Privacy Policy
First Page GA4 MCP · Last updated 28 July 2026
First Page GA4 MCP (“the application”) is an internal tool operated by First Page for its own staff. It lets authorised First Page employees read Google Analytics 4 reporting data for accounts that First Page already manages, so that analysis can be performed in the tools the team uses day to day. The application is not offered to the public and does not have external end users.
Who we are
The application is operated by First Page. For any question about this policy or about data held by the application, contact tools@firstpage.com.au.
Google user data we access
The application requests a single Google API scope:
https://www.googleapis.com/auth/analytics.readonly
This scope is read-only. Using it, the application reads: the list of Google Analytics accounts and properties an authorised account can see (property names, IDs, timezone, currency and data streams), and aggregated Analytics reporting data such as sessions, users, engagement, key events, revenue and the dimensions those metrics are broken down by.
During sign-in the application also reads the account’s email address, name and profile picture (openid, email, profile) purely to label the connection in the interface and to restrict administrative access to First Page staff.
Why we need it
First Page manages Google Analytics properties on behalf of its clients. Access to those properties is spread across a number of Google accounts. The application connects each of those accounts once, remembers which properties each can see, and uses that to answer reporting questions from staff without anyone having to log in to the Analytics interface property by property.
The read-only scope is the narrowest scope that permits this. No scope granting write, configuration or user-management access is requested, and the application contains no code capable of modifying an Analytics property.
How we store and protect it
When an account is connected, Google issues a refresh token. That token is encrypted with AES-256-GCM before it is written to storage, and is decrypted only in memory at the moment an Analytics API request is made. Encryption keys are held in Google Secret Manager and in the hosting provider’s encrypted environment store, separately from the tokens themselves.
Tokens and the property index are stored in Google Cloud Firestore in the australia-southeast1 region. Administrative access to the application requires signing in with a First Page Google Workspace account; accounts outside that domain are rejected.
Analytics reporting data itself is not retained. It is fetched from Google on demand, returned to the requesting staff member, and not written to any database by the application.
What we do not do
- We do not sell, rent or trade Google user data.
- We do not transfer it to third parties, other than the Google APIs it came from and the cloud infrastructure described above.
- We do not use it for advertising, or to build profiles of individuals.
- We do not use it to train, or to improve, generalised artificial intelligence or machine learning models.
- We do not allow humans to read it except the First Page staff member who requested the specific report.
The application’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and removal
A connected account’s refresh token is retained until the connection is removed. Removing a connection in the application revokes the token with Google and deletes the stored token and property index immediately.
The owner of any connected Google account can also revoke access at any time at myaccount.google.com/permissions, which immediately ends the application’s ability to read that account’s data.
Changes
If this policy changes, the revised version will be published at this address with an updated date above.
First Page · Australia · Singapore · Hong Kong · tools@firstpage.com.au