← Back to PDF Viewer

Privacy notice

Last updated: August 2026

MoonThing PDF Viewer is a restricted administrative service for approved users to list, preview, and download committed operational PDF reports. This notice explains how the service processes information.

Information we process

Google and Gmail data

The service authorizes one designated administrator Google account using basic account identity and Gmail send permission. Account identity is checked during authorization, and Gmail is used only to send one-time sign-in messages to approved users. These messages contain the recipient address, a six-digit code, its expiry notice, and security text.

The service does not request permission to read Gmail messages, contacts, Google Drive files, or mailbox contents. Google OAuth credentials are kept as server-side encrypted secrets and are not included in the browser application. MoonThing's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

How information is used

Information is used to authenticate approved users, prevent abuse, administer access, maintain security history, list and search committed reports, validate stored PDF integrity, and provide PDF preview and download. Active approved owners and viewers can access all committed reports; only the owner can add or revoke viewers.

Service providers and disclosures

Google and Gmail process sign-in-message delivery. Cloudflare provides the Pages and Functions runtime, D1 database, private R2 object storage, and network security infrastructure. Gmail receives sign-in-message data but does not receive report metadata or PDF files from this service. Report access is limited to active approved users, and viewer-account details are available to the owner for access administration.

Cookies, code validity, and retention

The service uses a secure, HTTP-only, same-site session cookie. One-time codes expire after 10 minutes and authenticated sessions after 8 hours. Signing out or revoking a viewer invalidates the relevant session.

Some expired authentication and rate-limit records are removed opportunistically after later authentication activity. Revoked allowlist records, security audit records, report metadata, and PDFs do not currently have a fixed automated deletion period in this application. Gmail message retention is controlled by Google and the relevant mail accounts.

Security

The service uses keyed hashes and fingerprints for authentication records, hashed server-side session tokens, secure cookie attributes, authenticated same-origin APIs, private non-cacheable PDF responses, and stored-file size and ETag validation. No internet service can guarantee absolute security.

Your access and choices

The owner can approve or revoke viewer access. Revocation immediately blocks active portal sessions but does not automatically erase the inactive allowlist record or historical security events. Downloaded PDF copies are stored on the user's device and are outside the portal's direct control.

Contact

For privacy questions or requests concerning an approved account, contact dvendo.tech@gmail.com.