Effective September 10, 2026
Kiki Gadget privacy policy
This policy describes how Kiki Gadget, maintained by Christian Coleman, uses account information when you choose to sign in and download files.
Google sign-in and shared files
In Gadget 0.162 and later, optional Google sign-in requests only your Google identity and email address (openid and email). Kiki's file service verifies the identity token and checks whether that email is on the private Kiki community member list. This does not grant Gadget access to your personal Google Drive.
The member list is imported from the Kiki folder's direct sharing list and refreshed by the operator when membership changes. A dedicated service account with Viewer access reads the shared Kiki folder. Kiki's Cloudflare service lists its files and streams the files you request to Gadget. It does not provide file editing, uploading or deletion.
Google user data is not sold, used for advertising or used to train artificial-intelligence models. Kiki's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Where information is processed and stored
Authentication happens in your browser with Google. Gadget never receives or stores your Google password. Gadget saves your account email and identity and refresh tokens on your PC, encrypted for your current Windows user with Windows Data Protection API. The refresh token is sent only to Google to renew your sign-in. The identity token is sent to Kiki's Cloudflare service to authenticate file requests.
Cloudflare processes your identity token, email address, requests, file metadata and streamed download content while delivering shared files. The private member list and the service-account credential are stored as Cloudflare service secrets. The gateway does not save downloaded file bodies or your identity tokens as application records. Google stores the source files; downloaded copies remain in the locations selected or managed by Gadget on your PC. This informational website does not receive your sign-in tokens.
Versions before 0.162 used direct, read-only access to your Drive and stored Google access and refresh tokens locally. Updating requires a fresh identity-only sign-in. You may separately revoke the older Drive authorization in your Google account connections.
Forum accounts
If you sign in to VPUniverse or VPForums, Gadget submits the name and password you enter directly to the selected site's HTTPS login endpoint. It stores a session cookie jar encrypted for your Windows user and a saved account name on your PC. It does not save your forum password. Downloads and account access are also subject to the selected site's policies.
Diagnostics and sharing
Gadget writes diagnostic logs locally. These may include operation names, HTTP response codes, file information and error details. Authentication logging is designed to exclude passwords, authorization codes and token or cookie values. Logs are not automatically sent to the developer. If you choose to share logs for support, review them first because other diagnostic information may include local paths or account-related details.
The Cloudflare gateway records error references, operation stages and HTTP status codes without including credentials, account emails or file names in those diagnostic messages. Cloudflare may also process and retain standard service request metadata, including IP addresses and request paths, under its operational and logging policies. These server records are available to the service operator for support and security.
Retention and your choices
Use the cogwheel's Download accounts option to remove a saved sign-in from this PC. This removes Gadget's saved session; it does not delete downloaded files or logs. You can separately revoke Google's authorization in your Google account connections. Contact the operator to remove your community membership; the gateway member list is refreshed separately from Drive sharing. Existing in-progress downloads may finish. Local files and logs remain until you delete them using Gadget's data-management options or Windows. You can use public downloads and manually downloaded files without linking an account.
This website
The hosting and delivery services for this website may process standard web-request information, such as an IP address and browser details, to deliver and operate these pages. These pages do not request Google credentials or access your Drive.
Questions and updates
Contact [email protected] for privacy questions. Changes to this policy will be published here with an updated effective date.