This is an English translation provided for convenience. If there is any inconsistency, the Turkish version prevails.

Data Access

How we access your data, explained line by line.

Here you'll find what happens when you connect your account, which permission we ask for and what we cannot do. Every claim is backed up in the evidence table at the end of the page.

In three sentences

The short answer

Through the official API

We don't scrape your page. We connect through Google's own interface, using the access permission set up for our app.

Read-only

We have no write permission on any channel. We can't post, we can't reply, and we can't change settings.

You're in control

You can remove the connection with one click in the dashboard; you can also revoke it from your Google account's permissions screen.

Password

We never ask for your password

The connection is set up with an authorization method called OAuth.

When you click connect, you're redirected to Google's own sign-in screen. You type your password directly into Google, not into our site — we never see that screen. Once Google confirms that you've granted permission, it gives us a limited key instead of your password. That key opens only the door you've authorized, and it stops working the moment you revoke it.

So the answer to "Can Sosyal Karne see my password?" is, technically, no: your password never enters our system at any stage.

Google Business Profile

On the Google side

Access to the Google Business Profile API is not open to everyone; it requires going through Google's access application process.

Sosyal Karne connects to this API after going through Google's access application process, and our app was assigned a quota of 300 requests per minute. Google also verified the brand information shown on our consent screen (name, logo, domain, privacy and terms links). In practice, this means you won't see an "unverified app" warning when you connect.

We ask for a single permission:

https://www.googleapis.com/auth/business.manage

The word "manage" in the name is Google's own naming; write operations may also be possible under this scope. We don't perform any — every data request our app sends to Google is a read (GET) request. The only exception is the call to Google's token endpoint to renew the key itself; that is a session operation, not a data request.

What we read from Google

  • Business name, category, address, phone, website, opening hours
  • Profile completeness and verification status
  • Search and Maps visibility metrics
  • Direction requests, calls and website clicks
  • Reviews, average rating, review response rate
  • Uploaded photos and business posts

What we cannot do

  • We cannot change your business information
  • We cannot reply to or delete reviews
  • We cannot publish posts or photos
  • We cannot update your opening hours or address
  • We cannot create ad campaigns or spend budget
  • We cannot access your other Google services such as Gmail, Drive or Calendar

We process the data we receive from Google in accordance with Google's API Services User Data Policy, including its Limited Use requirements. The details are set out in section 7.1 of our Privacy Policy.

Instagram

On the Instagram side

The connection is set up through Meta's official permission screen; here, too, your password is never passed to us.

What we read

  • Username, bio, website link, profile photo
  • Follower count and post count
  • Date, type, caption and image of posts
  • Likes and comments per post
  • Reach and impressions per post

What we don't access

  • Stories and Reels performance data
  • Your direct messages
  • Your follower list — we don't see who follows you
  • Follower demographics (age, gender, location breakdown)
  • Permission to post, comment or send messages
Other channels

Website, ads and AI visibility

Website

No connection needed. We view the public pages of your site the way any visitor would. For speed and technical measurements we use Google's public PageSpeed Insights service. We don't ask for your admin panel password, server access or FTP details.

Ad performance

We don't connect to your ad account. The assessment is based on the agency report or screenshot you upload to the dashboard. If you don't upload any document, the channel is assessed as "ad readiness" based on the existing website and Instagram findings.

AI visibility

We ask AI models about your business name and assess the answers they return. No private data belonging to you is used in this step; it works only with publicly available information.

Storage and security

Where the data is kept

Connection keys are stored encrypted in the database (AES-256-GCM). The encryption key is kept in the server configuration, not in the database. All traffic between the site and your browser is protected with HTTPS.

We don't sell your data to third parties for advertising purposes. We use two external service providers to run the service: our hosting provider, located in Turkey, and the AI service used for content analysis. Both process only the data the service requires.

You can remove the connection after your report card is prepared; you keep the report. If you want your account deleted entirely, follow the steps on the Data Deletion Instructions page.

Removing the connection

You can revoke access in two separate ways

One is on our side; the other is entirely under your control.

1

From the dashboard

On the Dashboard → Integrations screen, use the remove option next to the connected account. The key is deleted immediately.

2

From your Google account

You can revoke our access directly under Google Account → Security → Third-party apps. You don't need our approval.

Evidence

What each claim is based on

The facts behind the badge on our home page.

ClaimBasis
Official Google API accessWe connect to the Google Business Profile API after going through Google's access application process; the app was assigned a quota of 300 requests per minute.
Our brand information is verifiedThe brand verification status shows as complete in the Google console; our name, logo and legal links are displayed on the consent screen after this verification.
Consent screen without warningsThe app is in production mode and public; users do not see an "unverified app" screen.
Read-only permissionAll data requests sent to Google are GET requests. The only POST call goes to Google's token endpoint to renew the session key, not to access data.
A single scopeThe only permission requested from Google is business.manage. No Gmail, Drive, Calendar or ad account scopes are requested.
Your password is never requestedThe connection is set up with OAuth; the password is entered directly into Google and never reaches our system at any stage.
Remove it any timeThe connection can be deleted from the dashboard; it can also be revoked independently of us from the third-party apps screen of your Google account.

Note: Because our app does not request sensitive or restricted scopes, Google did not require a separate OAuth verification process. The statements on this page describe only API access and brand verification; they do not mean that Google supports, recommends or partners with Sosyal Karne.

Have a question?

Ask us anything about data access; we'll answer with the technical details.