Privacy Policy
This policy covers dgtlsunrise.com, the Grok Bot plugin, the Muse connector, and related consulting work. It is written for people and for Google's OAuth verification of the Grok Bot plugin and the Muse connector.
What the plugin is
The Grok Bot plugin runs locally on the user's Grok Bot computer. You connect Google accounts you already own so the agent can read and manage Google Analytics, Search Console, and Tag Manager in that session. OAuth tokens for the Grok Bot plugin stay on that computer. Connect Google once with all Free permissions up front. Live edits need your confirmation. The Muse connector is a separate path. It stores an encrypted Google refresh token on DGTL servers, as disclosed under Muse connector.
Google user data we access
When you connect Google, the plugin can use the products you enable:
- Google Analytics (GA4) : read property, report, and configuration data you can already see in Analytics. Manage property settings the tools support (data streams, key events, custom definitions, and Measurement Protocol secrets where enabled).
- Google Search Console : read site and query performance for properties you verify. Submit or delete sitemaps after you confirm.
- Google Tag Manager : read container and tag configuration. Create or update tags, triggers, and variables, and publish, after you confirm.
- Google Business Profile : optional and feature-flagged. Read listing information you already administer, only if that flag is on.
- Google Ads : not in the free plugin. Paid DGTL subscription (Pro) for reads and confirm-gated changes through the gateway described below. Product page: /google-ads.
- Merchant Center : not in the free plugin. Pro-gated. Plugin-direct Google on your machine (not the Ads/Meta/TikTok Worker hop). Reads and confirm-gated product-input writes. Nothing goes live until you approve it.
We do not request Gmail, Drive, Calendar, or Contacts.
Limited Use. DGTL Sunrise's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve the user-facing features of the Grok Bot plugin and the Muse connector. Grok Bot plugin tokens stay on your computer. The Muse connector stores an encrypted Google refresh token on DGTL servers, as disclosed under Muse connector. We do not sell it. We do not use it for advertising. We do not transfer it to third parties except as needed to run a request you initiated or as required by law.
Where that data lives
Grok Bot plugin (GA4, Search Console, GTM, and flagged GBP). OAuth tokens for the Grok Bot plugin stay on your computer. Report bytes are fetched into the local Grok session so the model can answer you. Sunrise Consulting LLC does not receive those Grok Bot report bytes and does not store those report bytes on DGTL servers. When you connect Klaviyo, the private API key stays on your machine.
Muse connector. When you connect DGTL Sunrise to Muse, you sign in with Google on https://muse-api.dgtlsunrise.com. You grant read-only access to Google Analytics (analytics.readonly, https://www.googleapis.com/auth/analytics.readonly), plus your Google account ID and email (openid and userinfo.email, https://www.googleapis.com/auth/userinfo.email). We store the Google refresh token on DGTL servers, encrypted with AES-256-GCM (JOSE alg A256GCM). We keep the DGTL access token only as a one-way hash. We use the refresh token only to fetch the Analytics reports you ask Muse for, and we do not store those report bytes. One user's stored Muse refresh token is not available to another user's Muse session. A complete disconnect requires both steps: revoke DGTL Sunrise at Google Account permissions, and email contact@dgtlsunrise.com so we delete the stored refresh token. The Grok Bot plugin is unchanged. Its tokens stay on your computer.
Paid Google Ads, Meta Ads, and TikTok Ads (Pro). Those calls go through an allowlisted DGTL gateway. The gateway attaches the credentials needed to complete the request and returns the vendor response to your session. Live changes need confirmation. The gateway does not store the report bytes. Meta and TikTok are not Google APIs; they are listed here because the same paid plan covers them. Merchant Center (Pro) stays plugin-direct on your machine: OAuth tokens and report bytes do not use that gateway hop, but a Pro subscription is still required.
If we ever need to keep a credential so a paid connector can keep working, we will say so in this policy before that ships, and it will still be used only to serve your request.
How we protect Google user data
This section states how Google user data is protected on the Grok Bot plugin path, on the Muse connector path, on Pro-gated Merchant Center, and on the paid Ads, Meta, and TikTok gateway. Grok Bot plugin tokens stay on your computer. The Muse connector stores an encrypted Google refresh token on DGTL servers, as disclosed under Where that data lives.
- Least privilege. The free plugin can read and manage Google Analytics, Search Console, and Tag Manager after you connect Google. Live edits need confirmation. We do not request Gmail, Drive, Calendar, or Contacts.
- Local token custody (Grok Bot plugin). OAuth tokens for the Grok Bot plugin stay on your Grok Bot computer. Sunrise Consulting LLC does not receive those Grok Bot plugin tokens and does not store those plugin tokens on DGTL servers. The Muse connector stores an encrypted Google refresh token on DGTL servers, as disclosed under Muse connector.
- Transit. Google API calls and this marketing site use HTTPS/TLS.
- Access control (Grok Bot plugin). Only the signed-in Grok Bot session on that machine can use the Grok Bot plugin tokens. The Grok Bot plugin keeps those tokens on that computer. Muse connector refresh tokens are stored on DGTL servers, as disclosed under Muse connector.
- No DGTL persistence of Grok Bot report bytes. On the Grok Bot plugin path, report bytes stay in the local session. Those report bytes are not stored on DGTL servers.
- Paid gateway. Google Ads, Meta, and TikTok calls go through an allowlisted DGTL gateway that does not archive report bytes. Live changes need confirmation. Merchant Center Pro calls stay on your machine (plugin-direct). If we ever store a credential so a paid connector can keep working, we will disclose that here before it ships.
- Revocation. For the Grok Bot plugin, revoke access at Google Account permissions and delete the local plugin data on your machine. For the Muse connector, a complete disconnect requires both steps: revoke DGTL Sunrise at Google Account permissions, and email contact@dgtlsunrise.com so we delete the stored refresh token. Email contact@dgtlsunrise.com if you need us to check what, if anything, we hold from a consulting engagement or paid subscription.
- Limited Use. Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, as stated above.
What we collect on the website
The marketing site is static. If you email or call us, we keep that correspondence to reply and, if you hire us, to do the work. We do not run a public account system on this domain. Server logs from our host (Cloudflare) may include IP address, user agent, and the URL requested, for security and uptime.
Consulting engagements
If you hire Sunrise Consulting LLC, we process whatever you send us to do the job: briefs, access you grant, drafts, invoices. That material is held under the engagement, not mixed into the plugin's Google data. We do not use client consulting files to train public models.
Sharing
We do not sell personal information. We share data only with processors who host this site or, for paid Ads, Meta, and TikTok, the allowlisted gateway that completes your request; with Google, Meta, or TikTok when you authorize an API call; or if the law requires it.
Retention and your choices
Local Grok Bot plugin data lasts as long as you keep the local session and tokens on your computer. Revoke Grok Bot plugin access any time at Google Account permissions. Delete the local Grok / plugin data on your machine the same way you delete other local app data. For the Muse connector, the stored Google refresh token remains on DGTL servers until you complete both disconnect steps: revoke DGTL Sunrise at Google Account permissions, and email contact@dgtlsunrise.com so we delete the stored refresh token. Email contact@dgtlsunrise.com to ask what, if anything, we hold from a consulting engagement or a paid subscription, and we will delete it unless we are required to keep it.
Children
The plugin and this site are for business users. We do not knowingly collect data from children under 13.
Changes
If this policy changes in a material way, we will update this page and the effective date. The current version lives at https://www.dgtlsunrise.com/privacy.
Contact
Sunrise Consulting LLC (DGTL Sunrise)
2152 W Lima Pl, Coeur d'Alene, ID 83814
contact@dgtlsunrise.com
858.354.3666