Freshwake

Privacy Policy

Last updated: 19 September 2026

This policy covers the Freshwake WordPress plugin, the Freshwake Pro add-on, the backend service at api.getfreshwake.com, and this website. It is written by Platemark, the sole operator of all of them.

The short version.

  • Your Google Search Console data never reaches our servers. The plugin reads it directly from Google and stores it in your own WordPress database.
  • We do not sell data, do not use it for advertising, and do not use it to train machine learning models.
  • This website sets no cookies, runs no analytics, and loads nothing from third parties.

1. Who we are

Platemark, based in Japan. You can reach us at ggg.billy@gmail.com for any question about this policy, including requests to delete data we hold.

2. Google user data

Freshwake requests exactly one Google OAuth scope:

https://www.googleapis.com/auth/webmasters.readonly — read-only access to your Google Search Console data.

We request no other scope. The plugin cannot modify anything in your Search Console account.

How that data is accessed

The plugin runs on your own WordPress server and calls the Search Console API directly from there. It retrieves, for each URL on your site, the clicks, impressions, click-through rate and average position reported by Search Console.

How it is used

To calculate the freshness and rewrite-priority scores, and to draw the charts and lists you see in your WordPress admin area. That is its only purpose.

Where it is stored

In your own WordPress database, in tables the plugin creates. It is not copied to our servers, and it is not sent anywhere else. We have no access to your Search Console data at any point — not in transit, not at rest, and not in support situations.

It does not ask Google for search-query data at all. Search queries can contain personal information, so the plugin requests only page-level figures. The safest way to handle that data is not to receive it.

How it is shared

It is not. The only party your Search Console data travels between is Google and your own server.

3. Limited Use

Freshwake's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we do not:

4. What our backend does receive

The backend at api.getfreshwake.com exists for three narrow reasons: completing the Google sign-in exchange, validating Pro licenses, and delivering Pro updates. Here is everything it touches.

DataWhyHow long
OAuth state value and authorization code To complete the Google sign-in and exchange the code for tokens Seconds. Deleted when used, and expired automatically if unused
Access and refresh tokens Passed straight back to your site after the exchange Never written to our database
Site identifier and a shared secret So we can tell that a request genuinely comes from your installation Until you ask us to delete it (see section 7)
Your WordPress admin URL To send your browser back to the right site after you approve access at Google Until you ask us to delete it (see section 7)
Pro license key, order reference and activated sites To enforce the number of sites a license covers and to deliver updates While the license is active, and afterwards as long as Japanese tax law requires us to keep accounting records

Your Google tokens are stored encrypted in your own WordPress database, using a key derived from your site's AUTH_KEY. They are not stored on our servers.

5. This website

These pages are static files. They set no cookies, include no analytics, and load no fonts, scripts or images from third parties. Our hosting provider keeps ordinary server access logs, which may include IP addresses, for security and operational purposes.

6. Payments

Freshwake Pro is sold through a third-party payment provider. Your card details go to that provider directly and are never seen or stored by us. We receive the order record and the license it corresponds to. The provider is identified on the checkout page and has its own privacy policy.

7. Keeping and deleting data

Data on your own site

The metric history, scores and tokens all live in your WordPress database and are yours. The plugin settings include an option to delete its tables when you uninstall it; the default is to keep them, so that reinstalling does not lose your history.

Your Google tokens and the secret that identifies your site to us are always removed when you uninstall, and the token is revoked at Google, whether or not you choose to delete the stored history.

Revoking access

You can disconnect Freshwake from Google at any time inside the plugin, or revoke it from your Google Account at myaccount.google.com/permissions. Either action stops all further access immediately.

Data on our backend

Disconnecting revokes your tokens, but at present it does not automatically delete the site identifier, shared secret and admin URL described in section 4. We are stating this plainly rather than implying a deletion that does not happen. Automatic deletion on disconnect is planned.

In the meantime, email ggg.billy@gmail.com and we will delete those records. We aim to respond within 30 days. Records tied to a paid license may need to be retained for accounting purposes; we will say so if that applies.

8. Where data is processed

Our backend runs on Google Cloud. The limited data described in section 4 may be processed outside your own country. Your Search Console data is not affected by this, because it never leaves your server.

9. Children

Freshwake is a tool for website operators and is not directed at children under 16. We do not knowingly collect data from them.

10. Changes to this policy

If we change this policy we will update the date at the top of this page. If a change materially affects how your data is handled, we will also note it in the plugin's changelog on WordPress.org.

11. Contact

Platemark, Japan — ggg.billy@gmail.com