ColloqAid

Privacy

Privacy Policy

This policy explains what ColloqAid processes locally, what is sent to Google or ColloqAid services when you choose those features, and how to remove your data.

Effective date: July 15, 2026

1. Scope and core privacy model

ColloqAid is a study and quiz builder. It can be used with browser storage and local package files. Google sign-in, Google Drive, feedback, and public sharing are optional features that are used only when you choose the relevant action.

A private local library is not automatically uploaded or published. Google Drive packs stay in the user's Google Drive unless the user deletes them or explicitly shares them. Public pack content is created only through the approved publish/share flow.

ColloqAid does not sell Google user data, use Google user data for advertising, or transfer Google user data to data brokers.

2. Information processed on your device

ColloqAid uses browser storage to keep the app usable between sessions. Depending on the features you use, locally processed data may include:

  • Slide and flashcard study libraries, entries, notes, images, canvases, and quiz groups.
  • Current-pack identity, saved-group choices, quiz progress, filters, preferences, appearance settings, and consent choices.
  • Local package import/export state, non-secret known-pack metadata, and temporary operation state.

The app uses localStorage for preferences and app state and IndexedDB for larger local data such as images and study records. It may also use short-lived sessionStorage values for non-secret browser-session coordination. Google OAuth access tokens are kept in memory and are not intentionally stored in persistent browser storage.

Clearing site data for ColloqAid in your browser removes local browser data for that browser profile. It does not delete files that you separately saved to Google Drive or exported to your device.

3. Google account information

When Google sign-in is used, ColloqAid may process basic identity information supplied by Google, such as your Google account identifier, display name, email address, and profile image. This information is used to show the connected account, associate app-owned settings, and authorize user-requested Google operations.

Google sign-in is not required to read the public About, Privacy, or Terms pages.

4. Google Drive permissions

ColloqAid requests the narrow Google Drive scopes below when the corresponding features are used:

  • https://www.googleapis.com/auth/drive.file allows ColloqAid to work with files it creates or files the user explicitly selects, opens, or shares with ColloqAid through Google Picker.
  • https://www.googleapis.com/auth/drive.appdata allows ColloqAid to store and retrieve private app-owned configuration, settings, profile/avatar references, synchronization state, and other application-owned data in Google Drive's hidden appDataFolder.

ColloqAid does not request full or broad read-only access to Google Drive. It does not silently scan the user's entire Google Drive. Google Picker is used when the user needs to select an arbitrary private Drive file.

Drive operations

Depending on the action you choose, ColloqAid can select a pack, import a selected pack, create or update a ColloqAid pack file, save or restore app-owned configuration data, and manage app-created or explicitly selected files. These operations use the same one-pack, one-file workflow presented in the app.

Private Drive files remain in your own Google Drive. ColloqAid does not copy private Drive content to public storage unless you explicitly choose to publish or share that pack.

5. Public sharing and Cloudflare R2

When a user explicitly publishes or shares a pack, the chosen pack content and public catalog information may be made available to other users. Public information may include the pack title, author or display name, institution, subject, language, semester or year, tags, description, profile information, avatar, entry and image counts, file size, and other details shown in the sharing preview.

Public application data may be stored in Cloudflare R2 and served through ColloqAid's Vercel-hosted application and API routes. A public pack remains the publisher's responsibility, including whether the publisher has permission to share its text, images, and other material.

6. Microscope resources

Microscope catalogs, Deep Zoom Image files, and image tiles are served from slides.colloqaid.com, backed by approved public storage. Requests for these assets may include ordinary network information such as IP address, user agent, requested URL, and timestamps as processed by the hosting and delivery providers.

7. When information is sent to services

ColloqAid sends information only as needed for the feature you use:

  • Google Identity Services, Google Drive API, and Google Picker API handle sign-in and user-requested Drive operations.
  • Vercel hosts the website and server-side API routes.
  • Cloudflare R2 stores approved public shared-pack, catalog, profile/avatar, and microscope data.
  • Resend receives the name, email address, message, and related context you submit only when the feedback email feature is configured and you send feedback.
  • Feature assets may load from Google Fonts, jsDelivr, esm.sh, and unpkg. The app also uses the Hipo university search endpoint and FlagCDN when those interface features are used.

The loaded feature libraries currently include React, ReactDOM, Excalidraw, OpenSeadragon, and JSZip. These services and CDNs may receive ordinary request metadata when the browser requests their resources.

ColloqAid does not currently include advertising, marketing pixels, or an analytics product in the application code.

8. Human access and disclosure

Human access to user data is limited to situations such as user-requested support, security investigation, abuse prevention, maintaining public shared content, or compliance with legal obligations. ColloqAid does not give employees or contractors routine access to private Google Drive contents.

Information may be disclosed when required by law, to protect users or the service, or to investigate security and abuse. Any such access should be limited to what is reasonably necessary.

9. Retention, deletion, and revoking access

  • Local browser data: use ColloqAid's reset controls or clear site data for colloqaid.com in your browser.
  • Google Drive packs: delete the relevant .gqb or .gqa file from Google Drive, including Drive trash if permanent deletion is desired.
  • Google access: revoke ColloqAid from the third-party access section of your Google Account. This stops future authorized access but does not automatically delete files already in your Drive.
  • Public pack, profile, or avatar: use the app's stop-sharing or deletion controls where available, or email ahmadi.gabriell@gmail.com with enough information to identify the public record.

Public records and backups may persist for a limited period in provider caches, logs, or backup systems after deletion. ColloqAid retains data only as long as needed for the service, the user's chosen feature, security, or legal obligations.

10. Security

ColloqAid uses HTTPS for the production website and service requests. OAuth access tokens are intended to remain in browser memory and are not intentionally logged or exposed. Server credentials and storage secrets remain in server-side environment configuration and are not included in frontend code.

No system can guarantee absolute security. Users should keep backups of important packs and protect access to their browser profile, device, and Google account.

11. Google API policy

ColloqAid's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the applicable Limited Use requirements.

12. Changes and contact

This policy may be updated when the app, providers, or legal requirements change. Material updates will be reflected by changing the effective date on this page.

For privacy questions, support, or deletion requests, contact ahmadi.gabriell@gmail.com.