This application is used for private research into Google OAuth consent screens and account notification emails.
Information accessed
Depending on the test, the application may request basic profile information, an email address, Google Drive metadata, or Gmail permissions. Tests use researcher-controlled accounts. Current testing checks permission grants and may authenticate to Gmail over IMAP, then disconnect without reading messages.
Data handling
OAuth credentials and tokens are handled through Google OAuth Playground or local test scripts. The research website does not collect Google passwords or tokens.
Notification emails, screenshots, and test results may be retained as research evidence. They may contain test-account email addresses, app names, permission details, and timestamps.
Sharing and retention
Relevant evidence may be submitted privately to Google’s Vulnerability Reward Program. Research records are retained while needed to investigate and document the issue. Tokens are not included in reports.
Removing access
You can revoke permissions through Google Account third-party connections. Revocation stops future authorised access but does not delete existing research records.
Contact
For privacy questions or deletion requests: georeith@gmail.com