Last updated: 18 August 2026
ORION connects to Google in two separate, independent ways. Each asks for different permissions, and you only ever grant the ones for the features you actually turn on.
ORION is operated by Avishalom Chen (אבישלום חן), in Israel, who is the controller of the data described in this policy.
| Operator | Avishalom Chen (אבישלום חן) |
|---|---|
| Legal form | Individual — not a registered business or company |
| Country | Israel |
| Contact | 1800beitel@gmail.com |
ORION is used by owners of business websites.
ORION uses two distinct Google applications. Connecting one does not connect the other, and each shows you its own consent screen listing exactly what it asks for.
This is the connection used to measure how your site performs in Google Search. It is read-only.
| Scope | Access | Why |
|---|---|---|
openid, email, profile | Read | To know which account authorised the connection and show it back to you |
webmasters.readonly | Read | Search Console queries, impressions, clicks, average position, and URL indexing status for properties you own |
analytics.readonly | Read | Google Analytics 4 reports for the same site |
This connection cannot change, delete, send or publish anything. It never asks for Gmail, Drive, Calendar, Contacts or YouTube.
Separately, ORION offers integrations that act on your Google Workspace data. These are optional. You are only asked for them if you enable the corresponding feature, and only the permissions that feature needs.
| Feature you enable | Access | What it does |
|---|---|---|
| Gmail | Read and write | Read messages, and compose or send mail on your behalf when a feature you configured does so |
| Google Calendar | Read and write | Read availability and create or update events |
| Google Sheets & Drive | Read and write | Read and write spreadsheets, and create files ORION itself produces |
| Google Drive metadata | Read | List files to let you choose one |
| YouTube | Read | Read channel and video data |
| Google Business Profile | Read and write | Read locations, reviews and performance; publish posts you approve |
| Merchant Center (not currently enabled) | Read and write | Product review status and product feed. This integration is being migrated to Google’s Merchant API and is not offered to customers today. |
ORION does not request access to your Google Contacts. Google Ads is a separate, optional integration with its own consent. It is not part of the Growth & Measurement connection, and advertising actions are performed only if you explicitly enable and configure that feature.
A measurement-only connection should never ask for Gmail, Drive or Calendar. If you are connecting ORION for search and analytics reporting and the consent screen asks for those, do not approve it and contact us. When you deliberately enable a Workspace feature, the wider permissions above are expected.
One ORION feature sends Google-derived data to an AI provider. We would rather name it precisely than hide it behind the word “infrastructure”.
| Feature | Provider | What is sent |
|---|---|---|
| SEO remediation — deciding which safe fix to apply to a page and writing the text for it | OpenAI | Search Console metrics for the page (impressions, click-through rate, the search term it competes on), Google Analytics 4 ecommerce counts (product views, add-to-cart, purchases), the page URL, title and an excerpt of its visible text, and your business details |
ORION's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect either connection at any time, from inside ORION or from your Google account permissions page. Either way access stops immediately and the stored credential is destroyed: disconnecting in ORION deletes the whole connection, and revoking at Google causes ORION to delete the credential the next time it tries to use it. To have stored measurement history deleted as well, email us and we will delete it.
Measurement history is kept while the connection is active and is deleted on request. Credentials are destroyed when a connection is disconnected or revoked, as described above.
If this policy changes materially, the updated date above changes and connected customers are notified.