ColloqAid

Privacy

Privacy Policy

This policy explains what ColloqAid processes locally, what is sent to Google or ColloqAid services when you choose those features, and how to remove your data.

Effective date: August 10, 2026

1. Scope and core privacy model

ColloqAid is a study and quiz builder. It can be used with browser storage and local package files. Google sign-in, Google Drive, feedback, and public sharing are optional features that are used only when you choose the relevant action.

The data controller for ColloqAid service data is Gabriel Ahmadi, Finland. Privacy questions and data-rights requests can be sent to colloqaid@gmail.com.

A private local library is not automatically uploaded or published. Google Drive packs stay in the user's Google Drive unless the user deletes them or explicitly shares them. Public pack content is created only through the approved publish/share flow.

ColloqAid does not sell Google user data, use Google user data for advertising, or transfer Google user data to data brokers.

2. Information processed on your device

ColloqAid uses browser storage to keep the app usable between sessions. Depending on the features you use, locally processed data may include:

  • Slide and flashcard study libraries, entries, notes, images, canvases, and quiz groups.
  • Current-pack identity, saved-group choices, quiz progress, filters, preferences, appearance settings, and consent choices.
  • Local package import/export state, non-secret known-pack metadata, and temporary operation state.

The app uses localStorage for preferences and app state and IndexedDB for larger local data such as images and study records. It may also use short-lived sessionStorage values for non-secret browser-session coordination. Google OAuth access tokens are kept in memory and are not intentionally stored in persistent browser storage.

Clearing site data for ColloqAid in your browser removes local browser data for that browser profile. It does not delete files that you separately saved to Google Drive or exported to your device.

3. Google account information

When Google sign-in is used, ColloqAid may process basic identity information supplied by Google, such as your Google account identifier, display name, email address, and profile image. This information is used to show the connected account, associate app-owned settings, and authorize user-requested Google operations.

Text-only feedback is available without Google sign-in. If you choose to attach screenshots, ColloqAid uses the existing basic openid, email, and profile permissions to verify that you are signed in and that Google has marked the account email as verified. Screenshot feedback does not request a new Google Drive permission. The access token remains in browser memory, is sent only in the authorization header for that request, and is not included in the feedback email.

When you submit a shared-pack report, the server verifies that Google has marked the signed-in email as verified. The address is not stored with the report. It is stored separately in encrypted form only if you actively select the optional email follow-up choice described in section 6.

Google sign-in is not required to read the public About, Privacy, or Terms pages.

4. Google Drive permissions

ColloqAid requests the narrow Google Drive scopes below when the corresponding features are used:

  • https://www.googleapis.com/auth/drive.file allows ColloqAid to work with files it creates or files the user explicitly selects, opens, or shares with ColloqAid through Google Picker.
  • https://www.googleapis.com/auth/drive.appdata allows ColloqAid to store and retrieve private app-owned configuration, settings, profile/avatar references, synchronization state, and other application-owned data in Google Drive's hidden appDataFolder.

ColloqAid does not request full or broad read-only access to Google Drive. It does not silently scan the user's entire Google Drive. Google Picker is used when the user needs to select an arbitrary private Drive file.

Drive operations

Depending on the action you choose, ColloqAid can select a pack, import a selected pack, create or update a ColloqAid pack file, save or restore app-owned configuration data, and manage app-created or explicitly selected files. These operations use the same one-pack, one-file workflow presented in the app.

Private Drive files remain in your own Google Drive. ColloqAid does not copy private Drive content to public storage unless you explicitly choose to publish or share that pack.

5. Public sharing and Cloudflare R2

When a user explicitly publishes or shares a pack, the chosen pack content and public catalog information may be made available to other users. Public information may include the pack title, author or display name, institution, subject, language, semester or year, tags, description, profile information, avatar, entry and image counts, file size, and other details shown in the sharing preview.

Public application data may be stored in Cloudflare R2 and served through ColloqAid's Vercel-hosted application and API routes. A public pack remains the publisher's responsibility, including whether the publisher has permission to share its text, images, and other material.

6. Moderation reports and optional email follow-up

A signed-in user may privately report a public shared pack. ColloqAid processes the selected category, the user's explanation, a pseudonymous reporter fingerprint, a pseudonymous reference to the public pack, submission timestamps, moderation status and decisions, and related audit records. Do not put unnecessary sensitive or confidential information in the explanation.

Authorized Admins and Moderators may read the report to investigate safety, rights, abuse, and service-integrity concerns. The pack creator cannot see the reporter's identity or private explanation. A report does not automatically hide a pack, restrict a creator, or produce any other punishment; a human moderator decides whether any separate action is appropriate.

The report form includes an optional, unchecked choice: Allow ColloqAid to email me about this report. If selected, the server stores the verified Google-account email in a separate private contact record encrypted with AES-256-GCM. The record also stores the report reference, purpose, notice version, and consent timestamp. The raw address is not written into the immutable report, returned to the Admin Console, shown to the creator, or used for unrelated messages. Leaving the choice off does not affect whether the report is reviewed.

Selecting the choice does not itself send an email. If authorized follow-up messaging is used, the server may decrypt the address only for that report and send the moderator's message through Resend. You may withdraw email follow-up permission at any time by contacting colloqaid@gmail.com. Withdrawal does not affect the lawfulness of earlier processing and does not require ColloqAid to erase the underlying safety report when another lawful basis still applies.

7. Microscope resources

Microscope catalogs, Deep Zoom Image files, and image tiles are served from slides.colloqaid.com, backed by approved public storage. Requests for these assets may include ordinary network information such as IP address, user agent, requested URL, and timestamps as processed by the hosting and delivery providers.

8. When information is sent to services

ColloqAid sends information only as needed for the feature you use:

  • Google Identity Services, Google Drive API, and Google Picker API handle sign-in and user-requested Drive operations.
  • Vercel hosts the website and runs the server-side API routes that authenticate and process reports. Vercel may also supply a coarse two-letter country code derived from request network location. ColloqAid uses that code only to choose the initial in-app flag, does not store the IP address for this feature, and keeps any manual flag choice as the user's preference.
  • Cloudflare R2 stores approved public shared-pack, catalog, profile/avatar, and microscope data, as well as private moderation reports, encrypted report-contact records, report correspondence, case state, and audit records. Feedback screenshots are not stored in R2.
  • Cloudflare Turnstile processes limited browser, device, network, interaction, and challenge signals needed to distinguish people from automated abuse. ColloqAid sends the short-lived Turnstile token and, when available, the request IP address to Cloudflare's Siteverify service. ColloqAid does not use Turnstile signals for advertising or analytics.
  • When the feedback email feature is used, Resend receives the name, reply email address, message, page path, request metadata, and any screenshots you actively attach. Attached originals are processed locally in the browser; the browser reduces them to no more than 800 KB each, removes embedded metadata by re-encoding, and sends no more than three processed images. The server validates, decodes, and re-encodes each image again before delivery. The processed total is limited to 2.4 MB. The resulting email and attachments are delivered to the ColloqAid support Gmail mailbox; ColloqAid does not create a separate screenshot archive in R2 or Vercel Blob.
  • If moderation follow-up messaging is configured and used, Resend receives the reporter's address, the moderation message, and delivery metadata needed to send that message.
  • Feature assets may load from Google Fonts, jsDelivr, esm.sh, and unpkg. The app also uses the Hipo university search endpoint and FlagCDN when those interface features are used.

The loaded feature libraries currently include React, ReactDOM, Excalidraw, OpenSeadragon, and JSZip. These services and CDNs may receive ordinary request metadata when the browser requests their resources.

ColloqAid does not currently include advertising, marketing pixels, or an analytics product in the application code.

10. Human access and disclosure

Human access to user data is limited to authorized people who need it for user-requested support, report review, security investigation, abuse prevention, maintaining public shared content, or compliance with legal obligations. ColloqAid does not give employees, moderators, or contractors routine access to private Google Drive contents.

Information may be disclosed when required by law, to protect users or the service, or to investigate security and abuse. Any such access should be limited to what is reasonably necessary.

ColloqAid does not use solely automated decision-making to punish a user, hide a pack, or resolve a moderation report.

11. Retention, deletion, and revoking access

  • Local browser data: use ColloqAid's reset controls or clear site data for colloqaid.com in your browser.
  • Google Drive packs: delete the relevant .gqb or .gqa file from Google Drive, including Drive trash if permanent deletion is desired.
  • Google access: revoke ColloqAid from the third-party access section of your Google Account. This stops future authorized access but does not automatically delete files already in your Drive.
  • Public pack, profile, or avatar: use the app's stop-sharing or deletion controls where available, or email colloqaid@gmail.com with enough information to identify the public record.
  • Feedback and optional screenshots: unsubmitted originals and locally processed previews stay in browser memory and are discarded when removed, after a successful submission, or when the page closes. Submitted feedback is delivered through Resend to the ColloqAid support Gmail mailbox. ColloqAid creates no separate R2 or Vercel Blob copy. Resend and Gmail may retain the delivered message and attachments under their service policies and account settings; ColloqAid deletes support correspondence when it is no longer reasonably needed for the request, service integrity, or legal obligations.
  • Moderation reports: open reports remain available while review is pending. Report, case, and correspondence records are scheduled for deletion 12 months after closure. Moderation audit records are retained for 24 months. An encrypted report-contact address is removed when follow-up permission is withdrawn or the case closes, whichever occurs first.

These periods are operational limits and may be applied through bounded manual or automated procedures. Information may be retained longer when a documented legal hold or legal obligation applies. Provider caches, security logs, or backups may take a limited additional period to expire after deletion.

12. Service providers and international transfers

Google, Vercel, Cloudflare, Resend, and their approved subprocessors may process information in the United States or other countries outside Finland and the European Economic Area. Where EU data-protection law applies, transfer safeguards may include an adequacy decision such as the EU-U.S. Data Privacy Framework or the European Commission's Standard Contractual Clauses, together with provider security measures.

Provider details and safeguards can change. Current information is available from Cloudflare's GDPR information, Cloudflare's Turnstile Privacy Addendum, Vercel's Data Processing Addendum, and Resend's Data Processing Addendum.

13. Security

ColloqAid uses HTTPS for the production website and service requests. OAuth access tokens are intended to remain in browser memory and are not intentionally logged or exposed. Server credentials and storage secrets remain in server-side environment configuration and are not included in frontend code.

Feedback attachments are restricted to signed-in users, limited in count and size, checked for supported image structure, re-encoded in the browser and again on the server, assigned generic filenames, and protected by Turnstile and rate limits. These safeguards reduce risk but cannot determine whether visible text or pixels contain sensitive information, so users must review every screenshot before sending it.

Private moderation records are stored in Cloudflare R2 and accessed through permission-checked server routes. Optional reporter contact addresses receive an additional application-level AES-256-GCM encryption layer and are stored separately from the report. Encryption reduces risk but does not make any system invulnerable.

No system can guarantee absolute security. Users should keep backups of important packs and protect access to their browser profile, device, and Google account.

14. Google API policy

ColloqAid's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the applicable Limited Use requirements.

15. Your data-protection rights

Depending on the circumstances and applicable law, you may have rights to access, correct, erase, restrict, or receive a copy of personal data, and to object to processing based on legitimate interests. Where processing relies on consent, you may withdraw that consent at any time.

To exercise a right, email colloqaid@gmail.com from an address that can reasonably help identify the relevant record. Do not send a password, OAuth token, or unnecessary sensitive information. ColloqAid may need proportionate information to verify the request and protect another person's data.

You may lodge a complaint with the Office of the Data Protection Ombudsman in Finland or another competent supervisory authority, including the authority where you live or work.

16. Changes and contact

This policy may be updated when the app, providers, or legal requirements change. Material updates will be reflected by changing the effective date on this page.

Controller: Gabriel Ahmadi, Finland. For privacy questions, consent withdrawal, or data-rights and deletion requests, contact colloqaid@gmail.com.