Privacy policy
Private by purpose and by boundary.
This policy explains how the owner-only Haeya Workspace Drive Metadata capability handles Google user data and private Storage Core evidence.
1. Operator and scope
Haeya Workspace Drive Metadata is a private capability operated for the Haeya Workspace owner. It is not offered as a multi-user public storage service. Questions or privacy requests may be sent to haeya.biz@gmail.com.
2. Google data requested
The capability requests the identity scopes openid and
email, plus the restricted, read-only scope
https://www.googleapis.com/auth/drive.metadata.readonly.
The identity scopes are used to bind authorization to the intended
Google account.
The intended Drive inventory is limited to:
- stable file, folder, and shortcut identifiers;
- names, MIME types, and object type;
- file size and quota usage when supplied by Google;
- created and modified timestamps;
- parent relationships, Drive space, and trashed state;
- ownership metadata needed to limit the census to items owned by the authorized account; and
- provider checksums when Google supplies them.
Haeya does not use this scope to read file bodies or document contents; download or export files; or create, edit, move, rename, share, trash, or delete Drive items. The intended census excludes Shared Drives and items merely shared directly with the account.
3. How data is used
Metadata is used only to provide the owner with a private storage inventory, census, age and size summaries, and review-only duplicate evidence. Duplicate evidence never authorizes automatic deletion. Google user data is not used for advertising, audience profiling, credit decisions, surveillance, or training general-purpose AI models.
Authorization is currently prepared, but the automated Storage Core inventory handoff is not yet implemented. Visiting this public site does not start OAuth or access Google data.
4. Storage, security, and retention
- Google access and refresh credentials are handled server-side, encrypted at rest with capability-bound authenticated encryption, and never placed in browser storage or public evidence.
- Google-side revocation stops provider authority but does not by itself delete Haeya's encrypted local credential record. Local credential deletion occurs when the owner disconnects the capability in Haeya Workspace or completes a verified deletion request. Disconnect requests provider revocation before local credential deletion.
- Limited account identity and authorization-status records may be retained for security, integrity, and audit history after the credential is deleted.
- When the Storage Core handoff is implemented, private snapshots, validation receipts, census records, and owner-facing review projections will remain private, owner-controlled evidence. They are retained until the owner deletes them manually or requests deletion at haeya.biz@gmail.com. No automatic retention period is promised.
5. Sharing, sale, and advertising
Haeya does not sell Google user data, share it with advertisers or data brokers, serve targeted advertising, or disclose it for another party’s independent use. Data is transferred only as necessary between Google, Haeya Workspace’s server-side components, and the owner-controlled Storage Core/private-output boundary to provide and secure the requested feature, or when legally required.
6. Google API Limited Use
Haeya Workspace’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Human access to raw Google user data is not permitted except at the owner’s direction, when necessary for security or abuse investigation, to comply with law, or where otherwise allowed by that policy.
7. Owner controls and deletion
The owner can disconnect the metadata capability in Haeya Workspace and can revoke Haeya Workspace from the Google Account permissions page. To request deletion of encrypted credentials, retained account records, private snapshots, census records, or review projections, email haeya.biz@gmail.com from the relevant owner account and identify the data to delete. Requests will be verified before deletion to protect the account.
8. This disclosure website
This public website contains no analytics, cookies, forms, advertising, tracking pixels, Google APIs, or authentication. Its only interactive elements are ordinary navigation and email links.
9. Changes
Material changes will be reflected on this page with a new effective date. Expanding the Google scope or changing the stated data use requires a separate review and updated disclosure before use.