Legal
Privacy Policy
This site and the apps listed below are run by Pradip Dobariya, an independent software consultant based in Rajkot, India. This policy explains what personal data I collect, why, how long I keep it, and how you can have it removed. You can reach me at any time at [email protected].
What this policy covers
- This website, pradipdobariya.com.
- Private portfolio links I send to prospective clients.
- MGT Journal, the work planning app at jammy.pradipdobariya.com, and the team workbook that runs the same app at workbook.masterglobaltech.com, including their optional calendar connections.
Work I do under a signed contract for a client is governed by that contract, not by this policy. In those projects the client is the data controller and I act on their instructions.
This website
There is no sign up, no contact form, no advertising and no analytics or tracking scripts on the public pages. I do not set cookies to follow you around. A session cookie is only set if you sign in to the admin area, which is for me alone.
The site is served through Cloudflare and runs on a server in the United Kingdom. Like any web server, it keeps short lived request logs that can include your IP address, the page you asked for, the time, and your browser user agent. These logs are used to keep the site up and to investigate abuse, and they are not used to build a profile of you.
If you email me, I keep that email and your address so I can reply and keep track of our conversation.
Private portfolio links
When I share confidential work with a prospective client, I create a private link for that one person. Against that link I store the name and email address you gave me, when the link was first opened, when it was last opened, and how many times. I use this to know whether the work has been seen and to expire or withdraw access.
These links carry an expiry and are often set to delete themselves. You can ask me to withdraw or delete a link and its record at any time and I will do it the same day.
Google user data
MGT Journal can connect to your Google Calendar so that work you plan in the app appears in your own calendar. The connection is optional. The app is fully usable without it, and nothing below happens unless you choose to connect and grant permission on Google's own consent screen.
What I ask for and why
The app asks for three permissions, and no more:
openidandemail, so the app knows which Google account you connected and can show it to you.https://www.googleapis.com/auth/calendar.app.created, which reaches only calendars this app itself created.
That last one is deliberately the smallest permission that does the job. The app cannot see your existing calendars, or any event in them. Google enforces that limit, it is not simply a promise in my code. Within the calendar it creates, the app uses the permission to:
- create a calendar of its own inside your Google account the first time you connect, so app entries never mix with your own;
- create, update and delete entries in that calendar when you add, change or finish work in the app;
- read back the entries it created so the two stay in step.
The sync is one way, from the app to Google. Nothing from your Google Calendar is copied into the app.
What is stored, and where
- Access and refresh tokens from Google, so the connection keeps working without asking you to sign in again. These are encrypted before they are written to the database.
- The email address of the connected Google account, read once from Google's OpenID userinfo endpoint, so you can see which account is connected and disconnect the right one.
- The id of the calendar the app created and the ids of the entries it created, so it can update the right entries later.
The content written into those entries is your own work from the app, such as a card title, its notes and its date. It is stored on a server in the United Kingdom.
What I never do with it
- I never sell Google user data or share it with data brokers, advertisers or any third party for their own use.
- I never use it for advertising or profiling.
- I never use it to train machine learning or AI models, mine included.
- No person reads your calendar data, except where you have asked me to help with a specific problem and given permission, or where the law requires it.
Limited Use
MGT Journal's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Turning it off and deleting the data
You can disconnect the calendar inside MGT Journal at any time. When you do, the stored tokens and the record of the connection are deleted. You can also revoke access from your Google Account at myaccount.google.com/permissions, which stops the app immediately.
Entries the app already created stay in your calendar so you do not lose your plan. You can delete that calendar yourself in Google Calendar, or email me and I will remove them for you.
Microsoft 365 and Outlook
MGT Journal can connect to an Outlook calendar in exactly the same way, and the same promises above
apply to it. Microsoft asks you to grant Calendars.ReadWrite, User.Read and
offline_access. The app uses them only to create its own MGT WORK
calendar in your account, to manage the entries it put there, and to read your email address so you
can see which account is connected. It does not read or change your other calendars, and the tokens
are encrypted at rest just as the Google ones are. Disconnecting in the app deletes them, and you can
revoke access yourself from your Microsoft account.
MGT Journal accounts
If you have an account in the app, I store your name, email address, a hashed password, and the work content you put into the app. Passwords are stored only as a hash and cannot be read back. Account data is kept while your account is open, and is deleted within 30 days of you asking me to close it.
Who else can see your data
I do not sell personal data. It is handled by a small number of suppliers who help run the service: the hosting provider for the server, Cloudflare for traffic and protection, and Google where you have connected your calendar. Each of them only handles what is needed to do their part. I may also disclose data where the law requires it.
Keeping it safe
Traffic is encrypted in transit with HTTPS. Google tokens are encrypted at rest. Access to the servers and databases is limited to me. Private portfolio links use long random tokens that are stored as a hash, so a copy of the database does not reveal a working link. No system is perfect, and if a breach ever affects your data I will tell you and the relevant authority promptly.
Your rights
You can ask me for a copy of the personal data I hold about you, ask me to correct it, or ask me to delete it. You can also object to how I use it or ask me to restrict it. Email [email protected] and I will reply within 30 days. If you are in the UK, the European Union or Australia, you also have the right to complain to your local data protection authority.
Children
These services are meant for business use and are not directed at children under 16. I do not knowingly collect their data.
Changes
If this policy changes in a way that affects you, I will update the date at the top and, where the change is significant and I have your email address, tell you directly.
Questions about any of this go to [email protected]. See also the Terms and Conditions.