B
Blog
Google OAuth 2.0 CompliantEffective Date: September 3, 2026

Privacy Policy

We respect your privacy and are committed to protecting personal data. This policy details our practices regarding information collection, usage, and our strict adherence to Google API Services User Data Policy standards.

Zero Data Selling

We never sell, rent, or monetize your personal data or Google account information to advertisers.

Google Limited Use

Strict adherence to Google API Services User Data Policy, restricting OAuth data to core app functionality.

End-to-End Encryption

All data in transit is encrypted using modern TLS/HTTPS, and credentials are cryptographically protected.

Your Data, Your Control

You can export your articles, request full account deletion, or revoke Google OAuth access at any time.

1. Introduction

Welcome to Blog Platform ("we", "our", or "us"). We operate the blogging and publishing application available at https://blog.shrey.online.

This Privacy Policy describes our policies and procedures on the collection, use, maintenance, protection, and disclosure of information when you access or use our services, create an account, publish articles, interact with community content, or authenticate through third-party identity providers such as Google and GitHub.

By accessing or using our platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our policies and practices, please do not use our services.

2. Google OAuth 2.0 User Data & Limited Use Disclosure

Google API Services User Data Policy Compliance

Blog Platform's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google Scopes Requested

When you choose to sign in or create an account using Google OAuth 2.0, we only request the minimal necessary scopes:

  • openid: Used to authenticate your identity via OpenID Connect.
  • https://www.googleapis.com/auth/userinfo.email: Used to retrieve your primary email address to create and link your user account.
  • https://www.googleapis.com/auth/userinfo.profile: Used to retrieve your display name and public avatar photo to populate your author profile.

Strict Restrictions on Google User Data

In adherence to Google's Limited Use requirements, we enforce the following strict guarantees:

  • No Advertising or Marketing Transfer: We do not transfer, disclose, or sell Google user data to third parties for targeted advertising, credit assessment, data broker exchanges, or commercial marketing.
  • No Unauthorized Human Access: No human is permitted to read Google user data unless you have given affirmative agreement, it is strictly necessary for security purposes (e.g. investigating abuse), or required by applicable law.
  • No Generalized AI Model Training: We do not use Google user data to train or fine-tune general artificial intelligence or machine learning models without explicit, affirmative consent.

3. Information We Collect

A. Information You Provide Directly

  • Account Profile: Name, username, email address, avatar photo, and bio when you register or edit your profile.
  • Published Content: Articles, draft stories, comments, tags, bookmarks, reactions, and badges you create or interact with.
  • Organization & Team Data: Workspace names, roles, and invitation emails if you create or join collaborative teams.

B. Information Collected Automatically

  • Device & Network Logs: IP address, user-agent string, browser type, and operating system for security, DDoS protection, and rate limiting.
  • Usage & Reading Analytics: Privacy-first aggregated view counts, reading time, and scroll-depth metrics to help authors understand content reach.

4. How We Use Your Information

We process your data strictly to deliver and maintain our services:

  • To authenticate you and maintain your active session via secure sessions and JSON Web Tokens.
  • To host, publish, render, and display your blog posts and author identity.
  • To send transactional emails (magic link authentication, workspace invites, and security alerts).
  • To detect, prevent, and mitigate fraud, spam, automated scrapers, and malicious activity.
  • To comply with statutory legal obligations and enforce our terms of service.

5. Data Storage, Security & Retention

We implement industry-standard administrative, physical, and technical safeguards to protect your personal data against unauthorized access, destruction, loss, or alteration:

  • Encryption in Transit: All HTTP traffic is protected by Transport Layer Security (TLS/HTTPS).
  • Database Security: Data is persisted in PostgreSQL databases secured with connection pooling, strict access credentials, and network isolation.
  • Rate Limiting & Protection: Write endpoints and authentication attempts are actively rate-limited via Redis sliding-window algorithms to guard against brute force attempts.

Retention: We retain your personal data for as long as your account remains active. If you request account deletion, your profile information and private drafts will be purged from our active databases.

6. Third-Party Service Providers

We only share minimal necessary data with trusted infrastructure and service providers operating under strict confidentiality and security commitments:

  • Identity Providers: Google Identity Services and GitHub OAuth (for optional user login).
  • Email Delivery: Resend (used exclusively to deliver passwordless magic links and invite notifications).
  • Cloud Storage & CDN: Cloudinary and Cloudflare R2 (for hosting user-uploaded article cover photos and avatars).
  • Database & Cache Hosting: Managed PostgreSQL and Upstash Redis for database and rate limiting operations.

7. Your Rights & Data Deletion

Regardless of your geographic location, you possess comprehensive rights over your personal data:

How to Request Account & Data Deletion

To delete your account and remove all personal information associated with your profile, submit a request to support@mail.shrey.online from your registered email address. We will verify your identity and process the deletion request within thirty (30) days.

How to Revoke Google Account Access

You may revoke our application's access to your Google account at any moment through Google's security portal:

Google Security: Third-party apps & services

8. Cookies & Local Storage

We use strictly essential cookies and local storage tokens necessary for the operation of our platform:

  • Session Cookies: Maintained by NextAuth to keep you securely signed in.
  • Theme Preference: Stored locally in your browser to remember your chosen light or dark theme setting.
  • CSRF Protection Tokens: Used to prevent Cross-Site Request Forgery attacks during authentication.

We do not deploy third-party advertising cookies or cross-site tracking pixels.

9. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy, your personal information, or our compliance with the Google API Services User Data Policy, please contact our data privacy team:

Direct Privacy Contact

support@mail.shrey.online

We respond to verified privacy and data deletion inquiries promptly within standard business hours.