics:Read.
- Wix — write access to published content, used only by a prepared action plan that has passed scope, autonomy, risk, and approval checks.
- Managed providers — backlink, keyword, AI answer, and language-model providers are operated by SERPclimber under its own accounts. Your project's domain, queries, and page content are sent to them only as needed for the evidence they supply.
Publishing approvals
The engine changes your site only through a frozen action plan. Copilot, the default, executes low-risk reversible work and asks before anything risky, external, or paid. Audit only / MCP never changes the site. Full still respects per-action spend limits and maximum risk. Every executed change leaves a receipt in its task thread and is verified against the live page. See Autonomy.
Secrets
OAuth tokens and API keys are encrypted at rest and never shown again after saving. They are entered only on the Integrations screen — never in chat — and chat responses, documentation search, and MCP results strip credentials and provider secrets.
Outside access
AI clients connect through OAuth with scopes you approve; read access and write access are separate scopes, and every write still goes through a prepared plan. Revoke a client at any time under Settings → Account → MCP access. See MCP access.
Keeping and removing data
Archiving a project stops all work and keeps its evidence. Removing a site from billing makes it read-only without deleting records. Deleting a conversation removes its messages permanently. Signing out other sessions is available under Settings → Account → Sessions.
