F
Falkyn

Privacy Policy

Last updated 18 September 2026

Falkyn is a desktop application for search and content analysis, developed and operated by Herringbone Digital. This policy explains what data the application accesses, how that data is used, where it is stored, who it is shared with, how it is protected, and how long it is kept. It pays particular attention to Google user data, which Falkyn can access through Google Search Console when you choose to connect your Google account.

The short version

Falkyn runs on your own machine and stores your work there. We do not operate analytics, tracking, or telemetry in the application. Google Search Console data is accessed only when you connect your account, stays on your computer, leaves it only when you ask the AI assistant to analyse it, and is never sold, transferred for advertising, or used to train AI models.

Who we are and what this covers

Falkyn is developed and operated by Herringbone Digital ("we" and "us" in this policy). The policy applies to the Falkyn desktop application and to falkyn.ai. Questions about it can go to dan@herringbonedigital.com.

What Google user data Falkyn accesses

Connecting Google Search Console is optional. Falkyn works without it. If you choose to connect, Falkyn requests these Google OAuth scopes and nothing more:

ScopeWhat it allowsWhy Falkyn asks
webmasters.readonly Read-only access to your Search Console properties and their search analytics To show which queries and pages bring you traffic, and to ground analysis in your real performance data rather than estimates
userinfo.email Your Google account email address To show which account is connected, so you can tell whether you are looking at the right property set
userinfo.profile Your basic profile information To display your name in the connection status

Through these scopes, Falkyn accesses the list of Search Console properties your Google account can see, the search analytics of the properties you choose to view (such as which queries and pages received clicks and impressions), and the email address and basic profile of the connected Google account.

The Search Console scope is read-only. Falkyn cannot submit sitemaps, request indexing, change settings, or modify anything in your Search Console account, because the permission to do so is never requested.

How Falkyn uses Google user data

Google user data is used only to provide Falkyn's features to you:

Google user data is not used for advertising, is not used to build profiles of you, is not sold to anyone, is not used to determine credit-worthiness or lending eligibility, and is not used to train generalised artificial-intelligence or machine-learning models.

Google API Services Limited Use

Falkyn's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Specifically, Google user data obtained through these scopes is not sold, not used or transferred for advertising, not used to train generalized AI or machine learning models, and not read by humans except with your explicit consent, to resolve a support issue you have raised, for security purposes, or where required by law.

How Falkyn stores your data

Falkyn is local-first. Your work lives on your computer, in your operating system's standard application-data location, and is not uploaded anywhere by the application:

Search Console data that Falkyn retrieves stays on your computer. Where it forms part of a conversation or a report, it is saved with that conversation or report in the same local database file. Apart from the AI requests described below, it never leaves your computer, and we keep no copy of it on our own systems.

Your Google OAuth tokens are encrypted at rest using your operating system's secure credential storage — Keychain on macOS, DPAPI on Windows — rather than being written in plain text.

Who Falkyn shares your data with

We do not sell, rent, or trade your data, and we do not share it with data brokers or advertisers. Some features necessarily send data to a third party in order to work, and every such destination is listed here.

Google user data is shared with only one kind of recipient: the model provider that answers when you ask the AI assistant for an analysis that includes your Search Console figures. It travels through Falkyn's AI gateway to that provider and to no one else.

DestinationWhat is sentWhen
Falkyn's AI gateway, operated on Cloudflare Workers, which routes to model providers including Anthropic and OpenAI The contents of your conversation, and whatever the assistant reads while working — page content, crawl data, and Search Console figures included in an analysis you request Only when you use an AI feature
Google Search Console API Requests for your own property data, authorized by your token Only while your Google account is connected
WorkOS Sign-in details for your Falkyn account When you sign in
Chrome UX Report API The URL or origin you are inspecting When you view Core Web Vitals
Websites you crawl or open in the built-in browser Ordinary web requests, as any browser makes When you crawl or browse
DataForSEO, if you supply your own credentials The keywords and locations you are researching Only if you configure it; it is off by default
Any Model Context Protocol server you connect Whatever that server's tools receive when called Only for servers you add and enable yourself

Model providers process the content you send in order to generate a response, under their own terms. Falkyn does not send your data to model providers for training.

How your data is protected

OAuth tokens are held in your operating system's secure credential store, encrypted at rest. Traffic to every service listed above is encrypted in transit with HTTPS. Falkyn requests only read-only access to Search Console, so its token cannot be used to change anything in your Search Console account. That said, no system is perfectly secure, and Falkyn runs on a computer whose security is ultimately in your hands.

How long your data is kept

Data stored on your computer stays until you remove it. Google OAuth tokens are kept until you disconnect Search Console in Falkyn or revoke access in your Google Account. Account records held for authentication persist while your account is active. Content sent to model providers is retained under their respective policies; we do not maintain a separate archive of your conversations.

Disconnecting Google and deleting your data

You can revoke Falkyn's access to your Google account at any time, from either end:

Because your work is stored locally, deleting it — including any Search Console data — is a matter of deleting it in the application, or uninstalling and removing the application's data folder. We hold no copy to delete on your behalf.

What Falkyn does not do

Children

Falkyn is a professional tool and is not directed at children under 13. We do not knowingly collect their information.

Changes

If this policy changes materially, including any change to how Google user data is accessed, used, stored or shared, the date at the top will change and the revised version will be posted here. Continued use after a change means you accept it.

Contact

Questions, requests, or anything about this policy: dan@herringbonedigital.com.