Privacy Policy

Gapivo Sign-In (auth.gapivo.com) signs you in to Gapivo applications using your Google account.

This service reads email and name from Google. Only the session JWT is stored in a browser cookie (24-hour expiry). No user data persists server-side.

What we read from Google

We request only the openid, email and profile scopes. We never request access to your Google contacts, calendar, files, or mail, and we cannot act on your behalf in Google.

What we store

Retention

The session token expires 24 hours after sign-in, after which it stops working and you sign in again. Signing out at /logout removes the cookie from your browser immediately. Because we hold no server-side session record, there is nothing further for us to delete.

Sharing

We do not sell, share, or transfer your data to third parties. Your email and name are readable only by the Gapivo applications you sign in to.

Contact

For privacy questions, contact the Gapivo platform operator at privacy@gapivo.com.