We collect user profile metadata returned by Google Sign-In, including names, email addresses, unique Google account IDs, and profile picture URLs. This information is used to provision secure access sessions inside the Simplify network.
We use a secure cookie named `simplify-session` containing encrypted session tokens to manage authenticated sessions. These cookies are marked HttpOnly and are kept strictly local to your current browsing interface. No cross-site tracking or advertising cookies are utilized within the Intranet.
We do not sell, distribute, or lease your private data, credentials, or session history to third parties. Google Sign-In requests identity scopes only. Workspace permissions for Gmail, Google Drive, Calendar, or Contacts are requested separately when an internal widget needs them and are handled through server-side session controls.
We protect organizational data with HTTPS, HttpOnly session cookies, encrypted session tokens, strict frame-ancestor directives, centralized security headers, and automated security smoke checks for protected routes and build artifacts.
You can query, correct, or request deletion of your session data or intranet profile records at any time by raising an operations ticket through the IT Administration portal.