Short version: we collect what you tell us and what you explicitly connect, we use it only to run the service you're paying for, and we never sell it or hand it to advertisers. If you connect Google Search Console, jump to Google user data: that section says exactly what we read and what we do with it.
Haazir is operated from India by the Haazir team. This policy covers haazir.dev, the free AI-visibility check, the customer dashboard, and the answer pages we publish on behalf of customers.
If you're just visiting or running the free check:
If you're a customer:
Analytics. We run our own lightweight, first-party enquiry tracker (haazir-track.js) on this site and, when a customer installs it, on theirs. It records an event type, the page path, the referring site, and a utm_source if one is present. It sets no cookies and collects no personal information. We do not use third-party analytics, advertising scripts, fingerprinting, or cross-site tracking of any kind.
Connecting Google Search Console is entirely optional. Nothing else in Haazir depends on it, and you can disconnect at any time. If you do connect it, here is precisely what happens.
The one scope we request: https://www.googleapis.com/auth/webmasters.readonly. It is read-only. It gives us no ability to change, submit, or delete anything in your Search Console account. We request no other Google scope: no email, no Drive, no contacts, no calendar.
Why we need it, and why nothing narrower works. Haazir tells you whether the pages we publish for you actually reached Google and what they earned. Only Search Console can answer that: it is the sole source of your real clicks, impressions and average position, and the only way to ask Google directly whether a specific page is indexed. Search Console offers no narrower read scope than webmasters.readonly, and public rank-checking tools cannot see your first-party performance data.
What we read:
What we store: your OAuth refresh token, encrypted at rest (AES-GCM); the identifier of the matched property; and the summaries we derive for your dashboard, such as index-health counts and your query performance. Access tokens are requested fresh for each call and are never written to disk.
What we never do with it. We do not sell it, rent it, or transfer it to anyone. We do not use it for advertising, ad targeting, or credit assessment. We do not use it to train AI or machine-learning models.
Who on our side can see it. Haazir is a done-for-you service, so our team does look at your results: that is the work you're paying for. Specifically: we review the summaries derived from your Search Console data (index status, performance trends) in our internal operations console to spot problems and act on them, and we read the underlying detail when you ask us for support, or where security or the law requires it. We do not read it for any other purpose.
Haazir's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How to disconnect. Press Disconnect in your dashboard: that deletes the stored token immediately. You can also revoke our access from your Google Account at myaccount.google.com/permissions. Either way, our access ends at once.
To run the service: to reply to your enquiry, to monitor whether AI assistants and Google surface your business, to write and publish answer pages for you, to show you your dashboard, and to bill you. We do not use your data to advertise to you, and we do not sell it: ever, to anyone.
We never sell or rent your data. We share it only with the service providers we need to operate Haazir, and only for that purpose:
We may also disclose information where the law requires it. If Haazir is ever acquired, we will tell you before your data moves.
Enquiries: for as long as we're talking, and a reasonable period after so we have context if you come back. Customer data: while your subscription is active, and after it ends we retain it so you can reactivate without starting over: we do not delete it on a fixed schedule, and you can ask us to erase it at any time (see Your rights). Billing records: as long as Indian tax law requires. Google Search Console tokens: until you disconnect, at which point they are deleted immediately.
Traffic is encrypted in transit (HTTPS). Long-lived credentials: including your Google refresh token: are encrypted at rest. Dashboard access is token-based, and administrative access is limited to the Haazir team.
Haazir is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.
You have the right to access, correct, or delete the personal information we hold about you, and to withdraw consent. To exercise any of these rights, email hello@haazir.dev from the email address you used. We'll respond within 7 working days.
Questions about this policy, or about what we hold on you? Email hello@haazir.dev.
Last updated 4 August 2026. It will be revised as the product grows; significant changes will be flagged on this page.