Privacy Policy
This policy explains how StepCodex collects, uses, and protects information when you use our site, tools, and Google OAuth sign-in.
1. Information We Collect
We follow a data-minimization approach. Different features may require different data.
- Account & sign-in (Google OAuth): when you sign in with Google, we may receive and store necessary identifiers such as email, name/display name, profile photo (if provided), and Google's unique user ID (sub).
- Usage & diagnostics: to maintain security and reliability, we may log basic telemetry (e.g., access time, request path, error codes, browser/device info, and coarse IP-related info).
- Content you submit: if you post text/links/descriptions to Issue Station or related features, we use and may store that content to provide the service.
2. How We Use Information
We use information only as necessary to provide and improve the service, maintain security, and meet legal obligations.
- Create and maintain accounts, complete sign-in, and manage sessions.
- Provide account-linked features (e.g., auth status, managing account-related content).
- Security: detect suspicious sign-ins, abuse, automated attacks, and stability issues.
- Support & communication: respond to inquiries and handle compliance requests.
3. Google OAuth & Third Parties
When you sign in with Google, authentication is provided by Google. We do not receive your Google password.
We use OAuth-provided information to identify you and create an account. We do not sell your personal information to third parties.
- Third-party services (used to provide the website and sign-in): Google (sign-in/identity).
- Infrastructure & security (may include): hosting/database, CDN/WAF (for delivery and protection), and error/logging systems (for troubleshooting). We aim to minimize collection and use it only for reliability and security.
- We may disclose necessary information to service providers (e.g., request logs, basic identifiers) solely to provide the service, maintain security, comply with law, and troubleshoot issues.
4. Cookies & Local Storage
We may use cookies or local storage to keep you signed in, remember preferences (e.g., language/theme), and prevent abuse.
You can clear cookies/site data in your browser to sign out or reset preferences.
5. Data Retention & Deletion
We retain data only as long as necessary to provide the service, comply with legal obligations, and resolve disputes.
- Account data: retained while your account is active; if you request deletion, we will process it within a reasonable period (unless required otherwise by law).
- Logs/security records: may be retained for a period for security auditing and troubleshooting.
6. Your Rights & Choices
You may access, correct, or delete your information, or withdraw certain permissions (subject to service requirements).
- Request account deletion/data export: contact us via email below (include your sign-in email for verification).
- Revoke Google access: manage in your Google Account security settings.
7. Children’s Privacy
The service is not directed to children under 13 (or the minimum age required by law in your jurisdiction). We do not knowingly collect personal information from children.
If you believe a child has provided personal information, contact us and we will investigate and delete it promptly.
8. Security
We use reasonable technical and organizational measures to protect information, such as encrypted transport (HTTPS), access controls, least privilege, and security monitoring.
However, no method of transmission or storage is 100% secure. If a security incident occurs, we will respond and notify as required by applicable law.
9. International Transfers & Compliance
Depending on where you access the service, data may be processed in different countries/regions (e.g., where hosting/security providers operate). We take reasonable measures to protect data and comply with applicable laws.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Continued use after changes means you understand and accept the updated policy.