Verification Code Helper

Privacy Policy

Effective September 30, 2026

This policy describes the personal, self-hosted Verification Code Helper application and this information website.

Access and use

With the Google account owner's authorization, the application accesses Gmail message metadata and message contents. It uses that data to identify supported verification messages, extract codes and links, provide selected account or subscription notifications, and parse receipts. Gmail modify permission also allows the application to mark processed messages as read. The application stores OAuth tokens to maintain this access; it does not store the Google account password.

Storage and retention

OAuth tokens, extracted codes and links, receipt records, processing history, and operational logs are stored on the operator's private infrastructure. Diagnostic email samples may be retained for troubleshooting. Private infrastructure backups may contain copies. Retention varies by record type; revoking Google access does not itself delete existing application records, backups, Telegram messages, or YNAB records.

Sharing

Selected verification codes, links, notifications, and receipt details may be delivered through Telegram to users approved by the operator. When the optional YNAB integration is enabled and a transaction is approved, receipt-derived transaction details are sent to the configured YNAB account. Telegram and YNAB process the information they receive under their own policies. Data may also be copied to the operator's private backup infrastructure.

Google user data is used for these user-facing features and their operation. It is not sold, used for advertising, or used to train general-purpose AI models. Verification Code Helper's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Control and deletion

You can revoke the application's access through your Google Account connections. Contact the operator through your existing private Telegram conversation with them or the support address displayed on Google's consent screen to request deletion of data on the operator's infrastructure. Copies held in Telegram or YNAB are managed separately through those services.

Authorization callback

The separate reauth.cronx.dev endpoint receives Google authorization responses through Cloudflare Tunnel and forwards them to the private application server. The server exchanges the one-use authorization code with Google, verifies the configured account, and stores the resulting tokens privately. Cloudflare processes callback traffic and request metadata to deliver and protect this endpoint.

This website

This website contains application information only. It has no login form and does not receive Gmail tokens or mailbox contents. Cloudflare hosts the pages and may process request metadata, including IP addresses, to deliver and protect the website. These pages do not include advertising or analytics scripts.

Contact and updates

The operator is the person who invited you to use this private application. Use your existing contact with them or the support address on Google's consent screen for privacy questions. Changes to this policy will be published on this page with an updated effective date.