MoonThing PDF Viewer
Privacy notice
MoonThing PDF Viewer is a restricted administrative service for approved users to list, preview, and download committed operational PDF reports. This notice explains how the service processes information.
Information we process
- Approved-user email addresses, owner or viewer roles, account status, and account administration timestamps.
- Authentication and abuse-prevention information, including keyed fingerprints derived from email addresses and network addresses, one-time-code hashes, attempt counts, and session metadata. The application database does not store plaintext one-time codes or raw session tokens.
- Security audit events for sign-in requests, successful sign-ins, and viewer access changes.
- Committed report metadata, including internal identifiers, location, collector and refiller names, report timestamps, filenames, and PDF sizes.
- Operational PDF files, which may contain information supplied by the report-generating system.
Google and Gmail data
The service authorizes one designated administrator Google account using basic account identity and Gmail send permission. Account identity is checked during authorization, and Gmail is used only to send one-time sign-in messages to approved users. These messages contain the recipient address, a six-digit code, its expiry notice, and security text.
The service does not request permission to read Gmail messages, contacts, Google Drive files, or mailbox contents. Google OAuth credentials are kept as server-side encrypted secrets and are not included in the browser application. MoonThing's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
How information is used
Information is used to authenticate approved users, prevent abuse, administer access, maintain security history, list and search committed reports, validate stored PDF integrity, and provide PDF preview and download. Active approved owners and viewers can access all committed reports; only the owner can add or revoke viewers.
Service providers and disclosures
Google and Gmail process sign-in-message delivery. Cloudflare provides the Pages and Functions runtime, D1 database, private R2 object storage, and network security infrastructure. Gmail receives sign-in-message data but does not receive report metadata or PDF files from this service. Report access is limited to active approved users, and viewer-account details are available to the owner for access administration.
Cookies, code validity, and retention
The service uses a secure, HTTP-only, same-site session cookie. One-time codes expire after 10 minutes and authenticated sessions after 8 hours. Signing out or revoking a viewer invalidates the relevant session.
Some expired authentication and rate-limit records are removed opportunistically after later authentication activity. Revoked allowlist records, security audit records, report metadata, and PDFs do not currently have a fixed automated deletion period in this application. Gmail message retention is controlled by Google and the relevant mail accounts.
Security
The service uses keyed hashes and fingerprints for authentication records, hashed server-side session tokens, secure cookie attributes, authenticated same-origin APIs, private non-cacheable PDF responses, and stored-file size and ETag validation. No internet service can guarantee absolute security.
Your access and choices
The owner can approve or revoke viewer access. Revocation immediately blocks active portal sessions but does not automatically erase the inactive allowlist record or historical security events. Downloaded PDF copies are stored on the user's device and are outside the portal's direct control.
Contact
For privacy questions or requests concerning an approved account, contact dvendo.tech@gmail.com.