This Privacy Policy explains how HIX Dragon ("we", "us") collects, uses, and protects information when you use Dragon Dash (the "Service"), including when you connect a Google account.
1. Who this Service is for
Dragon Dash is a private internal workspace for authorized members of the HIX Dragon team. Access is limited to allowlisted users. It is not a consumer social product and is not directed to children.
2. Information we collect
Depending on how you use the Service, we may process:
- Account credentials: email and authentication data used to sign in to the Service.
- Connected service credentials: API keys or tokens you choose to store so the Service can access approved third-party systems on your behalf. These are stored encrypted at rest.
- Operational data: information retrieved from services you connect, shown only to authorized team members inside the Service.
- Google user data: when you connect Google, we receive OAuth tokens and read-only data permitted by the granted scope (see below).
- Usage & diagnostics: basic server logs needed to operate and secure the Service.
3. Google user data
When a team member connects Google, we may request this OAuth scope:
https://www.googleapis.com/auth/admob.readonly
With that permission we may:
- Access the linked Google AdMob account information needed to identify the publisher account
- Fetch read-only AdMob reporting data so authorized team members can view it inside Dragon Dash
We store an encrypted OAuth refresh token so the Service can refresh access without asking to reconnect every time. We do not use Google user data for advertising, selling data, credit decisions, or unrelated AI training. We do not allow humans to read Google user data except:
- with your explicit request / consent for support
- as required for security investigations or legal compliance
- when data is aggregated and anonymized so it no longer identifies users or accounts
4. How we use information
- Authenticate allowlisted team members and secure the Service
- Provide the internal workspace features you are authorized to use
- Maintain connections you authorize (encrypted credential storage)
- Detect abuse, debug failures, and improve reliability
- Comply with applicable law and enforce our Terms of Service
5. Sharing of information
We do not sell personal information. We may share data only with:
- Infrastructure providers that host the Service (acting as processors under our instructions)
- Google when you authorize a Google connection (subject to Google's terms and your Google account settings)
- Other third parties you explicitly connect through the Service
- Authorities when required by law, or professional advisors under confidentiality
Google user data obtained via OAuth is not transferred to unrelated third parties except as needed to run the Service or as required by law.
6. Data storage, security, and retention
Credentials and OAuth refresh tokens are encrypted at rest. Access is restricted by authentication and an email allowlist. We retain data for as long as your organization uses the Service, or until an administrator deletes the relevant records. You may revoke Google access at any time from Google Account permissions and/or by removing the connection in Dragon Dash.
7. Your choices and rights
- Revoke Google access in your Google Account permissions
- Ask an administrator to remove your allowlisted email or delete stored connections
- Contact us to request access, correction, or deletion of personal data we hold about you, subject to legal and security exceptions
8. International transfers
The Service may be hosted in data centers outside your country. Where required, we rely on appropriate safeguards and our providers' contractual commitments.
9. Changes
We may update this Privacy Policy from time to time. The "Last updated" date at the top will change when we do. Continued use of the Service after an update means you acknowledge the revised policy.
10. Contact
Questions about privacy or Google user data: privacy@hixdragon.com
Operator: HIX Dragon · Product: Dragon Dash