Privacy policy
This policy explains what personal data FRIGG (”we”, “our”, “us”) collects when you sign in with Google, how it is used, and your rights. This application is subject to Google’s API Services User Data Policy, including the Limited Use requirements.
I. Information we collect via Google OAuth
When you authenticate with your Google account, we receive only the data you explicitly authorise. We request the minimum scopes necessary to operate the service.
Data element | Google scope | Why we need it
-------------------|--------------|------------------------------------------------
Name | profile | Display your identity within the app
Email address | email | Unique account identifier; transactional emails
Profile picture | profile | User interface avatar (optional, never stored)
Google Account ID | openid | Stable identifier to link sessions to your account
We do not request access to Gmail, Drive, Calendar, Contacts, or any other Google service unless explicitly listed above and visible on the Google consent screen.
II. How we use your data
Data obtained via Google OAuth is used solely for:
- Authenticating your identity and maintaining your session
- Creating and managing your user account
- Sending transactional messages related to your account (e.g., security alerts)
- Complying with legal obligations
We do not use Google user data to serve advertising, build profiles for resale, or train machine-learning models. Use of data obtained via Google APIs is limited to the purposes described in this policy and complies with Google’s API Services User Data Policy, including the Limited Use requirements (https://developers.google.com/terms/api-services-user-data-policy).
III. Data sharing and disclosure
We do not sell, rent, or trade your personal data. We may share it only:
- With service providers who process data on our behalf under strict confidentiality agreements (e.g., cloud hosting, error monitoring)
- When required by law, court order, or regulatory authority
- In the event of a merger or acquisition, where data protections remain binding
No Google user data is shared with third parties for independent use.
IV. Data retention and deletion
Your account data is retained for as long as your account is active. Upon account deletion, personal data is purged within 10 days from our primary systems and within 10 days from backups, except where retention is required by law.
You may revoke this application’s access to your Google account at any time via Google Account Permissions (https://myaccount.google.com/permissions). Revoking access does not automatically delete your account data; submit a deletion request as described in Section VI.
V. Security
We implement industry-standard security measures including transport encryption (TLS), encrypted storage, and access controls. OAuth tokens are stored securely and are never logged in plain text. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
VI. Your rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Request deletion of your data (”right to be forgotten”)
- Object to or restrict processing
- Data portability (receive a machine-readable copy)
To exercise any of these rights, contact us as described below.
VII. Changes to this policy
We may update this policy periodically. Material changes will be communicated via email or a prominent in-app notice at least 30 days before taking effect. Continued use of the application after the effective date constitutes acceptance of the revised policy.
VIII. Contact
Questions, data requests, or complaints:
Email: jr@juliorecalde.com