Privacy policy
Awesome Report ("the service") is operated by Yun Chu, a sole trader in
Australia. Questions about this policy: awesome.report.ai@gmail.com.
What we collect
When you sign in with Google
- your email address
- your name and profile picture, if your Google account has them
We ask Google only for openid, email and profile. We do not request
access to your Gmail, Drive, Calendar or any other Google service, and we
cannot read them.
When you use the service
- the reports you create, including all their content
- the names and tags you give them
- API keys you generate — stored only as a one-way hash, never the key itself
- which workspaces you belong to
Automatically
- standard server logs kept by our hosting provider, which include IP
addresses, request times and browser user-agent strings
We do not use advertising trackers, analytics pixels or third-party cookies.
The only cookies we set are the ones that keep you signed in and remember which
workspace you are viewing.
Why we collect it
- Your email identifies your account and is how you sign in.
- Report content is the service. We store it so we can show it back to you.
- Logs are used to keep the service running and to investigate abuse.
We do not sell personal information. We do not share it for advertising.
Who else sees it
The service runs on infrastructure operated by others. Each of these
necessarily processes some of your data:
- Google — sign-in only. They tell us your email; we tell them nothing
about what you do here.
- Vercel — hosting and request logs. Your data is processed on their
servers.
- Neon — the database holding accounts, workspaces and report metadata.
- Vercel Blob — storage for the report pages themselves.
- Stripe — payments, if you subscribe to the paid plan. They receive your
email and billing details and hold your card. We never see your card number.
We do not give your information to anyone else unless we are legally required
to.
Where it is stored
Your data is stored and processed in the United States, not in Australia.
Our application servers run in Vercel's us-east-1 region. By using the
service you accept that your information is handled overseas.
Reports you publish
A report is private to your workspace unless you publish it.
Publishing creates a separate, unguessable link. **Anyone holding that link can
read the report without signing in.** There is no password and no second
factor. Published pages are marked so search engines do not index them, but a
link that is shared or forwarded cannot be un-shared — you can only revoke it,
which stops the link working from that moment.
Do not publish anything you would not be comfortable becoming public.
How long we keep it
- Reports are kept until you delete them or delete your account.
- Deleting a report removes its content and its public link immediately.
- Deleting your account removes your profile, your workspaces, and every report
and API key in them. This cannot be undone.
- Server logs are kept by our hosting provider on their own schedule.
Your choices
- See your data — everything we hold about you is visible in the app: your
reports, your workspaces, your keys.
- Delete a report — from the
⋯menu next to it. - Delete your account — in Settings. This removes everything.
- Ask us — write to awesome.report.ai@gmail.com with any request or complaint
about your information.
Security
Sign-in is handled by Google; we never see your password. Sessions are signed
and expire. API keys are stored as hashes, so a copy of our database would not
yield a working key. Traffic is encrypted in transit.
No service is perfectly secure, and we do not claim otherwise.
Changes
If this policy changes materially we will update the date at the top. Continued
use after a change means you accept the new version.