SS2.me
Privacy Policy
Last updated: 23 July 2026
Overview
This privacy policy explains how SS2.me handles personal information when you visit SS2.me or use an application or service operated by SS2.me that links to this policy. It includes specific disclosures about information received through our add-ons and integrations with Google APIs (“Google user data”).
Information we collect
We may collect information you provide directly, such as your name, email address, account information, support requests, and other information you choose to submit. When an application offers Google sign-in or a Google-connected feature, it only requests the Google permissions shown on the Google consent screen. Depending on the feature you choose and the permissions you grant, Google user data may include your basic Google account information (such as your name, email address, profile image, and Google account identifier), OAuth access or refresh tokens, and the Google service data needed to provide the feature you requested.
You can decline a requested Google permission, although the related feature may then be unavailable. We do not access Google user data beyond the permissions you grant.
Technical data
Like most websites, basic technical data may be processed automatically by the hosting platform or network providers, such as IP address, browser type, device information, and request logs. This data is generally used for security, performance, and troubleshooting.
Cookies and similar technologies
This website is not intended to rely on advertising cookies. However, essential technical cookies or similar storage may still be used by the browser, hosting platform, or embedded services if applicable.
How we use Google user data
Google user data is used only to:
- authenticate you and maintain your account or session;
- provide the Google-connected feature that you deliberately choose to use;
- maintain, secure, and troubleshoot that feature; and
- comply with applicable law.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, retargeting, personalised marketing, creditworthiness, or lending decisions.
When and with whom Google user data is shared
We do not sell Google user data or transfer it to advertising platforms, data brokers, or information resellers. We disclose Google user data only in the following limited circumstances:
- Service providers: to hosting, database, security, and infrastructure providers that process data on our behalf solely to operate and secure the application. They may only process the data under our instructions and must protect it.
- Google: when communicating with Google services at your direction or as necessary to provide the Google-connected feature.
- Legal and security reasons: when disclosure is required by applicable law or is reasonably necessary to investigate fraud, abuse, or a security incident.
- Business transfer: as part of a merger, acquisition, or sale of assets only after obtaining any explicit prior consent required by the Google API Services User Data Policy.
- At your direction: when you clearly ask us to share specific data and consent to that disclosure.
No other transfer or disclosure of Google user data is permitted. Humans do not read Google user data unless you have affirmatively agreed to the review of specific data, it is necessary for security or legal compliance, or the data has been aggregated and anonymised for lawful internal operations.
How sensitive data is protected
We use technical and organisational safeguards designed to protect sensitive data:
- data is encrypted in transit using HTTPS/TLS, and stored Google user data, including OAuth tokens, is encrypted at rest;
- OAuth client secrets and other credentials are kept in restricted server-side secret storage and are not exposed in public source code or client-side application code;
- access is limited using authentication, role-based access controls, and the principle of least privilege;
- we request the narrowest Google OAuth scopes needed for the user-facing feature and limit collection and retention to what is necessary;
- systems and dependencies are maintained and security-relevant activity is monitored and investigated; and
- service providers that handle data on our behalf are required to apply appropriate confidentiality and security protections.
No method of transmission or storage is completely secure, but we review and update these safeguards in light of the nature and sensitivity of the data.
Data retention
We retain personal information only for as long as necessary to provide the relevant service, protect it, resolve disputes, and meet legal obligations. Google OAuth tokens are kept only while your Google connection is active or while needed to provide the feature you requested. When access is revoked or no longer needed, tokens are revoked where applicable and deleted from our systems. Residual copies may remain temporarily in encrypted backups until they are overwritten under the normal backup cycle.
Your choices and deletion
You can disconnect the Google integration within the relevant application, where that option is available, or revoke its access through your Google Account connections. You may also use the contact option in the relevant application to request access to, correction of, or deletion of your personal information and Google user data. Revoking Google access stops new access but does not by itself delete information already stored, so please make a deletion request if you also want stored data removed.
Other websites and services
This website and related applications may link to third-party websites. Once you leave a service covered by this policy, the third party’s privacy policy and practices apply.