Everwished Bills & FundSaving privacy policy
PoC/MVP policy text for review. Contact details, controller details and any final legal approvals are TBC before production use.
TL;DR
We do not sell your data. We do not track app or site usage for profiling. We do not analyse your account data with AI or machine learning. The app is designed to use Google Sign-in, keep session details in memory, and store the user data shown in the portal in your own Google Drive. We only ask for access needed to create, manage and share the app-created file used to run the service.
The optional Remember Me choice stores a small first-party preference cookie only. It must not contain secrets, access tokens, app session data or loaded user data. Google may set its own cookies as part of Google Sign-in; those are controlled by Google, not by this app.
Who this policy is for
This policy applies to the Everwished Bills & FundSaving PoC/MVP app and its information pages. It explains how personal data is intended to be handled when a user signs in, views account details, chooses settings, requests support or gives feedback.
Data controller
The data controller is expected to be the approved Everwished service operator for this app. Final controller identity, registered details and contact route are TBC before production launch.
Personal data we expect to process
- Google account email address and unique Google user ID for sign-in and account matching.
- Display Name, optional profile picture, UW account number and signup date shown in the account view.
- Supported charity, donated-to-date amount and pending-payment amount shown in the charity view.
- User settings such as font size, dark mode, high contrast and reduced motion.
- Information submitted through approved profile update, contact or feedback forms.
Why we process it
We process this data only for the specific purpose of running the service, showing the user's portal information, saving user-controlled settings, handling profile update requests, responding to contact or feedback, and maintaining the integrity and security of the app-created Drive file.
Lawful basis
The expected lawful bases under UK data protection law are contract or steps linked to a requested service, legitimate interests in operating a privacy-conscious user portal, and consent where a user actively chooses optional settings such as Remember Me or submits an optional form. Final lawful-basis wording should be confirmed before production launch.
Where data is stored
The app is designed to store portal data in an app-created file in the user's Google Drive. It is not designed to maintain a separate Everwished app database for this PoC/MVP. Session details, OAuth access tokens and loaded user data are held in memory for the current tab and cleared when the tab is closed, hidden or signed out.
Cookies and similar technologies
If the user does not choose Remember Me, the app should not set a first-party cookie. If the user chooses Remember Me, the app may set a small first-party cookie recording that choice. The cookie must not be used as an app session cookie and must not store secrets, access tokens or loaded user data.
Google Sign-in may involve Google cookies or browser storage controlled by Google. The app cannot set or read Google's domain cookies directly.
Sharing
The app is designed to share only its own app-created Google Drive folder or file with the approved Everwished service operator account or group. It must not share unrelated Google Drive files. Approved Google Forms may receive profile update, contact or feedback submissions when configured.
No selling, tracking or AI profiling
We do not sell user data. We do not track app or site usage for advertising or behavioural profiling. We do not use app account data for AI or machine-learning analysis.
Retention
In-memory session data is retained only for the current tab session. Data stored in the user's Google Drive remains there until removed under the approved service process or by the user where Google Drive permissions allow. Form submissions should be retained only for as long as needed to handle the request and meet legal, audit or service obligations.
Security
The PoC/MVP is designed to request the least Google Drive access that can support app-created files, validate Google identity claims, avoid broad Drive access, avoid persistent local app storage of tokens and loaded data, and constrain configured form/document URLs.
Your rights
Under UK data protection law, users may have rights to access, correct, delete, restrict or object to processing of personal data, and to data portability where applicable. Users may also complain to the Information Commissioner's Office. The final production policy should include the approved contact route for exercising rights.
Changes to this policy
This policy may be updated as the PoC/MVP becomes a live service, especially when final controller details, form routes, legal wording and production hosting are approved.