PRIVACY POLICY

Privacy Policy

This Privacy Policy explains how Pocket Exporter, operated by Hojong Yu, accesses, uses, protects, and deletes Google user data when providing its Google Sheets export features.

Effective date
2026-07-30
Service
Pocket Exporter

1. Application purpose and information processed

Pocket Exporter is a data-export utility for an issue-management application. It uses Google OAuth only when an authorized user asks to export a selected issue list or a completed AI work result to a new Google spreadsheet owned by the Google account the user authorizes.

  • The main application verifies the signed-in user, role, and export permission.
  • The issue records or AI result being exported are revalidated against the application's own data source.
  • The OAuth Broker processes a request identifier, OAuth state, PKCE verifier, and short-lived access token.
  • The OAuth Broker does not receive issue titles, assignees, labels, or AI result content.

2. Google user data accessed and how it is used

Pocket Exporter requests only the following two OAuth scopes:

Google Sheets spreadsheets Creates a new spreadsheet, writes the data selected by the user, and formats it as a readable table.
Google Drive drive.file Identifies and manages only files created by this application and removes an incomplete file if an export fails.

Google user data is used only to create, write, format, identify, and, if an export fails, delete the spreadsheet created by the user's current export request.

Pocket Exporter does not read existing spreadsheet content, browse the user's full Google Drive file list, or request Google profile, Gmail, or contacts access. Google user data is not used for advertising, sale, credit, employment, insurance decisions, user profiling, or general or personalized AI model training.

3. Retention and deletion

  • No refresh token is requested or stored.
  • OAuth state and the PKCE verifier are used to validate one authorization request and cannot be reused after consumption or expiration.
  • The access token is encrypted at rest, remains available for no more than 10 minutes, and is deleted when the main server claims it once.
  • Related state and grant records are deleted immediately after successful completion, cancellation, or a handled error.
  • Expired records from interrupted requests are removed under the service's operational cleanup policy and cannot be used after expiration.
  • Authorization codes, access tokens, and complete OAuth state values are not written to application logs.

The authorized Google account owns the generated spreadsheet and can retain, share, move, or delete it directly in Google Drive.

4. Service providers and data sharing

The requested export uses Google OAuth, Google Sheets API, Google Drive API, Google Cloud Run, Firestore, and Secret Manager. Google's applicable terms and privacy policies also govern processing performed by Google services.

Google user data is not sold or disclosed to another third party except when required by law or explicitly authorized by the user.

5. User choices and access revocation

Users can control their data and permissions in the following ways:

  • Cancel the permission request on the Google consent screen.
  • Revoke Pocket Exporter access from Google Account third-party connections.
  • Delete generated spreadsheets directly in Google Drive.
  • Contact the operator below with a privacy or deletion request.

6. Security measures

  • OAuth state and PKCE (S256) protect the callback from request tampering.
  • Requests between the main server and OAuth Broker are verified with an HMAC signature and short timestamp window.
  • The short-lived access token is encrypted at rest and atomically consumed once to prevent reuse.
  • The Google OAuth Client Secret and encryption key are stored in Secret Manager.
  • Public policy and OAuth result pages use CSP, frame blocking, no-store, and other security headers.

7. Changes to this policy

This policy and its effective date will be updated if the features, requested scopes, or data-handling practices change. Material changes will be announced through the service or the published support contact.

8. Contact

Operator: Hojong Yu

Email: yuhojong95@gmail.com