Every page request receives the first-party browser identifier described above. A database user is created when that browser starts its first valid username or email task. The user record stores the cookie identifier, site language, Cloudflare country value, Accept-Language value, and created/updated timestamps.
A history task stores the raw query, scan type, task identifier, completion state, normalized result records, simplified site names, visitor IP, created/updated timestamps, and—when those paths run—public-web results and AI status, errors, duration, search output, and summary output.
History is available to the current browser identifier; Google login is not required. Anyone with access to the same browser profile may therefore be able to view its username and email history. IP lookups are not displayed in this history interface.
If you connect Google, the OAuth request asks for openid, email, and profile. The returned Google subject identifier, name, email address, and profile-image URL are stored with the user record. The Google password is entered with Google, not SpiderFoot.tools, and the access token used to request profile data is not written to the user table by this code.