Least-privilege Google access
DataFawn requests only the read-only Search Console scope. It cannot modify your site, your Search Console settings, or any other Google service.
Security
DataFawn only needs read access to your search data and your public pages. These are the controls that protect it.
DataFawn requests only the read-only Search Console scope. It cannot modify your site, your Search Console settings, or any other Google service.
OAuth access and refresh tokens are encrypted at rest with AES-256-GCM authenticated encryption under a key that is separate from all other application secrets.
Every product entity belongs to a workspace, and every read and write is authorized server-side against your membership. Cross-workspace requests return the same not-found response as an unknown record.
All outbound fetches treat the supplied URL and every redirect as hostile. Private, loopback, link-local, and reserved addresses are rejected, DNS is revalidated before each hop, and the connection is pinned to the validated address.
Win Cards and Weekly Wrapped summaries are private until you create a link. Links use unguessable tokens, can expire, and can be revoked at any time.
Workspace, membership, integration, task, and sharing actions append entries to an activity log that the application cannot update or delete, enforced by a database trigger.
Public endpoints are rate limited. Per-workspace and global provider spend ceilings stop runaway provider usage before it happens.
A workspace owner can delete a workspace at any time. Deletion cancels billing, revokes the Google connection, and removes workspace data, keeping only an audit entry and a receipt of identifiers.
Email support@datafawn.comwith the affected URL, the steps to reproduce, and the impact you observed. Please do not test against other customers' workspaces or run denial-of-service traffic. We confirm receipt before investigating and will tell you what we found.