Last updated 18 September 2026
Falkyn is a desktop application for search and content analysis, developed and operated by Herringbone Digital. This policy explains what data the application accesses, how that data is used, where it is stored, who it is shared with, how it is protected, and how long it is kept. It pays particular attention to Google user data, which Falkyn can access through Google Search Console when you choose to connect your Google account.
Falkyn runs on your own machine and stores your work there. We do not operate analytics, tracking, or telemetry in the application. Google Search Console data is accessed only when you connect your account, stays on your computer, leaves it only when you ask the AI assistant to analyse it, and is never sold, transferred for advertising, or used to train AI models.
Falkyn is developed and operated by Herringbone Digital ("we" and "us" in this policy). The policy applies to the Falkyn desktop application and to falkyn.ai. Questions about it can go to dan@herringbonedigital.com.
Connecting Google Search Console is optional. Falkyn works without it. If you choose to connect, Falkyn requests these Google OAuth scopes and nothing more:
| Scope | What it allows | Why Falkyn asks |
|---|---|---|
webmasters.readonly |
Read-only access to your Search Console properties and their search analytics | To show which queries and pages bring you traffic, and to ground analysis in your real performance data rather than estimates |
userinfo.email |
Your Google account email address | To show which account is connected, so you can tell whether you are looking at the right property set |
userinfo.profile |
Your basic profile information | To display your name in the connection status |
Through these scopes, Falkyn accesses the list of Search Console properties your Google account can see, the search analytics of the properties you choose to view (such as which queries and pages received clicks and impressions), and the email address and basic profile of the connected Google account.
The Search Console scope is read-only. Falkyn cannot submit sitemaps, request indexing, change settings, or modify anything in your Search Console account, because the permission to do so is never requested.
Google user data is used only to provide Falkyn's features to you:
Google user data is not used for advertising, is not used to build profiles of you, is not sold to anyone, is not used to determine credit-worthiness or lending eligibility, and is not used to train generalised artificial-intelligence or machine-learning models.
Falkyn's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Specifically, Google user data obtained through these scopes is not sold, not used or transferred for advertising, not used to train generalized AI or machine learning models, and not read by humans except with your explicit consent, to resolve a support issue you have raised, for security purposes, or where required by law.
Falkyn is local-first. Your work lives on your computer, in your operating system's standard application-data location, and is not uploaded anywhere by the application:
Search Console data that Falkyn retrieves stays on your computer. Where it forms part of a conversation or a report, it is saved with that conversation or report in the same local database file. Apart from the AI requests described below, it never leaves your computer, and we keep no copy of it on our own systems.
Your Google OAuth tokens are encrypted at rest using your operating system's secure credential storage — Keychain on macOS, DPAPI on Windows — rather than being written in plain text.
We do not sell, rent, or trade your data, and we do not share it with data brokers or advertisers. Some features necessarily send data to a third party in order to work, and every such destination is listed here.
Google user data is shared with only one kind of recipient: the model provider that answers when you ask the AI assistant for an analysis that includes your Search Console figures. It travels through Falkyn's AI gateway to that provider and to no one else.
| Destination | What is sent | When |
|---|---|---|
| Falkyn's AI gateway, operated on Cloudflare Workers, which routes to model providers including Anthropic and OpenAI | The contents of your conversation, and whatever the assistant reads while working — page content, crawl data, and Search Console figures included in an analysis you request | Only when you use an AI feature |
| Google Search Console API | Requests for your own property data, authorized by your token | Only while your Google account is connected |
| WorkOS | Sign-in details for your Falkyn account | When you sign in |
| Chrome UX Report API | The URL or origin you are inspecting | When you view Core Web Vitals |
| Websites you crawl or open in the built-in browser | Ordinary web requests, as any browser makes | When you crawl or browse |
| DataForSEO, if you supply your own credentials | The keywords and locations you are researching | Only if you configure it; it is off by default |
| Any Model Context Protocol server you connect | Whatever that server's tools receive when called | Only for servers you add and enable yourself |
Model providers process the content you send in order to generate a response, under their own terms. Falkyn does not send your data to model providers for training.
OAuth tokens are held in your operating system's secure credential store, encrypted at rest. Traffic to every service listed above is encrypted in transit with HTTPS. Falkyn requests only read-only access to Search Console, so its token cannot be used to change anything in your Search Console account. That said, no system is perfectly secure, and Falkyn runs on a computer whose security is ultimately in your hands.
Data stored on your computer stays until you remove it. Google OAuth tokens are kept until you disconnect Search Console in Falkyn or revoke access in your Google Account. Account records held for authentication persist while your account is active. Content sent to model providers is retained under their respective policies; we do not maintain a separate archive of your conversations.
You can revoke Falkyn's access to your Google account at any time, from either end:
Because your work is stored locally, deleting it — including any Search Console data — is a matter of deleting it in the application, or uninstalling and removing the application's data folder. We hold no copy to delete on your behalf.
Falkyn is a professional tool and is not directed at children under 13. We do not knowingly collect their information.
If this policy changes materially, including any change to how Google user data is accessed, used, stored or shared, the date at the top will change and the revised version will be posted here. Continued use after a change means you accept it.
Questions, requests, or anything about this policy: dan@herringbonedigital.com.