Privacy Policy

Effective October 7, 2026 · Applies to savraj.co and everything under it, including Every Spot (savraj.co/nyc) and the Draft Room (savraj.co/draft).

savraj.co is a personal website run by Savraj Singh Dhanjal ("I", "me"). This page explains exactly what information the site collects, why, who it's shared with, how long it's kept, and how you can delete it. The short version: the site collects as little as it can, never sells anything, and doesn't use advertising. The blog and general pages use one analytics tool (FullStory, section 4); the Every Spot and Draft Room tools don't.

1. Google sign-in (Every Spot)

Every Spot lets you sign in with your Google account so you can save places as Want to try, Tried or Skip and add notes. Signing in is optional; the map works fully without it.

What Google shares with the site when you sign in (the standard "openid email profile" sign-in, nothing more):

  • your Google account ID (a number that identifies your account),
  • your email address,
  • your name, and
  • your profile picture URL.

The site does not get access to your Gmail, Drive, Calendar, contacts, location history or any other Google data, and never sees your Google password.

How it's used: only to sign you in, to show your name and picture in the page header while you're signed in, and to keep your saved places and notes attached to your account so they follow you between devices.

What's stored: one private file per signed-in person containing your Google account ID, email, name, and the places you've marked (each mark's status, your note, and when you saved it). It's stored in Google Cloud Storage (United States), accessible only to the website's server. Your profile picture is shown from Google's servers and is not stored. Sign-in uses a short-lived token held in your browser's session storage; the site keeps no login sessions or passwords.

Google API Services User Data Policy: savraj.co's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Information from Google is used only to provide the sign-in and saved-places features described above. It is not sold, not used for advertising, not shared with anyone except as described in section 5, and not used to train any AI or machine-learning model.

2. Location and addresses (Every Spot)

  • Addresses and street corners you type are sent to the site's server to look them up. The server passes the text to Nominatim (OpenStreetMap's address search) to find the location.
  • "Use my location, live" asks your browser for your location only after you turn it on. Your coordinates are sent to the site's server to calculate walking times and aren't saved to your account or any database.
  • Map pins and settings (your start and destination, slider positions, meet-up people) are remembered in your own browser's local storage so the page looks the same next visit. They stay on your device. A live GPS position is never saved there.
  • "Share this meetup" puts the meet-up's locations and labels into the link, so anyone you send the link to can see them.

3. Draft Room

The Draft Room stores the display names people type to join a draft and the results of the auction (who won which player, for how much) so a draft's history can be viewed later at its room link. No accounts, emails or contact details are collected.

4. Server logs, blog comments, and other services

  • Server logs. Like most websites, the hosting provider (Google App Engine) records standard request logs: IP address, browser type, the page or address requested and when. Requests to Every Spot include the map coordinates being looked up. These logs are used only to keep the site running and debug problems, and are deleted automatically after about 30 days.
  • Blog comments are provided by Disqus, which loads only on blog posts. If you comment or interact with Disqus, their privacy policy applies.
  • Page resources. Pages load fonts from Google Fonts, map images from OpenStreetMap's tile servers, and code libraries from public CDNs (unpkg, jsDelivr). Those services receive your IP address and browser details as part of serving the files.
  • Analytics on general pages. The home page, blog, about page and other general pages (including this one) use FullStory, a session analytics service that records how visitors interact with those pages — pages viewed, clicks, scrolling and mouse movement, device and browser type, approximate location from IP address — so I can see how the site is used and fix problems. FullStory does not run on Every Spot (savraj.co/nyc) or the Draft Room (savraj.co/draft), and it never receives your Google account information. FullStory's privacy policy applies to its processing; content blockers or your browser's "do not track" tools can prevent it from loading.
  • No ads. The site doesn't use advertising networks or ad tracking pixels.

5. Sharing

I don't sell, rent or trade personal information, and I don't share it with anyone except: the service providers that run the site on my behalf (Google Cloud for hosting and storage); the services named in sections 2 and 4 that your browser or the site contacts to provide a feature (including FullStory on general pages); or if required by law. Information received from Google sign-in is never shared with any of these services.

6. How long data is kept, and deleting it

  • Your saved places and notes are kept until you delete them. To erase everything stored about you, sign in to Every Spot and use Delete my data next to your name — it removes your file immediately. You can also clear individual marks at any time, or email me and I'll delete it for you.
  • To also remove savraj.co's access to your Google account, visit your Google Account → Third-party connections.
  • Server logs are deleted automatically after about 30 days.
  • Draft results are kept so past drafts can be viewed; email me to have a draft's records removed.
  • Browser-stored settings can be cleared from your browser's site data settings at any time.

7. Security

All traffic uses HTTPS. Stored data sits in private Google Cloud storage that only the site's server can access, and sign-in tokens are verified with Google on every request. No method of storage is perfect, but the site keeps as little as possible so there's little to protect.

8. Children

The site isn't directed at children under 13, and I don't knowingly collect their information. If you believe a child has signed in, email me and I'll delete the data.

9. Changes

If this policy changes, I'll update this page and its effective date. Material changes to how Google account data is used will be described here before they take effect.

10. Contact

Questions or requests: savraj@gmail.com.

Terms of Service