Google integration
Privacy policy
This policy describes the personal local Repo Steward deployment operated by the contact listed below. Effective date: 4 October 2026.
What Google access permits
After consent, Repo Steward receives OAuth credentials for Search Console access to verified sites and for verifying new sites. Search Console can return verified site URLs, site permissions, sitemap submission and processing information, and URL indexing status. The site verification service returns the verification material needed to prove control of a site.
How the integration uses that data
Repo Steward uses these permissions to select the relevant site property, publish a verification file to an owned GitHub Pages source when needed, confirm ownership with Google, submit that site's sitemap and display the result of URL inspection. Google access does not guarantee indexing or a position in search results.
Storage and retention
OAuth client credentials and the refresh token are saved on the operator's computer for background Google requests. Job results and relevant site URLs are stored in the local application database and may remain in operator-created backups. These files remain until the operator removes them or changes the deployment. The operator controls access to the computer, backups and the authenticated web panel.
Where information is sent
Authorized requests send the credentials and selected site information to Google's OAuth, Search Console and Site Verification services. Ownership verification publishes a Google verification file on GitHub Pages through GitHub. That verification file and the site's sitemap are public; the OAuth credentials and refresh token are not part of those publication files.
The application also offers content generation and chat through separately configured AI providers. Text entered into those features is sent to the chosen provider. Do not paste OAuth credentials or private reports into those features. Google OAuth tokens are used by the Google integration to authenticate Google requests, not as content-generation input.
Limited use
The Google integration uses Google data to provide the site verification, sitemap and indexing-status features described here. It does not sell Google user data or use it for advertising. Repo Steward's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Revocation and deletion
Revoke the app's permission through Google Account connections to stop future authorized access after existing access tokens expire. To remove saved data, the operator must also remove the local OAuth credential files, relevant database records and any retained copies or backups. Revocation alone does not delete local reports or published site files.
Contact and changes
For questions about this deployment or deletion, contact the operator through the repository's issue tracker. Issues are public: do not include credentials or private personal information. This policy must be updated before this deployment changes its Google data practices or is offered as a broader hosted service.