Last updated 30 July 2026
Falkyn is a desktop application for search and content analysis. This policy explains what data the application handles, what leaves your computer, and what we do and do not do with it.
Falkyn runs on your own machine and stores your work there. We do not operate analytics, tracking, or telemetry in the application. Google Search Console data is read only when you connect your account, is stored locally, and is never sold, transferred for advertising, or used to train AI models.
This policy applies to the Falkyn desktop application and to falkyn.ai. Questions about it can go to dan@herringbonedigital.com.
Connecting Google Search Console is optional. Falkyn works without it. If you choose to connect, Falkyn asks for these scopes and nothing more:
| Scope | What it allows | Why Falkyn asks |
|---|---|---|
webmasters.readonly |
Read-only access to your Search Console properties and their search analytics | To show which queries and pages bring you traffic, and to ground analysis in your real performance data rather than estimates |
userinfo.email |
Your Google account email address | To show which account is connected, so you can tell whether you are looking at the right property set |
userinfo.profile |
Your basic profile information | To display your name in the connection status |
The Search Console scope is read-only. Falkyn cannot submit sitemaps, request indexing, change settings, or modify anything in your Search Console account, because the permission to do so is never requested.
Falkyn's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Specifically, Google user data obtained through these scopes is not sold, not used or transferred for advertising, not used to train generalized AI or machine learning models, and not read by humans except with your explicit consent, to resolve a support issue you have raised, for security purposes, or where required by law.
Falkyn is local-first. The following live on your computer, in your operating system's standard application-data location, and are not uploaded anywhere by the application:
Your Google OAuth tokens are encrypted at rest using your operating system's secure credential storage — Keychain on macOS, DPAPI on Windows — rather than being written in plain text.
Some features necessarily send data outward. Each is listed here.
| Destination | What is sent | When |
|---|---|---|
| Falkyn's AI gateway, operated on Cloudflare Workers, which routes to model providers including Anthropic and OpenAI | The contents of your conversation, and whatever the assistant reads while working — page content, crawl data, and Search Console figures included in an analysis you request | Only when you use an AI feature |
| Google Search Console API | Requests for your own property data, authorized by your token | Only while your Google account is connected |
| WorkOS | Sign-in details for your Falkyn account | When you sign in |
| Chrome UX Report API | The URL or origin you are inspecting | When you view Core Web Vitals |
| Websites you crawl or open in the built-in browser | Ordinary web requests, as any browser makes | When you crawl or browse |
| DataForSEO, if you supply your own credentials | The keywords and locations you are researching | Only if you configure it; it is off by default |
| Any Model Context Protocol server you connect | Whatever that server's tools receive when called | Only for servers you add and enable yourself |
Model providers process the content you send in order to generate a response, under their own terms. Falkyn does not send your data to model providers for training.
You can revoke Falkyn's access to your Google account at any time, from either end:
Because your work is stored locally, deleting it is a matter of deleting it in the application, or uninstalling and removing the application's data folder. We hold no copy to delete on your behalf.
Data stored on your computer stays until you remove it. Account records held for authentication persist while your account is active. Content sent to model providers is retained under their respective policies; we do not maintain a separate archive of your conversations.
OAuth tokens are held in your operating system's secure credential store. Traffic to every service listed above uses HTTPS. That said, no system is perfectly secure, and Falkyn runs on a computer whose security is ultimately in your hands.
Falkyn is a professional tool and is not directed at children under 13. We do not knowingly collect their information.
If this policy changes materially, the date at the top will change and the revised version will be posted here. Continued use after a change means you accept it.
Questions, requests, or anything about this policy: dan@herringbonedigital.com.