Privacy policy
Last updated 24 September 2026
Mantaq is an AI workspace for marketing and SEO teams. This policy covers the data we handle, and in particular what happens to your Google data when you connect a Google account.
Connecting a Google account is optional
Mantaq works without any Google connection. You only grant access if you want to ask questions about your Search Console or Analytics data.
What we request, and why
| Permission | What it allows | Why we need it |
|---|---|---|
webmasters.readonly |
Read-only access to Search Console for properties the connected account can already access. | To answer questions about search queries, landing pages, clicks, impressions and average position. |
analytics.readonly |
Read-only access to Google Analytics 4 for the same account. | To answer questions about users, sessions, acquisition channels and page views. |
userinfo.email |
The email address of the connected Google account. | To display which account is connected, so teams can tell several linked accounts apart and avoid linking the same one twice. |
These are the narrowest scopes that support the feature. Mantaq holds no permission to create, edit or delete anything in your Google account, and it cannot see any Google property the connected account does not already have access to.
How we use Google data
When a question needs Search Console or Analytics data, Mantaq requests the figures needed to answer it and uses them for that answer. Nothing else.
- Google data is fetched at the time of the question, not copied into a separate store or search index.
- We do not retain the Search Console or Analytics figures after the answer has been produced.
- We do not use Google user data to train, retrain or improve any AI model.
- We do not use it for advertising, profiling or any form of marketing.
What we store, and how it is protected
The only Google data we keep is what is needed to maintain the connection you authorised:
- A refresh token. This is the credential that lets Mantaq keep reading on your behalf. It is encrypted before it is written to disk, on infrastructure we control, and the key is kept separately from the data.
- The Google address and the name your team gave it. This is how the connection is identified in the interface.
Short-lived access tokens are requested from Google as needed and held in memory only; they are never written to disk. No Google credential is ever sent to the browser, written to logs, or returned by any API we expose.
Who can see it
A connected Google account is available to everyone in your Mantaq workspace, so a team can work on shared client accounts. Nobody outside your workspace can reach it.
We do not sell Google user data, and we do not share it with third parties for their own purposes. Data passes only between your workspace, Google, and the AI model that produces the answer to your question.
Limited Use disclosure. Mantaq's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Removing access
You can disconnect a Google account at any time in Mantaq under Admin → Existing Connectors → Google Account → Unlink. This deletes the stored refresh token immediately, and Mantaq can no longer read that account's data.
You can also revoke access directly from your Google account at myaccount.google.com/permissions, which takes effect regardless of anything done inside Mantaq.
Other data we handle
Apart from Google data, Mantaq stores what your team adds: documents, conversations and workspace settings. Accounts are identified by email address, and model usage is recorded so administrators can see cost and activity per person.
Changes to this policy
If what we do with Google user data changes, we will update this page and the date above before the change takes effect.
Contact
Questions about this policy, or about data we hold: support@mantaq.ai.