Data and trust
Privacy policy
Quackdex is a single-owner application that builds a private, searchable index of Google Contacts. This policy explains what the service accesses, why it accesses it, and how the data is handled.
Google data we access
When the owner chooses to connect Google, Quackdex requests the identity scopes openid email profile and the read-only Contacts scope https://www.googleapis.com/auth/contacts.readonly. Quackdex does not request the write-capable Contacts scope.
Quackdex reads contact information made available through the Google People API, such as names, email addresses, phone numbers, organizations, addresses, dates, relationships, URLs, and related provenance supplied by Google.
How we use the data
- To authenticate the configured owner of this application.
- To build and refresh a searchable local contact index.
- To show contact values and their source provenance to the owner.
- To report safe synchronization counts, timestamps, and error classes.
Google Contacts remains read-only. Quackdex does not create, edit, delete, merge, or otherwise write contact data back to Google. Quackdex never changes Google Contacts.
Storage and sharing
Google data, synchronization observations, source snapshots, and derived contact indexes are processed on the server and stored in the application's configured database. OAuth credentials are encrypted before persistence. Access tokens, refresh tokens, raw provider payloads, and synchronization cursors are not sent to the browser.
Quackdex does not sell Google data or use it for advertising. Data may be processed by the hosting and database providers needed to run the service, under the operator's configuration, and may be disclosed when required by law.
Retention and local reset
Quackdex retains source evidence and synchronization history so that derived indexes can be rebuilt and explained. The local reset feature rebuilds the derived canonical index without contacting Google; it intentionally preserves source history, completed sync records, and audit history.
For a complete deletion request, contact the Quackdex operator before using the local reset feature, because reset is not a full erasure operation.
Security
Quackdex uses HTTPS in production, keeps Google API access on the server, encrypts stored OAuth credentials, and limits access to the configured owner. No online service can guarantee absolute security, so credentials should never be shared through chat, issues, logs, or source control.
Changes and contact
This policy may be updated when the service or its data practices change. The effective date above identifies the current version. For privacy questions or deletion requests, contact the Quackdex operator through the service owner.