Privacy Policy
First Page MCP · Last updated 29 July 2026
First Page MCP (“the application”) is an internal tool operated by First Page for its own staff. It lets authorised First Page employees read Google Analytics 4 and Google Search Console reporting data for accounts that First Page already manages, so that analysis can be performed in the tools the team uses day to day. The application is not offered to the public and does not have external end users.
Who we are
The application is operated by First Page. For any question about this policy or about data held by the application, contact tools@firstpage.com.au.
Google user data we access
The application requests two Google API scopes:
https://www.googleapis.com/auth/analytics.readonly
https://www.googleapis.com/auth/webmasters.readonly
Both scopes are read-only. Using analytics.readonly, the application reads: the list of Google Analytics accounts and properties an authorised account can see (property names, IDs, timezone, currency and data streams), and aggregated Analytics reporting data such as sessions, users, engagement, key events, revenue and the dimensions those metrics are broken down by.
Using webmasters.readonly, the application reads: the list of Google Search Console properties an authorised account can see (site URLs and the account’s permission level on each), and aggregated Search Console performance data such as clicks, impressions, click-through rate and average position, broken down by search query, page, country, device and date, together with sitemap status and URL indexing status.
During sign-in the application also reads the account’s email address, name and profile picture (openid, email, profile) purely to label the connection in the interface and to restrict administrative access to First Page staff.
Why we need it
First Page manages Google Analytics properties and Search Console sites on behalf of its clients. Access to those properties is spread across a number of Google accounts. The application connects each of those accounts once, remembers which properties and sites each can see, and uses that to answer reporting questions from staff without anyone having to log in to the Analytics or Search Console interface property by property.
Both scopes are requested in a single authorisation because one account typically holds both kinds of access, and asking twice would double the number of times each account owner is prompted without narrowing what is accessed.
These read-only scopes are the narrowest that permit this. No scope granting write, configuration or user-management access is requested, and the application contains no code capable of modifying an Analytics property or a Search Console site.
How we store and protect it
When an account is connected, Google issues a refresh token. That token is encrypted with AES-256-GCM before it is written to storage, and is decrypted only in memory at the moment an Analytics or Search Console API request is made. Encryption keys are held in Google Secret Manager and in the hosting provider’s encrypted environment store, separately from the tokens themselves.
Tokens and the property and site indexes are stored in Google Cloud Firestore in the australia-southeast1 region. Administrative access to the application requires signing in with a First Page Google Workspace account; accounts outside that domain are rejected.
Analytics and Search Console reporting data itself is notretained. It is fetched from Google on demand, returned to the requesting staff member, and not written to any database by the application.
What we do not do
- We do not sell, rent or trade Google user data.
- We do not transfer it to third parties, other than the Google APIs it came from and the cloud infrastructure described above.
- We do not use it for advertising, or to build profiles of individuals.
- We do not use it to train, or to improve, generalised artificial intelligence or machine learning models.
- We do not allow humans to read it except the First Page staff member who requested the specific report.
The application’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and removal
A connected account’s refresh token is retained until the connection is removed. Removing a connection in the application revokes the token with Google and deletes the stored token and the property and site indexes immediately.
The owner of any connected Google account can also revoke access at any time at myaccount.google.com/permissions, which immediately ends the application’s ability to read that account’s data.
Changes
If this policy changes, the revised version will be published at this address with an updated date above.
First Page · Australia · Singapore · Hong Kong · tools@firstpage.com.au