Privacy Policy
This policy explains what Project-S collects, why, where it is stored, and how to have it deleted. It covers data obtained from your Google Account when you sign in.
Who we are and what this app is
Project-S is a private, invitation-only inventory tool used by a single small resale operation to track auction purchases from pickup through to resale. It is operated by its owner, who can be reached at sy0135@gmail.com, and runs at nine9.dev.
It is not a public product and there is no sign-up. Accounts exist only because the owner has explicitly granted access to a specific Google address. If you have not been given access, you cannot create an account and we hold no data about you.
What we collect from your Google Account
Signing in uses Google OAuth. We request two scopes, both of which Google classifies as non-sensitive:
| Scope | What it gives us | Why we need it |
|---|---|---|
userinfo.email |
Your email address | It is your identity in the app. Access is granted per email address, so this is what we check to decide whether you may sign in and which parts of the app you may open. |
userinfo.profile |
Your name and profile picture | Displayed in the app so it is clear which account is currently signed in. |
We request nothing else. We do not ask for, receive, or have any way to read your Gmail, Google Drive, Google Sheets, contacts, calendar, photos, or any other Google service.
What else the app stores
- Your access record — your email address and the list of app areas the owner has granted you, so the server can enforce it on every request.
- A login session — a server-side session holding your email, name, and picture, referenced by a cookie in your browser.
- Google OAuth tokens — stored on the server so a sign-in can be completed.
- Business records you create or import — auction receipts, inventory items, prices, conditions, notes, storage locations, and product data retrieved from public retail listings. This is inventory data about goods, not personal data about people.
- Ordinary server logs — request and error logs, which may include IP addresses and the email address of a signed-in user, kept for security and debugging.
How we use it
Only to operate the app:
- To authenticate you and keep you signed in.
- To decide which areas of the app you are permitted to open.
- To show who is signed in.
- To keep the service secure and diagnose faults.
We do not sell, rent, or share your personal data with anyone, ever. We do not use it for advertising, profiling, or training machine-learning models, and we do not transfer it to third parties for any purpose of their own.
Cookies and tracking
The app sets one cookie: a session cookie that keeps you signed in. It is strictly necessary —
without it you cannot stay logged in. It is marked HttpOnly so scripts cannot read
it, and it is sent only over HTTPS.
There are no analytics, advertising, or tracking cookies, and no third-party trackers, pixels, or analytics SDKs anywhere in the app. We do not track you across other websites, and the app sends no behavioural data to anyone.
Who else touches the data
- Google — performs the sign-in and tells us your email, name, and picture. Governed by Google's Privacy Policy.
- Hostinger — hosts the server the app and its data run on.
- Retail and auction sites — the app fetches public product information (titles, prices, images) to enrich inventory records. These requests carry no personal data about app users.
No other party receives data from this app.
Where it is stored and how it is protected
- All data is held on the app's own server, not in a third-party database or analytics service.
- Traffic is served over HTTPS.
- Every request is checked against the signed-in user's granted permissions, enforced server-side.
- Sessions expire automatically — after 2 hours of inactivity, and in all cases within 24 hours.
- Access is limited to the specific email addresses the owner has granted; everyone else is refused at sign-in.
How long we keep it
- Sessions — deleted when they expire or when you sign out.
- Your access record — kept while you have access, and deleted when the owner revokes it.
- Business records — kept for as long as they are needed for inventory and tax purposes.
- Logs — rotated and discarded in the ordinary course of running the server.
Your choices
You can, at any time:
- Sign out, which destroys your session.
- Revoke the app's access to your Google Account at myaccount.google.com/permissions. This immediately stops the app receiving anything further from Google.
- Ask us to delete your data. Email sy0135@gmail.com and we will delete your access record, your sessions, and any stored profile information. Requests are handled within 30 days.
- Ask what we hold about you, and we will tell you.
Children
Project-S is a business tool and is not directed to children. We do not knowingly collect data from anyone under 13.
Compliance with Google API Services
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Data obtained from Google is used solely to provide and improve the sign-in and access-control features described above, is never sold, and is never transferred to others except as required by law.
Changes to this policy
If this policy changes, the revised version will be posted on this page with an updated date. The date at the top always reflects the current version.
Contact
Questions about this policy, or about data we hold: sy0135@gmail.com.