Effective date:
This policy explains how V2EX accesses, uses, stores, and shares information received when a user chooses to sign in with Google. It applies specifically to the V2EX Google sign-in integration.
V2EX requests only the Google OAuth email scope. During sign-in, V2EX receives and processes:
The access token is used to make a single request to Google's UserInfo service during the sign-in attempt. The authentication handler does not request offline access, does not receive or retain a refresh token, and does not store the access token in the V2EX account database.
Google's UserInfo response may contain additional technical or account fields. V2EX does not use or persist Google profile fields such as the user's name, profile picture, locale, given name, or family name. V2EX does not request access to Gmail, Google Contacts, Google Drive, Google Calendar, or other Google product data.
V2EX uses the Google-provided email address and verification status only to:
V2EX does not use Google user data for advertising, profiling, credit decisions, or surveillance.
For a V2EX account created or accessed through Google sign-in, V2EX stores:
These records are part of the V2EX account. Google access tokens and Google profile data are not stored as part of the account.
V2EX does not sell Google user data or share it with data brokers or advertising platforms.
V2EX may disclose or allow service providers to process the registered email address only when reasonably necessary to operate V2EX, provide account-related communications or support, protect the service and its users, investigate abuse or security incidents, or comply with applicable law. Service providers acting for V2EX are expected to handle the information only for the applicable service purpose and subject to appropriate confidentiality and security obligations.
V2EX's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
The registered email address and related account records are retained while needed to operate and secure the V2EX account, resolve disputes, enforce applicable agreements, and comply with legal obligations. Security, anti-abuse, transaction, or audit records may be retained when reasonably necessary for those purposes.
Revoking V2EX's access from the Google Account permissions page prevents future authorization through that grant, but it does not by itself delete the V2EX account or information already stored by V2EX.
Where available, users may update their registered email address through V2EX account settings. To ask about access, correction, deletion, or account closure, contact [email protected] from the registered email address.
V2EX uses HTTPS for the Google authorization flow and takes reasonable technical and organizational measures to protect account information against unauthorized access, alteration, disclosure, or destruction. No method of transmission or storage can be guaranteed to be completely secure.
Google sign-in begins only when the user chooses that sign-in method and selects a Google Account. Users can review or revoke V2EX's Google authorization through Google Account permissions. Google's handling of information is governed by the Google Privacy Policy.
V2EX may update this policy when the Google sign-in integration or applicable requirements change. Material changes to the way V2EX uses Google user data will be disclosed, and consent will be obtained when required, before the new use begins. The effective date above identifies the current version.
Questions or requests concerning this policy or V2EX's handling of Google sign-in data may be sent to [email protected].