Skip to content
PreferiumJoin the waitlist

Industry NewsSEO

Google's SerpApi lawsuit raises questions for reporting suppliers

Google amended its SerpApi complaint in August 2026. For agencies, the practical task is to understand where rank-tracking data comes from and how to retain report history.

A brass balance scale on a stone plinth above rows of filing shelves, one pan holding a tangle of wire, the other a small crowd of figures.
Jump to a section

A legal dispute involving a search-data supplier can matter to agencies even when their dashboards continue working. Google’s amended SerpApi complaint is a reason to understand the dependencies behind a report, not to assume that every rank tracker is about to fail.

Where rank-tracking data comes from

SERP just means search engine results page — what you see after you type something into Google. Scraping means having a program load that page automatically and pull out the useful parts: which sites are listed, in what order, which ones got quoted in an AI Overview, which ones paid for the ad slot.

A tool may use this kind of collection directly or buy the results from a supplier. When a rank tracker reports that a client moved from position 9 to position 6, nobody at that company typed the keyword by hand. A machine did, thousands of times a day, from many locations. The same plumbing sits under keyword databases, share-of-voice dashboards, competitor reports, and the newer tools that count how often a brand turns up in AI Overviews.

Some tools scrape for themselves. Plenty buy it wholesale. SerpApi is one of the larger wholesalers — it sells structured Google results through an API, which is just a way for one program to request data from another.

The dispute as reported in July and August 2026

Google announced the suit on 19 December 2025. Its version of events: SerpApi disguises its traffic, runs large networks of bots, gives its crawlers fake and shifting names, and resells material Google licenses from other people — images in Knowledge Panels, real-time data. Court filings, as reported by MediaPost, put the volume at hundreds of millions of automated searches a day and name Google’s anti-bot system SearchGuard.

The reported claims concern the DMCA’s anti-circumvention provisions and access to copyrighted material. That is a narrower question than whether collecting any public search result is lawful.

SerpApi moved to dismiss on 20 February 2026, arguing that a bot-detection system protects ad revenue rather than copyright, and that public information stays public: “We provide structured access to publicly available information,” the company wrote, pointing at the hiQ Labs v. LinkedIn line of cases.

On 20 July, Judge Yvonne Gonzalez Rogers in the Northern District of California dismissed parts of the complaint, according to Search Engine Land. Claims about results containing no copyrighted material were dismissed permanently. For results that do contain copyrighted material, the court found Google hadn’t shown that SearchGuard was put in place with the authority of the copyright owner — protecting someone else’s work on your own initiative isn’t the same as being asked to. Google held on to two things: it can bring a DMCA claim without owning the underlying content, and the court accepted that circumvention had been adequately alleged. It got 21 days to try again.

What changed on 10 August

Google refiled, in the same court, adding allegations about licensed content. The amended complaint goes straight at the gap the judge left: authority from the owner. Google now says its licensing partners expressly asked it to keep unauthorised parties away from their content, and it names Reddit — which licenses its content to Google — as having told Google not to let third parties extract and independently commercialise it. SerpApi’s counsel said the company is confident and will respond.

This is a smaller case than the one Google filed in December. It is also pointed at a specific slice of the results page: the licensed slice. Reddit threads, Knowledge Panel imagery, real-time feeds. If you have watched which sources AI Overviews lean on this year, you will recognise that list.

What agencies should actually do about it

The filing alone does not establish an interruption in your supplier’s service. Check the dependencies and the reporting process.

Find out where your data comes from. Ask each vendor in your stack, in writing, whether they scrape Google themselves or buy it. Many resell. A supplier-level ruling would hit several dashboards you think of as independent.

Export your history. Rank history is the one thing you cannot rebuild later. Keep periodic exports in a format you can read independently of the supplier, with dates, locations and query definitions attached.

Stop treating one API as a source of truth in client reporting. If a single vendor outage would leave a monthly report with a hole in it, that’s a reporting design problem regardless of how this case ends.

Separate measurement from the work. An outage in rank collection does not stop you checking the client’s own pages for access, content and technical issues.

Want this running under your brand?Preferium AI Edge is a white-label platform agencies resell to their clients: your brand, your Stripe, your packages and prices. Registration opens to agencies from the waitlist first.Talk to usJoin the waitlistHow white label works

Build your agency on Preferium

Partner registration opens by invitation from the waitlist, and there is no date yet. Read the agency agreement and how partner billing works before you decide.

  1. Connect a client site
  2. Set the control level
  3. Run under your brand

Privacy choices

Choose which optional technologies Preferium AS may use. All of them are off until you choose.

Analytics: Google Analytics 4 counts page views. Google may receive the page address, referrer, network address, browser and device details, and online identifiers. Browser storage: _ga, _ga_*: Up to 730 days. Renewed on activity. The browser may shorten the storage period.

Provider: Google Ireland Limited. Google may transfer data to the United States.

See the cookie notice, the privacy notice and theterms.

Necessary technologies Used for site functions

Preferium AS and Cloudflare deliver the site and protect forms against abuse. A local preference remembers if you pause animation. When optional tracking is available, the site can also remember your documented privacy choices.

Consent receipt
Provider: Preferium AS. HttpOnly receipt that documents and retrieves your consent choice. Name in the browser: __Host-preferium_consent. Storage period: The receipt is valid for up to 180 days without rolling renewal.
Local privacy choices and pending rejections
Provider: Preferium AS. Local storage of privacy choices and pending rejections. The entry alone can never allow optional technologies; a valid server receipt is required. Name in the browser: preferium-consent-v2. Storage period: Until the entry is overwritten or the browser site data is cleared. No automatic timed deletion is configured.
Privacy choice synchronization between tabs
Provider: Preferium AS. The latest message that synchronizes privacy choices and pending rejections between tabs. The message can only close optional technologies and trigger a new server check. Name in the browser: preferium-consent-sync-v1. Storage period: Until the entry is overwritten or the browser site data is cleared. No automatic timed deletion is configured.
Motion pause preference
Provider: Preferium AS. Session storage restores the requested accessibility preference between pages in this tab. Nothing is sent to a server. Name in the browser: preferium-motion-paused. Storage period: Until this browser tab session ends.
Cloudflare Turnstile
Provider: Cloudflare. Abuse protection that loads only on forms where Turnstile is necessary. Storage period: Short-lived control value tied to a form submission.
Analytics

Helps us understand how the site is used, when you consent.

Provider: Google Ireland Limited. The data may include the page address, referrer, network address, browser/device, online identifiers and usage events.

_ga, _ga_*
Processes site usage for aggregated analytics after specific consent. Storage period: Up to 730 days. Renewed on activity. The browser may shorten the storage period.

You can withdraw your choice via Privacy choices. That stops further optional loading but does not recall data already sent to Google. We attempt to delete known first-party values; the browser may prevent deletion of third-party values.

How Google uses and is responsible for data · How Google uses information from partner sites · Google privacy policy