This is an English translation provided for convenience. If there is any inconsistency, the Turkish version prevails.
Here you'll find what happens when you connect your account, which permission we ask for and what we cannot do. Every claim is backed up in the evidence table at the end of the page.
We don't scrape your page. We connect through Google's own interface, using the access permission set up for our app.
We have no write permission on any channel. We can't post, we can't reply, and we can't change settings.
You can remove the connection with one click in the dashboard; you can also revoke it from your Google account's permissions screen.
The connection is set up with an authorization method called OAuth.
When you click connect, you're redirected to Google's own sign-in screen. You type your password directly into Google, not into our site — we never see that screen. Once Google confirms that you've granted permission, it gives us a limited key instead of your password. That key opens only the door you've authorized, and it stops working the moment you revoke it.
So the answer to "Can Sosyal Karne see my password?" is, technically, no: your password never enters our system at any stage.
Access to the Google Business Profile API is not open to everyone; it requires going through Google's access application process.
Sosyal Karne connects to this API after going through Google's access application process, and our app was assigned a quota of 300 requests per minute. Google also verified the brand information shown on our consent screen (name, logo, domain, privacy and terms links). In practice, this means you won't see an "unverified app" warning when you connect.
We ask for a single permission:
The word "manage" in the name is Google's own naming; write operations may also be possible under this scope. We don't perform any — every data request our app sends to Google is a read (GET) request. The only exception is the call to Google's token endpoint to renew the key itself; that is a session operation, not a data request.
We process the data we receive from Google in accordance with Google's API Services User Data Policy, including its Limited Use requirements. The details are set out in section 7.1 of our Privacy Policy.
The connection is set up through Meta's official permission screen; here, too, your password is never passed to us.
No connection needed. We view the public pages of your site the way any visitor would. For speed and technical measurements we use Google's public PageSpeed Insights service. We don't ask for your admin panel password, server access or FTP details.
We don't connect to your ad account. The assessment is based on the agency report or screenshot you upload to the dashboard. If you don't upload any document, the channel is assessed as "ad readiness" based on the existing website and Instagram findings.
We ask AI models about your business name and assess the answers they return. No private data belonging to you is used in this step; it works only with publicly available information.
Connection keys are stored encrypted in the database (AES-256-GCM). The encryption key is kept in the server configuration, not in the database. All traffic between the site and your browser is protected with HTTPS.
We don't sell your data to third parties for advertising purposes. We use two external service providers to run the service: our hosting provider, located in Turkey, and the AI service used for content analysis. Both process only the data the service requires.
You can remove the connection after your report card is prepared; you keep the report. If you want your account deleted entirely, follow the steps on the Data Deletion Instructions page.
One is on our side; the other is entirely under your control.
On the Dashboard → Integrations screen, use the remove option next to the connected account. The key is deleted immediately.
You can revoke our access directly under Google Account → Security → Third-party apps. You don't need our approval.
The facts behind the badge on our home page.
| Claim | Basis |
|---|---|
| Official Google API access | We connect to the Google Business Profile API after going through Google's access application process; the app was assigned a quota of 300 requests per minute. |
| Our brand information is verified | The brand verification status shows as complete in the Google console; our name, logo and legal links are displayed on the consent screen after this verification. |
| Consent screen without warnings | The app is in production mode and public; users do not see an "unverified app" screen. |
| Read-only permission | All data requests sent to Google are GET requests. The only POST call goes to Google's token endpoint to renew the session key, not to access data. |
| A single scope | The only permission requested from Google is business.manage. No Gmail, Drive, Calendar or ad account scopes are requested. |
| Your password is never requested | The connection is set up with OAuth; the password is entered directly into Google and never reaches our system at any stage. |
| Remove it any time | The connection can be deleted from the dashboard; it can also be revoked independently of us from the third-party apps screen of your Google account. |
Note: Because our app does not request sensitive or restricted scopes, Google did not require a separate OAuth verification process. The statements on this page describe only API access and brand verification; they do not mean that Google supports, recommends or partners with Sosyal Karne.
Ask us anything about data access; we'll answer with the technical details.