Privacy policy
trendpluto · last updated 28 August 2026
trendpluto is a private trend-intelligence engine operated by an individual (contact: [email protected]). It has no public accounts and no general sign-up. The dashboard at trendpluto.com is reachable only by a fixed allowlist of Google accounts maintained by the operator; everyone else is refused at sign-in.
What we receive from Google
Signing in uses Google Sign-In with the openid, email and profile scopes. Google returns a signed ID token containing your email address, whether that address is verified, your name, profile picture URL and Google account ID. We request no other scopes and hold no Google API access token, so we cannot read your Gmail, Drive, Calendar, contacts or any other Google service.
What we do with it
- The email address is checked against the allowlist. If it is not on the list, sign-in is rejected and nothing about the attempt is retained beyond an ordinary server log line.
- If it is on the list, the server issues a session token containing that email and an expiry. The token is held in your browser's
sessionStorageand is discarded when you sign out or close the tab. It expires after 24 hours regardless. - Name, profile picture and account ID are used only to render the Google sign-in button in your browser. They are never sent to our server and are never stored.
There is no user profile, no account record and no database row created for a person. The only place your email exists on the server side is in configuration — the allowlist itself — and inside the short-lived session token you carry.
Operational logs
The engine records an audit line for each API call: method, path, response status, row count and duration. These lines identify the calling product (an API client, not a person) and are deleted after 30 days. They exist so an empty or failing data feed can be diagnosed.
What we never do
- We do not sell, rent or trade personal data.
- We do not share it with third parties for their own purposes.
- We run no advertising, ad networks or cross-site tracking.
- We do not use Google user data to develop, improve or train any model.
trendpluto's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Where the data lives
The engine runs on Microsoft Azure (Central US) and the dashboard is served as static files by Cloudflare Pages. Those providers process traffic on our behalf as infrastructure; neither receives Google profile data from us.
Your choices
Sign out to destroy the session immediately, and revoke trendpluto's access at any time from your Google account permissions. To be removed from the allowlist, or to ask what is held about you, email the address above; removal takes effect on the next request, because the allowlist is re-checked on every one.
Changes
If this policy changes, the date at the top changes with it. Material changes will be communicated directly to the allowlisted accounts, since that is the entire audience.