NAVINES NOISE is provided by NAVINES ISRAEL LTD (“NAVINES,” “we,” “us”). This policy separates the hosted Search Console MCP from the Chrome extension because they use different permissions, infrastructure and storage.
Two products, no automatic bridge
Hosted service
Search Console MCP
You explicitly connect Auth0 and Google. An authenticated MCP request can read authorized Search Console data through NAVINES servers.
Local browser product
Chrome extension
You explicitly select Analyze this page. Version 1.0.0 processes that page locally in Chrome and does not send its report to the MCP service.
Hosted service
Google Search Console MCP data handling
The MCP uses Auth0 OAuth 2.1 to identify the user and Google OAuth with the single https://www.googleapis.com/auth/webmasters.readonly scope. It can retrieve data from properties your Google account is permitted to access; it cannot submit, remove or change Search Console resources.
What the service stores
- Auth0 subject, verified email when supplied, account timestamps and connection status.
- The Google refresh token encrypted at rest with AES-256-GCM, its encryption metadata and the granted read-only scope.
- Trial or active-access status, expiry and minimal tool reservation, success, failure, rate-limit and administrator audit records.
What the service does not store
NOISE does not persist Search Console reports, property lists, search queries, pages, countries, devices, clicks, impressions, CTR, positions, URL-inspection results, sitemaps or full Google API responses. Tool arguments and returned result rows are not written to Neon or operational logs.
What happens during a tool call
After the MCP bearer token is verified, the server uses the encrypted Google connection in memory to make the requested Google API call and returns a bounded result to the authenticated MCP client. Google processes that request under its own terms. NAVINES records only the minimal success, failure and access-control event needed to enforce the trial, rate limits and security audit.
Disconnect and retention
You can disconnect Google from the dashboard. That action deletes the encrypted refresh token and connection grant. Minimal user, access and audit records may remain for account security, abuse prevention and legal obligations; they contain no Search Console report data. You can also revoke NAVINES NOISE from your Google account controls.
NAVINES NOISE’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Chrome extension
Local scan core rule
NOISE scans only the active HTTP or HTTPS page and only after the user opens the extension, reads the disclosure and selects Analyze this page. Version 1.0.0 performs the analysis locally in Chrome and does not automatically send scan data to NAVINES or any third party.
Chrome extension information processed
To create the user-requested report, NOISE processes:
- The selected page URL.
- Rendered page title, meta description, canonical and robots values.
- Document language, selected headings, Open Graph, Twitter Card and hreflang metadata.
- Aggregate counts for visible words, images, links, forms, structured-data blocks, resources and DOM elements.
- Basic JSON validity for JSON-LD blocks.
- HTTPS and mixed-content indicators.
- Aggregate accessibility and structure indicators, such as missing alternatives, labels, accessible names and landmarks.
- Browser-observed navigation, resource and supported performance entries used to derive TTFB, transfer size, DOM readiness, observed LCP and long-task time when available.
- Rule-based scores, findings, evidence, recommended actions and report limitations derived from those signals.
Before a URL is retained in the report, NOISE removes query parameters, fragments and embedded username/password information. URL parameters may be processed momentarily in the active page as part of the requested scan; they are not retained in the saved report.
Local storage and retention
NOISE stores only the latest structured report in chrome.storage.local so the popup and full-report screen can display it. The retained report contains the sanitized page URL, page title, scan time, aggregate counts and derived performance values, scores, issue evidence, recommendations and limitations. Raw description, heading text and social metadata are used only during the scan and are not retained. A new scan replaces the previous report.
You can delete the saved report at any time by selecting Delete local report in the full-report screen. Chrome also removes the extension’s local storage when the extension is uninstalled, subject to Chrome’s behavior.
Information not intentionally read or retained
NOISE does not intentionally read or store passwords, cookies, authentication tokens, form values, full source HTML or the page’s full visible text. It does not access Chrome’s History API, monitor tabs in the background or retain a list of browsing history. It does not create a user account or collect contact, health, financial, payment, authentication or precise-location information.
Because a webpage’s title, metadata or headings can contain information chosen by that webpage, scan private or authenticated pages only when you understand that selected metadata and derived findings will be kept locally in the latest report.
Chrome permissions
NOISE does not execute remotely hosted code.
Purpose and Limited Use
Website content, web browsing activity and supported browser-performance activity are handled only to provide the visible, user-requested page-analysis feature. They are not used for unrelated purposes, advertising, behavioral profiling, credit decisions or lending.
NAVINES NOISE’s use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Security
Keeping the report on the user’s device limits exposure, but no local storage mechanism is guaranteed to be immune from access by the device owner, browser profile, malware or other software with appropriate access. Protect your Chrome profile and device and avoid scanning sensitive pages unnecessarily.
Chrome extension limitations
NOISE is a browser snapshot, not a full-site crawler, security audit or accessibility certification. It has no Search Console, analytics, backlink, server-log, server-configuration or CrUX field data. Its scores are internal heuristics and are not Google ranking scores. The separate MCP can read authorized Search Console data but does not change a website, Search Console property or Google account.
Changes
If either product changes the data handled, this policy and the relevant product disclosures will be updated before that processing begins, and any required user notice or consent will be obtained.
Contact
Questions or privacy requests: hello@navines.com
NAVINES ISRAEL LTD