HEALTH GEAR SHOP OS / CUSTODY

Data practices

Privacy notice

This notice covers HGS Custody Rehearsal and the HGS OS custody tool operated by Health Gear Shop. It does not replace the retail store’s privacy policy.

Last updated: September 17, 2026.

Information used

The custody tool uses the authorized Google account’s email and account identifier, explicitly selected folder identifiers, app-authorized file identifiers and names, file sizes, storage-quota information, encrypted archive bytes, hashes and verification receipts. OAuth access and refresh credentials allow authorized operations without repeatedly signing in.

Rehearsals use synthetic artifacts. Separately authorized production recovery archives may contain HGS OS canonical mapping records, product and variant identifiers, raw SKUs, evidence and decision history. Customer orders, payment data and marketplace authorization secrets are outside this custody archive’s current purpose.

Purpose and access limits

We use this information to verify the correct account and folder, store encrypted recovery copies, check independent readback, recover authorized records and preserve audit history. Google Drive access uses only drive.file, covering app-created or explicitly authorized files. The tool does not enumerate unrelated Drive contents or request Gmail or contacts access.

Storage, protection and service providers

Archives are encrypted before upload to the owner’s Google Drive folders. OAuth credentials are encrypted at rest in the custody credential store. Authorized local tooling currently performs rehearsal operations; controlled production provisioning uses Cloudflare services for isolated credential brokers, coordination and verification.

The owner recovery key is kept separately from the Drive copies. An authorized verification process also has a decryption identity so it can check archive contents. This is not a claim that the verification service cannot decrypt archives. Network communication with Google and Cloudflare uses HTTPS.

Google provides Drive storage and authorization. Cloudflare provides website hosting and, when provisioned, custody processing and storage. Access by authorized operators is limited to operation, recovery, requested support, security needs or legal requirements. We do not sell Google user data, use it for advertising or use it to train AI models. Use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

Retention, revocation and deletion

Recovery archives and verification history follow an append-only recovery policy. They remain until an explicit owner-reviewed retention or deletion decision; the tool does not automatically prune custody history.

You can revoke Google access in your Google Account’s third-party connections settings. Revocation stops future authorized access but does not itself delete previously stored Drive files or recovery records. Contact healthgearshop@gmail.com to request disconnection, deletion or information about retained records. Requests are reviewed against recovery, security and applicable legal obligations; existing independent backups may require separate action.

This public website

This site has no sign-in, upload form, application analytics or tracking scripts. Cloudflare may process normal request metadata, such as IP addresses, for delivery and security. Do not send passwords, OAuth tokens or recovery keys by email.

Changes and contact

Material changes will be reflected in this notice and its update date. Questions about these practices can be sent to healthgearshop@gmail.com.