Privacy policy
What data Vigía sees, what it stores, for how long, and who answers for it.
The essentials in four sentences. Vigía only reads: it cannot change any setting in your Google Workspace because it does not request any write permission. It never asks for access to the content of Gmail, of Drive or of any file. The e-mail addresses of the people in your organisation that appear in a report are deleted automatically after 24 hours. When you disconnect, everything is deleted and access is revoked at Google.
Who the data controller is
The data controller is Diego Fariña, in a personal capacity, as the developer and operator of Vigía. Contact for any question about data or to exercise your rights: diego@diegofarina.com.
Vigía does not belong to any company and does not act on behalf of any organisation other than yours.
Vigía's two roles
The distinction matters because it determines who decides about each piece of data:
- Controller of the data of your own administrator account: the address you connect with and your primary domain. Vigía processes them in order to provide you with the service.
- Processor of the data of the other people in your organisation who appear in a report. The controller of that data is your organisation; Vigía processes it on your behalf, following your instructions, only to produce the report you asked for, and deletes it after 24 hours.
Legal basis
| Processing | Basis (GDPR) |
|---|---|
| Reading your Workspace configuration in order to generate the report | Your explicit consent, given on Google's screen (art. 6(1)(a)). It can be withdrawn at any time, and withdrawing it stops the processing. |
| Storing the score and the state of each control to show you how they change over time | Performance of the service you requested (art. 6(1)(b)). |
| Minimal technical logs so the service works and is secure | Legitimate interest (art. 6(1)(f)), limited to what is indispensable. |
The permissions requested, and what each one is for
All of them are read-only and none belongs to Google's 'restricted' category, which is precisely the one that would give access to the content of messages and files. This is the complete list, the same one you will see on the consent screen:
| Permission | What for |
|---|---|
openid |
The identifier of the Google session that authorises the connection. |
email |
Which administrator address connected, so it can be shown in the interface and the authorisation tied to your organisation. |
admin.directory.user.readonly |
List the accounts and their security metadata: 2-Step Verification enrolment, administrator role, last sign-in, suspension state, creation date, recovery details and organizational unit. |
admin.directory.domain.readonly |
List your verified domains, so SPF, DKIM, DMARC and MTA-STS can be checked for each one through public DNS. |
admin.reports.audit.readonly |
Read the audit log: which third-party applications have been authorised, recent administrative changes, and sign-in events. |
cloud-identity.policies.readonly |
Read the settings configured in your Admin console (Drive sharing, Gmail forwarding, password policy, session length, Marketplace and Groups) so they are checked automatically instead of by hand. |
profile is not requested: Vigía does not read your name or your photo.
What is stored, and for how long
| Data | What for | How long |
|---|---|---|
A vigia_theme cookie holding the value light or dark, and nothing else |
Remembering whether you chose the light or the dark theme, so these pages do not change the background on you when you leave the dashboard. It contains no identifier, it cannot be used to recognise you, and it only exists if you press the toggle: by default your operating system's preference is respected and nothing is stored | One year, or until you set it back to your system's theme |
| Your primary domain and your verified domains | Identifying your organisation and knowing what to check | Until you disconnect |
| The address of the administrator who connects | Showing you which authorisation is active and sending you the alerts | Until you disconnect |
| An OAuth refresh token, encrypted at rest (Fernet, AES-128 in CBC mode with HMAC) | Repeating the scheduled scan without asking you for consent again | Until you disconnect |
| The score, the counts and the result of each control (identifier and state) | Showing you the progress, the improvements and the regressions | Until you disconnect |
| E-mail addresses of the people in your organisation who appear as affected by a finding | So that you can tell who to act on | 24 hours, and then they are deleted automatically |
| The IP addresses your super administrators have signed in from, read from the login audit log, and the country they correspond to | Showing you where the accounts that control the whole tenant are normally signed in from, and warning you if a country appears in which no previous sign-in was on record | 24 hours, and then they are deleted automatically |
After those 24 hours the report still says how many accounts were affected by each finding, but no longer who. To see it again you only have to run a new scan.
About the people in your organisation
It is worth saying plainly: a report names employees of yours who have never used Vigía and have never consented to anything. That is why their information is the only kind with a short, automatic deletion deadline, and why it is the least possible: the e-mail address, the finding that affects them and —only in the case of super administrators— the IP address they signed in from, because without it there is no way to tell you that one of those accounts has started being used from somewhere else. Nothing more. It never includes the content of their messages, their files or the rest of their activity.
Those IP addresses never leave this server. The country is worked out here, with a local file: no geolocation service is queried, because doing so would mean sending your organisation's administrators' addresses to one more company.
What is never done
- Reading, storing or transmitting the content of e-mails, attachments or Drive files: the permissions that would allow it are not requested, so it is technically impossible.
- Changing any setting in your Workspace. There is no write path in the application; remediation goes no further than giving you the link to the screen where you act yourself.
- Selling your data, passing it on for commercial or advertising purposes, or using it to train artificial intelligence models.
- Using your data for anything other than showing you your own results.
Limited use of Google data
Vigía's use of information received through the Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically: the data is used only to provide and improve the user-facing functionality of the product, it is not transferred to third parties except as strictly necessary to provide the service or where the law requires it, it is not used for advertising purposes, and no person reads it, except with your explicit permission, for security reasons, to comply with the law, or when it is aggregated and anonymised.
The third parties involved
Vigía does not sell or pass on data, but providing the service involves these providers. All of them are listed, including those that only see technical metadata:
| Provider | What it sees | Why |
|---|---|---|
| Google (Admin SDK and Cloud Identity) | The read requests made to it | It is the source of the data being analysed |
| Cloudflare | The IP address and connection metadata of whoever visits the site; it terminates the TLS encryption | It publishes the site and protects it |
| Zoho (e-mail) | Your alert address and the subject and body of the message, which includes your domain name and the titles of your findings | Delivering the e-mail alerts you have switched on |
| Public DNS resolvers (Cloudflare 1.1.1.1, Google 8.8.8.8) | The domain names being queried | Checking SPF, DKIM, DMARC and the rest of the public records |
The list above is the four providers involved. The database that turns an IP address into a country is not one of them: it is a downloaded file, queried on this server, not a service, so it receives nothing. It uses DB-IP IP-to-Country Lite, published under CC BY 4.0, whose licence requires this attribution.
Vigía loads nothing from third parties in the browser: the fonts are served from this same domain and there are no scripts, analytics, telemetry or external images on any page. You can check this in your browser's network tab.
Your rights
You can exercise your rights of access, rectification, erasure, restriction, objection and portability at any time by writing to diego@diegofarina.com. The answer arrives within a maximum of one month.
Two of them, moreover, you can exercise yourself, immediately and without asking anybody's permission: erasure by pressing 'Disconnect', and objection by removing access from your own Google account. How to do it is in Your data.
If you consider that the processing is not right, you can complain to the data protection authority that applies to you: in Spain the Agencia Española de Protección de Datos (AEPD), in the United Kingdom the Information Commissioner's Office (ICO).
Security
- The refresh token is stored encrypted; the key lives outside the database.
- All traffic goes over HTTPS.
- The application has no write operation against the Google APIs.
- The minimum necessary is stored, and what expires is deleted with no human intervention.
Changes to this policy
If anything substantial changes —what data is processed, how long it is kept or which third parties are involved— the date in the footer will be updated and, if the change affects you, notice will be sent by e-mail to the connected administrator address.