Privacy Policy
Last updated: 2026-09-30
This Privacy Policy explains how Shambix collects, uses, stores, shares, and deletes information for:
- Shambix Growth Console — the WordPress plugin (including Google OAuth “Connect with Google”)
- Shambix Growth Cloud — the prepaid credits portal and API at https://growthcloud.shambix.com/ (fallback https://sgc-portal.pages.dev/)
Contact: info@shambix.com · https://www.shambix.com/
1. Who we are
Shambix is the operator and developer of Shambix Growth Console and Shambix Growth Cloud. For privacy requests, email info@shambix.com.
2. Google user data (OAuth and Google APIs)
This section is specific to Google user data obtained through Google OAuth and Google APIs when a WordPress administrator uses Connect with Google in Shambix Growth Console Settings.
2.1 Types of Google user data we access
- Identity: Google account email (and related OpenID identity claims) to display which account is Connected in Settings
- Google Search Console: list of sites/properties the account can access; search analytics (queries, pages, clicks, impressions, countries, devices); URL Inspection results; sitemaps for the selected property
- Google Analytics 4: list of Analytics accounts/properties and web data stream default URIs (to match the WordPress site host); report metrics and dimensions for the selected property (for example sessions, channels, sources, landing pages, countries, events)
OAuth scopes requested are readonly: Search Console readonly, Google Analytics readonly, plus openid and email for the Connected label. We do not request scopes that write or change your Google properties, ads, Gmail, Drive, or Calendar.
2.2 How we use Google user data
- Only to provide and improve user-facing features of Shambix Growth Console on the customer’s WordPress installation: Connect / Disconnect, property pickers, connection Test, Refresh and scheduled refresh, dashboards, and optional Advisor tools that call the same readonly APIs
- To show the Connected Google account email in Settings and Help status
- We do not use Google user data to serve advertisements
- We do not sell Google user data
- We do not use Google user data for credit scoring or lending decisions
- We do not use Google user data to train generalized / non-personalized AI or ML models
- Optional Shambix Growth Cloud AI receives aggregated digests prepared on WordPress for profile/advice/Ask jobs. It does not receive Google OAuth refresh tokens
2.3 Storage of Google user data
- OAuth refresh tokens, Connected email, and selected Search Console / GA4 property identifiers are stored on the customer’s WordPress site (encrypted at rest in WordPress options)
- Short-lived Google access tokens may be cached briefly on that same WordPress site
- Dashboard-derived metrics derived from Google APIs may be stored as files under the WordPress uploads directory used by the plugin
- Shambix Growth Cloud servers do not store long-lived Google refresh tokens and do not run ongoing GSC/GA4 report jobs on behalf of the site
2.4 Sharing and transfer of Google user data
- Google: after Connect, Search Console and GA4 API calls are made from the customer’s WordPress server to Google
- Shambix Growth Cloud Worker: during the Connect redirect, Google sends a short-lived authorization code to our Worker so we can exchange it for tokens and return a sealed payload to WordPress. The Worker does not persist Google refresh tokens
- We do not sell Google user data or share it with data brokers, advertisers, or unrelated third parties
- We do not transfer Google user data to other apps except as needed to operate the features above (WordPress site ↔ Google; ephemeral code exchange on the Worker)
2.5 Protection of Google user data
- Encryption at rest on WordPress for stored Google credentials
- HTTPS/TLS in transit
- WordPress capability checks (
manage_options) and CSRF protections on Connect and Disconnect - Sealed one-time OAuth return payload (no plaintext refresh token in browser query strings intended for storage)
2.6 Retention and deletion of Google user data
- Google OAuth credentials remain while the site stays Connected
- Administrators can Disconnect in Settings: we attempt to revoke the Google token and clear local OAuth secrets and related caches
- Uninstalling the plugin deletes plugin settings and stored keys from that WordPress installation (including Google OAuth material held by the plugin)
- Derived dashboard files on that site are removed when the plugin uninstall wipe runs, or can be cleared by the site administrator
- For assistance with deletion: info@shambix.com
2.7 Google API Services User Data Policy (Limited Use)
Shambix’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, Google user data obtained via restricted/sensitive scopes is used only to provide or improve user-facing features that are prominent in Shambix Growth Console, is not sold, and is not used for serving advertisements, creditworthiness, or unrelated AI/ML training as prohibited by that policy.
3. Shambix Growth Cloud account data (portal and API)
Separate from Google OAuth, if you create a Growth Cloud account we process:
- Account: email address, password hash (not the plaintext password), optional Stripe customer identifiers
- Sites: home URL, label, API key hashes, credit balance, usage events (AI turns, purchases, transfers)
- AI jobs: request payloads needed to complete the job (for example digests prepared by WordPress), sent to our Worker and Anthropic when Cloud AI is used
- Payments: processed by Stripe; we store payment-related IDs and credit top-up amounts, not full card numbers
- Optional Trends: if you add DataForSEO credentials in the WordPress plugin, those stay on WordPress and are billed by DataForSEO (not Growth Cloud credits)
We process this data to provide accounts, authenticate site API keys, debit and transfer credits, process payments, prevent abuse, and operate the service.
4. Cookies and similar technologies
This Privacy Policy and the product homepage do not set cookies for reading. The credits portal may use cookies or local storage for signed-in session management. WordPress admin sessions are controlled by your WordPress installation.
5. Processors (Shambix Growth Cloud)
- Cloudflare (Workers / Pages hosting)
- Neon (database)
- Stripe (payments)
- Anthropic (AI completion when Cloud AI is used)
- Email delivery provider (optional; password-reset messages only)
- Google (OAuth authorization code exchange during Connect, and Google APIs when called from the customer’s WordPress site)
6. Retention (Growth Cloud accounts)
Account and usage records are kept while the account is active and for a reasonable period afterward for billing, security, and audit. You may request account closure by emailing info@shambix.com.
7. Your choices and rights
- In WordPress: Connect or Disconnect Google; change selected properties; uninstall the plugin
- In the portal: change password; create or rotate site API keys; move credits between your sites
- Request access to or deletion of Growth Cloud account data by emailing info@shambix.com
8. Children
Shambix Growth Console and Shambix Growth Cloud are intended for business / website operators. They are not directed to children under 16, and we do not knowingly collect Google user data from children.
9. Plugin Help
Additional notes about local WordPress storage appear in the plugin under Help → Data & privacy on your WordPress site.
10. Changes
We may update this Privacy Policy. The “Last updated” date above will change when we do. Material changes that affect Google user data handling will be reflected on this page and, where required, in the Google OAuth consent configuration.
11. Contact
info@shambix.com · shambix.com · Product home: Shambix Growth Console