You do not need a Numic account. Numic uses Apple’s iCloud to sync between your devices and a small authentication service to connect to Bing. There are no advertising, third-party analytics, or third-party crash-reporting SDKs in the app.
We do not sell your personal information or use your search data for advertising. You choose which accounts to connect and which optional features to use.
1. Who we are
Numic is operated by Matias Tonning in Norway (“we”, “us”). Matias Tonning is the controller responsible for the personal information processed to provide Numic. Contact us at support@numic.app.
This policy covers Numic for iOS, iPadOS, and macOS, its Bing authentication service, the numic.app website, and support communications. Google, Microsoft, and Apple also process information under their own policies when you use their accounts and services.
Features can differ by app version, device, and availability. The sections on sync and optional Advisor processing apply when you use those features. Visiting this website does not connect a Google or Bing account.
2. Connected accounts
Connecting Google Search Console or Bing Webmaster Tools lets Numic access the sites and data you authorize. This includes site addresses, search queries, page URLs, clicks, impressions, search positions, country and device breakdowns, indexing results, and sitemap information. Queries and URLs can contain personal or confidential information. Numic uses this data to display reports, inspect pages, provide widgets, and run the features you choose.
You sign in with the provider. Numic does not receive your Google or Microsoft password. It receives authorization tokens that let it make permitted requests. Additional management permissions are requested separately for actions such as submitting sitemaps or URLs; reporting alone does not require those permissions.
Numic connects directly from your device to Google’s APIs. It receives a Google account identifier and, when supplied, your email address to identify the connected account. Google authorization credentials are kept in Apple Keychain, with sync described below. They are not sent to Numic’s Bing service.
The Google permissions used by Numic are openid and email to identify your connected account, and webmasters.readonly to read Search Console properties, performance, sitemaps, and inspection results. If you choose site management, Numic instead requests webmasters access so it can carry out supported changes you request, such as adding a property or submitting a sitemap. Numic does not request access to your Gmail messages, Google Drive files, contacts, or calendars.
Google data is used to provide your reports, comparisons, widgets, inspections, exports, and enabled Advisor features. Search data and derived results can be shared with Apple for the sync or cloud AI features described below. They are not sent to our website host or Bing authentication service. If you send a report or screenshot to support, that copy is handled as support email.
Numic’s use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. This also applies to information derived from Google data. We do not sell this data, use it for advertising or credit decisions, or use it to train general-purpose AI models. We do not read your Google data unless you agree to share specific data for support, access is needed to investigate a security issue, or the law requires it. Any disclosure must also satisfy Google’s Limited Use requirements.
Bing
Bing sign-in and token renewal use our authentication service at auth.numic.app, hosted by Cloudflare. The service stores encrypted access and refresh tokens, the permission scope, a random connection identifier, and security information needed to protect the connection. It does not store your search reports. Your device requests those directly from Bing.
The service receives normal network information, including your IP address, and uses a keyed hash of the IP address to limit abusive requests. Temporary sign-in cookies protect the OAuth flow; they expire after ten minutes and are not used for tracking. Application request logging is disabled on the authentication service. Cloudflare still processes network and security data to operate its infrastructure.
3. Your devices and iCloud
Numic stores report caches, settings, saved inspections, and Advisor results on your devices. Its widgets read the information they need from storage shared with the app on that device.
When you use cross-device sync, Numic uses a private CloudKit database in your Apple iCloud account. Synced information includes connection metadata, preferred sites, preferences, saved inspection history, and Advisor reviews and their supporting evidence. This can include site addresses, page URLs, and search queries. Disposable report caches and device-specific window and widget settings stay local.
Where connected accounts sync between devices, their credentials use iCloud Keychain separately. They are not placed in ordinary CloudKit records. Apple’s services and your iCloud settings govern how synced information is protected and made available to your devices. CloudKit records do not necessarily have the same end-to-end encryption protections as iCloud Keychain.
4. Advisor
Advisor reviews the search data for sites you enable. Basic analysis runs on your device. If you enable AI reviews on a supported device when that feature is available, selected search metrics, queries, URLs, and relevant evidence are sent to Apple’s Private Cloud Compute to generate the review. Your provider passwords and authorization tokens are not included. These requests generate recommendations for you; we do not use them to train general-purpose AI models.
Public-page reading is a separate setting shown during Advisor setup. When enabled, Numic can fetch public pages from the site being reviewed and extract text such as titles, headings, and excerpts. Relevant excerpts can be included in an AI review. Numic does not sign in to those pages or send your Google or Bing credentials to them.
If automatic reviews are enabled, Numic can run further reviews when you use the app without a separate request each time. You can turn off Advisor, automatic reviews, or public-page reading in Advisor settings.
Saved reviews and supporting evidence are stored with your app data and can sync through iCloud. You can turn off optional reviews and page reading. Turning them off stops future processing; it does not itself remove reviews already saved. Advisor offers suggestions for you to assess and does not make decisions with legal or similarly significant effects about you.
5. This website
The Numic website is hosted by Vercel. When you visit, Vercel processes technical request information, such as your IP address, requested URL, time of access, browser information, and referring page when your browser supplies it. This is used to deliver the website, diagnose failures, and protect it from abuse.
We do not use Vercel Web Analytics, Speed Insights, advertising pixels, or other website analytics. We do not place analytics or advertising cookies. Essential infrastructure or security cookies, if required by the hosting service, are used only for those purposes. The temporary cookies used for Bing sign-in are described in section 2.
The interactive preview uses sample data. It does not connect to your search accounts or send what you enter in its controls to Google, Bing, or a Numic reporting server.
6. Other information
Public web requests. Features such as sitemap checks, site icons, and public-page reading contact the relevant website. Its server receives your IP address and the requested URL. Core Web Vitals lookups send the page or site address to Google’s Chrome UX Report service.
Purchases. Apple handles purchases through the App Store. We do not receive your payment card details. Apple provides purchase, entitlement, or sales information where needed to deliver purchases and administer the app.
Diagnostics. Numic does not include third-party analytics or crash-reporting SDKs. Apple may provide app usage or crash information according to your Apple privacy settings and its developer reporting services.
Support. We use Google Workspace to host support@numic.app. If you email us, we receive your email address, message, and any attachments you choose to send. We use them to respond and resolve the issue. Please avoid sending passwords, tokens, or unnecessary personal information.
8. How long data is kept
- On-device and iCloud data: kept while needed for your saved settings, connections, and history, until you delete it or it is replaced or removed by the app’s cache and history limits. iCloud copies and device backups are subject to your Apple settings and Apple’s retention processes.
- Bing connection credentials: kept while the connection is active. A connection expires after 90 days without a successful renewal through the authentication service. A completed service-side deletion removes its tokens from active storage. A random identifier and hashed credential can remain for up to 90 days to safely handle deletion retries.
- Temporary authentication data: sign-in state expires after ten minutes, completion tickets after two minutes, and encrypted completion-retry data after ten minutes. Rate-limit records expire after ten minutes without an accepted update. Expired records are scheduled for automatic cleanup.
- Recovery copies: Cloudflare’s storage recovery history can retain copies of deleted authentication data for up to 30 days. These are separate from active service storage.
- Support emails: routine conversations and their attachments are deleted within 12 months after the issue is resolved. Information needed for a legal obligation or an active dispute is retained for that purpose and deleted when it is no longer needed. The email provider’s backup and recovery periods can continue after deletion from the mailbox.
- Hosting and security records: Vercel and Cloudflare retain infrastructure records according to their service settings and published retention criteria, including operating and securing their services, meeting legal obligations, and resolving incidents. We do not maintain a separate website visitor database or use these records for advertising.
We use Apple Keychain, encrypted storage for Bing tokens, and encrypted network connections to protect information. No storage or transmission method can guarantee absolute security.
9. Your choices
Stop Google access. Remove the connection in Numic’s connected-account settings. You can also open your Google Account’s third-party connections, select Numic, and remove its access. Google provides instructions for managing app connections. Removing access stops future authorized requests; it does not automatically erase reports and history already saved on your devices or in iCloud.
Stop Bing access. Remove the connection in Numic and revoke Numic separately in Bing Webmaster Tools. Removing a Bing connection from our service does not itself revoke Microsoft’s underlying authorization. If a removal cannot reach our service, it remains pending until a retry succeeds or the connection expires.
Remove saved information. Use Numic’s controls for clearing report caches, inspection history, and Advisor history. These are separate types of saved data; clearing a report cache does not clear Advisor history. Removing a connection on one device should not be treated as confirmation that every synced copy has been erased. Manage Numic’s access to iCloud and its stored iCloud data through your Apple settings.
Turning off sync or uninstalling the app does not necessarily delete existing iCloud data, Keychain items, backups, or data on other devices. Deletion changes can take time to reach an offline device. Removing data from Numic does not remove the original reports held by Google or Bing, or copies you have exported.
For help removing saved or synced information, or deleting data held by the authentication service, contact support@numic.app. We can help with the steps for data on your devices or in your iCloud account; we cannot simply access those private stores from a support console.
10. Your privacy rights
As a Norwegian operator, we process personal information under the GDPR and Norway’s Personal Data Act. Our legal bases are:
- Providing the service you request (Article 6(1)(b)): account connections, reports, widgets, requested management actions, and sync.
- Consent (Article 6(1)(a)): optional cloud AI reviews and public-page reading. You can withdraw consent in the app, without affecting processing that already took place lawfully. OAuth permission also limits which provider data we can access; it is not blanket consent to unrelated uses.
- Legitimate interests (Article 6(1)(f)): serving and securing the website and authentication service, preventing abuse, and responding to support requests. We limit processing to what is needed and balance these interests against your rights.
- Legal obligations (Article 6(1)(c)): records and disclosures required by applicable law.
Providing connected-account data is optional, but reports for your sites cannot work without it. You can use the demo without connecting an account and use basic reporting without enabling cloud AI or public-page reading.
Depending on applicable law, you may request access, correction, deletion, restriction, or a portable copy of your personal information, and object to processing based on legitimate interests. Email support@numic.app to make a request. We may need limited information to verify the request and normally respond within one month, without charging a fee. If the law permits extra time because of the complexity or number of requests, we will explain the reason within that first month. Rights can be subject to legal exceptions, which we will explain if relevant to your request.
You can complain to Norway’s data protection authority, Datatilsynet, or to the authority where you live or work in the EEA, or where you believe an infringement occurred. You do not have to contact us before contacting an authority.
Numic is a tool for people managing websites and is not directed at children. If you believe a child has provided personal information to us, please contact us so we can address it.
11. Changes and contact
We will update this page when Numic’s data practices change and revise the date above. For material changes, we will provide an appropriate notice in the app or before the affected feature is used, and seek consent where required.
Privacy questions and requests can be sent to Matias Tonning at support@numic.app.