doesthings.online
Privacy Policy
How doesthings.online handles information used for authentication and access control.
Last updated: July 26, 2026
doesthings.online provides privately operated web applications for invited users. This policy explains what information those services receive, why it is used, and the choices available to you.
Information we receive
When an approved user chooses Google Sign-In, doesthings.online receives only the basic account information needed to identify and authenticate that user:
- a stable Google account identifier;
- email address;
- name; and
- profile image.
The services may also create essential session records and security logs, such as sign-in time, IP address, browser information, and access-control decisions.
doesthings.online does not request access to Gmail, Google Drive, Google Calendar, contacts, files, messages, or other Google content.
How information is used
Information is used only to:
- authenticate approved users;
- identify the correct account;
- enforce invitation and access-control rules;
- maintain secure sessions; and
- prevent, investigate, and respond to abuse or security incidents.
Google Sign-In information is not used for advertising, profiling, or marketing.
Sharing and sale
Personal information is not sold. It is not shared with advertisers or data brokers.
Information may be processed by infrastructure providers only as necessary to operate and secure the services. Information may also be disclosed when required by law, or when reasonably necessary to protect users, the services, or others from fraud, abuse, or security threats.
Google API data
Use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Cookies and sessions
The services use essential cookies or similar local storage only to maintain authenticated sessions, remember security-related preferences, and protect against request forgery. The public branding pages do not use advertising or analytics cookies.
Retention and deletion
Basic account information is retained while a user remains approved and as needed for account security. Security records may be kept for a limited period to investigate incidents and prevent abuse. Information is deleted or de-identified when it is no longer needed, subject to short-lived operational backups and legal obligations.
To request access to or deletion of your account information, email ryan@joshandryan.net. Access to the private services may end when the information required to authenticate an account is deleted.
Security
Reasonable technical and organizational measures are used to protect information, including encrypted transport, restricted administrative access, and access controls appropriate to the invitation-only nature of the services. No method of storage or transmission is completely secure.
Changes to this policy
This policy may be updated when the services or legal requirements change. The date above will be revised when material changes are published.
Contact
Questions or privacy requests may be sent to ryan@joshandryan.net.