Effective September 30, 2026
Privacy Policy
This policy describes JaNiya’s Study Lab, a personal biomedical-sciences study application operated by JaNiya Ulysse, and its optional Google Drive integration. The study application is private; this separate public site provides information only.
Google data and permissions
The integration requests https://www.googleapis.com/auth/drive.file. This provides per-file access to files created by the application or specifically made available to it by the user, including through Google Picker. It does not request unrestricted access to the entire Drive.
The application reads selected destination-folder identifiers, names and type, and metadata for accessible application files and folders, including file IDs, names, parent-folder IDs and Drive viewing links. It creates study-material copies and course/lecture folders, locates existing copies to avoid duplicates, and may move those copies within the selected destination. The current sync implementation uploads Study Lab material contents to Drive; it does not download arbitrary Drive file contents.
After authorization, the application also attempts to retrieve the connected account’s email address from Google’s user-information endpoint and stores it if Google returns it. No separate email or profile scope is requested by the current connection flow. The application does not request Gmail, contacts or calendar access, and does not receive your Google password.
Why access is used
Drive access is optional and is used to maintain an independent Drive copy of eligible materials created or uploaded in the private Study Lab, organize those copies, and display synchronization status. The integration is a copy/organization workflow; it is not a general two-way Drive editor. Native editable notes are not automatically exported to Drive by the current implementation.
Credentials and protection
A Google OAuth refresh token is stored in the private application database to obtain short-lived access tokens without asking the user to authorize every sync. The refresh token is encrypted before storage using AES-256-GCM with a random initialization vector. Its encryption key and OAuth client secret are read from server-side hosting configuration, separately from the database record.
Access tokens are obtained when needed and are not persisted in the connection database by the current implementation. A short-lived access token is sent to the authenticated browser for Google Picker. The client ID and Picker API key are also supplied to that browser; the refresh token, client secret and token-encryption key are not returned by that endpoint. Google API requests use HTTPS. The private application uses account-restricted hosting and owner-filtered records. These measures do not guarantee absolute security, and this policy does not claim that all stored study content is application-encrypted.
Stored records
Connection records may include the account email when available, an owner identifier, encrypted refresh token, selected root-folder ID and name, and creation/update timestamps. Sync records may include the Study Lab material ID, Drive file ID and viewing link, destination folder path, material fingerprint, status, error message, attempt count and update time. Study Lab separately stores uploaded files and their names, types, sizes, course/category and creation time. Copies sent to Drive may carry application metadata identifying the source material, course, lecture, week and fingerprint.
Sharing and sale
Google user data is not sold. The Drive integration sends authorization and file requests to Google and stores connection and sync records using the application’s hosting/database infrastructure. It does not publish these records on this information site or create public Drive sharing permissions. Existing Drive folder permissions can affect who can view copies placed there; the user controls those permissions in Google Drive.
The Drive-sync implementation does not send Google OAuth tokens or retrieved Drive metadata to an AI provider, advertisers or marketing services. Separate study-generation features may send user-selected Study Lab materials to an AI service when used; uploading or syncing those materials does not make them public. Infrastructure providers process data as needed to operate their services.
Revoke access and request deletion
To disconnect Google access, visit Google Account’s third-party connections, select the Study Lab connection, and remove its access. The current application has no in-app disconnect control. Revocation prevents further authorized Drive access after Google invalidates the credentials, but does not automatically erase the stored connection/sync records, Study Lab originals or existing Drive copies.
Connection and sync records have no automatic expiration or scheduled deletion in the current implementation and remain until manually removed or replaced. Contact the operator to request removal of stored connection information or other application data. There is currently no self-service account-wide deletion process or guaranteed deletion timetable.
Deleting an uploaded material in Study Lab removes its stored file and material record through the application’s deletion function. It does not automatically delete the corresponding Drive copy or associated sync-history record. Delete Drive copies directly in Google Drive if desired. No verified backup-purge schedule is represented here.
This public information site
This site has no application database, sign-in, Google integration, analytics, forms, embedded third-party services or application-set cookies. The hosting platform may process ordinary request information to deliver and protect the site.
Contact
For privacy questions or deletion requests, contact JaNiya Ulysse at janiyaulysse@gmail.com.