Privacy policy
Last updated 6 October 2026
Factlore ("we") is a web application at factlore.io that shows a company's administrators who has access to which systems. This policy describes the data Factlore handles, why, and how it is protected and deleted. Questions: [email protected].
1. Who this applies to
Factlore has two kinds of data subjects.
- Customers. The company that signs up and its administrators, who connect their systems.
- People in the customer's systems. Employees, contractors and guests whose accounts appear in the systems a customer connects. These people may never use Factlore. For their data, the customer decides the purpose and Factlore processes it on the customer's behalf.
2. Data Factlore receives
From the customer when signing up: the administrator's name and email address, and the organisation name.
From connected systems, read-only: account and access information only, such as names, email addresses, account status, group membership, administrator roles, and which third-party apps an account has authorized. Factlore does not read the content of email, files, documents, calendars or messages.
From files the customer uploads: a people list or user export, for example a CSV of current and former staff with names, email addresses, department and dates.
3. Data received from Google APIs
A Google Workspace administrator can connect their domain to Factlore. Factlore then requests these read-only scopes:
| Scope | What Factlore reads | Why |
|---|---|---|
admin.directory.user.readonly | User list: name, primary email, suspended and archived status, administrator flags, last login time, deletion time. | To list the accounts that exist and whether each is active, suspended or deleted. |
admin.directory.group.member.readonly | Groups and their members and owners. | To show access that comes through group membership and who owns a group. |
admin.directory.rolemanagement.readonly | Administrator role assignments. | To show who holds administrator privileges. |
admin.reports.audit.readonly | Sign-in events and events recording that a user authorized or revoked a third-party app. | To show when an account was last used and which third-party apps an account has authorized. |
Factlore does not request access to Gmail, Drive, Calendar or other user content, and with these scopes it cannot create, change or delete anything in Google Workspace.
Limited Use. Factlore's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- Factlore uses Google user data only to provide and improve the user-facing features described on this page: showing the customer's administrators who has access to what.
- Factlore does not sell Google user data, and does not use or transfer it for advertising, including personalised, retargeted or interest-based advertising.
- Factlore does not transfer Google user data to third parties, except to the processors listed in section 6 as necessary to run the service, to comply with law, or as part of a merger or sale with notice to the customer.
- No person at Factlore reads Google user data unless the customer asks for support and agrees to it, it is needed to investigate abuse or a security incident, or the law requires it.
- Factlore does not use Google user data to develop, improve or train generalised AI or machine-learning models.
4. How data is used
- To show administrators the accounts, access relationships, owners and evidence in their own organisation.
- To run the leaver audit: list what a departed person still has, and check again the next day.
- To match accounts across systems to the people on the customer's people list. Matches that are uncertain are put to a person to confirm.
- To send email to administrators and, when the customer chooses, to account holders (for example a question about whether an account is theirs).
- To secure and maintain the service.
Factlore does not make decisions about people automatically. Every permission it requests today is read-only, and under them it does not change access in any connected system.
5. Storage, security and retention
- Each customer's data is stored separately from other customers' data and is enforced by the database, not only by application code.
- Connections to Factlore use TLS. Credentials and tokens for connected systems are encrypted at rest under a key held per organisation.
- Factlore does not write credentials, tokens or customer identifiers to its logs.
- Data is kept while the customer's account is active. Temporary synchronisation data is deleted when no longer needed.
- When a customer disconnects a system, Factlore stops reading from it. The customer can also revoke Factlore's access at any time in their Google Admin console or the other provider's console.
6. Who else handles data
| Processor | Purpose | Data |
|---|---|---|
| OVH SAS (OVHcloud, France) | Server and database hosting | All data stored by Factlore, encrypted in transit. |
| Cloudflare, Inc. (USA) | DNS and web traffic proxying for factlore.io | Requests to Factlore pass through Cloudflare's network and are encrypted in transit. |
| Resend | Sending email | Recipient addresses and message content, retained by Resend for 30 days. Messages do not contain access details. |
Factlore does not sell personal data.
7. Deletion and your rights
A customer can ask for its data to be deleted by emailing [email protected] from an administrator address. Factlore verifies the request, deletes the data and confirms by email. Some audit records may need to be kept where law or a compliance obligation requires it, and Factlore will say which.
If you are a person whose account appears in a customer's systems, you can ask Factlore for access to, correction of or deletion of your data. Because the customer controls that data, Factlore may refer your request to the customer. Where the GDPR applies, you also have the right to complain to your data protection authority.
A customer can export its data on request.
8. Changes
If this policy changes in a way that affects how Google user data is used, Factlore will notify customers' administrators by email before the change takes effect. The date at the top shows the latest version.
If Factlore later asks for a permission that allows a change in a connected system, this policy is updated first, and the permission applies to a customer's connection only after that customer's administrator approves it.
9. Contact
Factlore, [email protected]