Privacy policy

Last updated: 16 September 2026

Awesome Report ("the service") is operated by Yun Chu, a sole trader in

Australia. Questions about this policy: awesome.report.ai@gmail.com.

What we collect

When you sign in with Google

We ask Google only for openid, email and profile. We do not request

access to your Gmail, Drive, Calendar or any other Google service, and we

cannot read them.

When you use the service

Automatically

addresses, request times and browser user-agent strings

We do not use advertising trackers, analytics pixels or third-party cookies.

The only cookies we set are the ones that keep you signed in and remember which

workspace you are viewing.

Why we collect it

We do not sell personal information. We do not share it for advertising.

Who else sees it

The service runs on infrastructure operated by others. Each of these

necessarily processes some of your data:

about what you do here.

servers.

email and billing details and hold your card. We never see your card number.

We do not give your information to anyone else unless we are legally required

to.

Where it is stored

Your data is stored and processed in the United States, not in Australia.

Our application servers run in Vercel's us-east-1 region. By using the

service you accept that your information is handled overseas.

Reports you publish

A report is private to your workspace unless you publish it.

Publishing creates a separate, unguessable link. **Anyone holding that link can

read the report without signing in.** There is no password and no second

factor. Published pages are marked so search engines do not index them, but a

link that is shared or forwarded cannot be un-shared — you can only revoke it,

which stops the link working from that moment.

Do not publish anything you would not be comfortable becoming public.

How long we keep it

and API key in them. This cannot be undone.

Your choices

reports, your workspaces, your keys.

about your information.

Security

Sign-in is handled by Google; we never see your password. Sessions are signed

and expire. API keys are stored as hashes, so a copy of our database would not

yield a working key. Traffic is encrypted in transit.

No service is perfectly secure, and we do not claim otherwise.

Changes

If this policy changes materially we will update the date at the top. Continued

use after a change means you accept the new version.