1. Scope and core privacy model
ColloqAid is a study and quiz builder. It can be used with browser storage and local package files. Google sign-in, Google Drive, feedback, and public sharing are optional features that are used only when you choose the relevant action.
The data controller for ColloqAid service data is Gabriel Ahmadi, Finland. Privacy questions and data-rights requests can be sent to colloqaid@gmail.com.
A private local library is not automatically uploaded or published. Google Drive packs stay in the user's Google Drive unless the user deletes them or explicitly shares them. Public pack content is created only through the approved publish/share flow.
2. Information processed on your device
ColloqAid uses browser storage to keep the app usable between sessions. Depending on the features you use, locally processed data may include:
- Slide and flashcard study libraries, entries, notes, images, canvases, and quiz groups.
- Current-pack identity, saved-group choices, quiz progress, filters, preferences, appearance settings, and consent choices.
- Local package import/export state, non-secret known-pack metadata, and temporary operation state.
The app uses localStorage for preferences and app state and IndexedDB for larger local data such as images and study records. It may also use short-lived sessionStorage values for non-secret browser-session coordination. Google OAuth access tokens are kept in memory and are not intentionally stored in persistent browser storage.
Clearing site data for ColloqAid in your browser removes local browser data for that browser profile. It does not delete files that you separately saved to Google Drive or exported to your device.
3. Google account information
When Google sign-in is used, ColloqAid may process basic identity information supplied by Google, such as your Google account identifier, display name, email address, and profile image. This information is used to show the connected account, associate app-owned settings, and authorize user-requested Google operations.
Text-only feedback is available without Google sign-in. If you choose to attach screenshots, ColloqAid uses the existing basic openid, email, and profile permissions to verify that you are signed in and that Google has marked the account email as verified. Screenshot feedback does not request a new Google Drive permission. The access token remains in browser memory, is sent only in the authorization header for that request, and is not included in the feedback email.
When you submit a shared-pack report, the server verifies that Google has marked the signed-in email as verified. The address is not stored with the report. It is stored separately in encrypted form only if you actively select the optional email follow-up choice described in section 6.
Google sign-in is not required to read the public About, Privacy, or Terms pages.
4. Google Drive permissions
ColloqAid requests the narrow Google Drive scopes below when the corresponding features are used:
https://www.googleapis.com/auth/drive.fileallows ColloqAid to work with files it creates or files the user explicitly selects, opens, or shares with ColloqAid through Google Picker.https://www.googleapis.com/auth/drive.appdataallows ColloqAid to store and retrieve private app-owned configuration, settings, profile/avatar references, synchronization state, and other application-owned data in Google Drive's hiddenappDataFolder.
ColloqAid does not request full or broad read-only access to Google Drive. It does not silently scan the user's entire Google Drive. Google Picker is used when the user needs to select an arbitrary private Drive file.
Drive operations
Depending on the action you choose, ColloqAid can select a pack, import a selected pack, create or update a ColloqAid pack file, save or restore app-owned configuration data, and manage app-created or explicitly selected files. These operations use the same one-pack, one-file workflow presented in the app.
Private Drive files remain in your own Google Drive. ColloqAid does not copy private Drive content to public storage unless you explicitly choose to publish or share that pack.
5. Public sharing and Cloudflare R2
When a user explicitly publishes or shares a pack, the chosen pack content and public catalog information may be made available to other users. Public information may include the pack title, author or display name, institution, subject, language, semester or year, tags, description, profile information, avatar, entry and image counts, file size, and other details shown in the sharing preview.
Public application data may be stored in Cloudflare R2 and served through ColloqAid's Vercel-hosted application and API routes. A public pack remains the publisher's responsibility, including whether the publisher has permission to share its text, images, and other material.
6. Moderation reports and optional email follow-up
A signed-in user may privately report a public shared pack. ColloqAid processes the selected category, the user's explanation, a pseudonymous reporter fingerprint, a pseudonymous reference to the public pack, submission timestamps, moderation status and decisions, and related audit records. Do not put unnecessary sensitive or confidential information in the explanation.
Authorized Admins and Moderators may read the report to investigate safety, rights, abuse, and service-integrity concerns. The pack creator cannot see the reporter's identity or private explanation. A report does not automatically hide a pack, restrict a creator, or produce any other punishment; a human moderator decides whether any separate action is appropriate.
The report form includes an optional, unchecked choice: Allow ColloqAid to email me about this report.
If selected, the server stores the verified Google-account email in a separate private contact record encrypted with AES-256-GCM. The record also stores the report reference, purpose, notice version, and consent timestamp. The raw address is not written into the immutable report, returned to the Admin Console, shown to the creator, or used for unrelated messages. Leaving the choice off does not affect whether the report is reviewed.
Selecting the choice does not itself send an email. If authorized follow-up messaging is used, the server may decrypt the address only for that report and send the moderator's message through Resend. You may withdraw email follow-up permission at any time by contacting colloqaid@gmail.com. Withdrawal does not affect the lawfulness of earlier processing and does not require ColloqAid to erase the underlying safety report when another lawful basis still applies.
7. Microscope resources
Microscope catalogs, Deep Zoom Image files, and image tiles are served from slides.colloqaid.com, backed by approved public storage. Requests for these assets may include ordinary network information such as IP address, user agent, requested URL, and timestamps as processed by the hosting and delivery providers.
9. Purposes and legal bases
- Requested app, account, Drive, and sharing features: processing is necessary to provide the feature you request and perform the Terms of Service, or to take steps at your request.
- Feedback and support: processing the details and optional screenshots you submit is necessary to answer your request and improve or repair the service. Turnstile and bounded rate limiting support ColloqAid's legitimate interest in preventing automated abuse and protecting service availability.
- Safety and moderation: ColloqAid relies on legitimate interests in protecting users, investigating abuse and rights concerns, maintaining service integrity, preventing misuse, and documenting proportionate moderation decisions. These interests are balanced against the rights and freedoms of affected people.
- Optional report follow-up: storing and using the verified email for report-specific follow-up is based on your consent. It is separate from report submission and can be refused or withdrawn without disadvantage.
- Legal compliance: information may be processed when necessary to meet a legal obligation or establish, exercise, or defend legal claims.
10. Human access and disclosure
Human access to user data is limited to authorized people who need it for user-requested support, report review, security investigation, abuse prevention, maintaining public shared content, or compliance with legal obligations. ColloqAid does not give employees, moderators, or contractors routine access to private Google Drive contents.
Information may be disclosed when required by law, to protect users or the service, or to investigate security and abuse. Any such access should be limited to what is reasonably necessary.
ColloqAid does not use solely automated decision-making to punish a user, hide a pack, or resolve a moderation report.
11. Retention, deletion, and revoking access
- Local browser data: use ColloqAid's reset controls or clear site data for
colloqaid.comin your browser. - Google Drive packs: delete the relevant
.gqbor.gqafile from Google Drive, including Drive trash if permanent deletion is desired. - Google access: revoke ColloqAid from the third-party access section of your Google Account. This stops future authorized access but does not automatically delete files already in your Drive.
- Public pack, profile, or avatar: use the app's stop-sharing or deletion controls where available, or email colloqaid@gmail.com with enough information to identify the public record.
- Feedback and optional screenshots: unsubmitted originals and locally processed previews stay in browser memory and are discarded when removed, after a successful submission, or when the page closes. Submitted feedback is delivered through Resend to the ColloqAid support Gmail mailbox. ColloqAid creates no separate R2 or Vercel Blob copy. Resend and Gmail may retain the delivered message and attachments under their service policies and account settings; ColloqAid deletes support correspondence when it is no longer reasonably needed for the request, service integrity, or legal obligations.
- Moderation reports: open reports remain available while review is pending. Report, case, and correspondence records are scheduled for deletion 12 months after closure. Moderation audit records are retained for 24 months. An encrypted report-contact address is removed when follow-up permission is withdrawn or the case closes, whichever occurs first.
These periods are operational limits and may be applied through bounded manual or automated procedures. Information may be retained longer when a documented legal hold or legal obligation applies. Provider caches, security logs, or backups may take a limited additional period to expire after deletion.
12. Service providers and international transfers
Google, Vercel, Cloudflare, Resend, and their approved subprocessors may process information in the United States or other countries outside Finland and the European Economic Area. Where EU data-protection law applies, transfer safeguards may include an adequacy decision such as the EU-U.S. Data Privacy Framework or the European Commission's Standard Contractual Clauses, together with provider security measures.
Provider details and safeguards can change. Current information is available from Cloudflare's GDPR information, Cloudflare's Turnstile Privacy Addendum, Vercel's Data Processing Addendum, and Resend's Data Processing Addendum.
13. Security
ColloqAid uses HTTPS for the production website and service requests. OAuth access tokens are intended to remain in browser memory and are not intentionally logged or exposed. Server credentials and storage secrets remain in server-side environment configuration and are not included in frontend code.
Feedback attachments are restricted to signed-in users, limited in count and size, checked for supported image structure, re-encoded in the browser and again on the server, assigned generic filenames, and protected by Turnstile and rate limits. These safeguards reduce risk but cannot determine whether visible text or pixels contain sensitive information, so users must review every screenshot before sending it.
Private moderation records are stored in Cloudflare R2 and accessed through permission-checked server routes. Optional reporter contact addresses receive an additional application-level AES-256-GCM encryption layer and are stored separately from the report. Encryption reduces risk but does not make any system invulnerable.
No system can guarantee absolute security. Users should keep backups of important packs and protect access to their browser profile, device, and Google account.
14. Google API policy
ColloqAid's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the applicable Limited Use requirements.
15. Your data-protection rights
Depending on the circumstances and applicable law, you may have rights to access, correct, erase, restrict, or receive a copy of personal data, and to object to processing based on legitimate interests. Where processing relies on consent, you may withdraw that consent at any time.
To exercise a right, email colloqaid@gmail.com from an address that can reasonably help identify the relevant record. Do not send a password, OAuth token, or unnecessary sensitive information. ColloqAid may need proportionate information to verify the request and protect another person's data.
You may lodge a complaint with the Office of the Data Protection Ombudsman in Finland or another competent supervisory authority, including the authority where you live or work.
16. Changes and contact
This policy may be updated when the app, providers, or legal requirements change. Material updates will be reflected by changing the effective date on this page.
Controller: Gabriel Ahmadi, Finland. For privacy questions, consent withdrawal, or data-rights and deletion requests, contact colloqaid@gmail.com.