LEADIY

Leadiy/Google Sign-In Permissions

Google login.
Identity only.

Leadiy uses Google to confirm who you are. It does not request Gmail, Drive, Contacts, Calendar, or general Google API access.

  • Updated30 August 2026
  • OperatorSole proprietor Oleh Halahan
  • LocationKryvyi Rih, Ukraine

The short answer

Leadiy receives an ID token for authentication, verifies it on the server, and stores basic identity fields. It does not receive a Google API access token.
Used for
Account creation and sign-in
Google products
No access to Gmail, Drive, Contacts, Calendar, Photos, or files
Password
Never shared with Leadiy

Fields received and stored

FieldWhy it is used
Google subject ID (sub)Stable identifier for the Google account
Verified emailAccount address, communication, and admin-role recognition for the designated owner email
Display nameProfile identity inside Leadiy
Profile-picture URLOptional avatar in the workspace

The ID token is verified against Leadiy’s Google Web Client ID using Google’s server-side authentication library. The raw token is not stored in the Leadiy database.

Sign-In button and One Tap

The dedicated sign-in screen can load Google Identity Services when you request authentication. On public pages, proactive Google One Tap loads only after you choose “Accept all” in the cookie controls.

Google may set functional or security values such as g_state or g_csrf_token. Details and controls are listed in the Cookie Policy.

What happens after sign-in

After Google identity is verified, Leadiy creates its own random session token, stores only a SHA-256 hash of that token, and sends the browser an HttpOnly, SameSite=Lax cookie that is Secure in production. A normal session can last up to 30 days and ends earlier when you sign out.

The first successful sign-in starts the two-hour trial for a new user. The designated operator email is recognised as admin through the same Google sign-in flow; users are not asked to choose a role.

Revoking Google access

You can review or remove Leadiy in your Google Account’s connected-app settings. Removing access means a future Google sign-in may require consent again.

Revocation does not automatically delete data already stored by Leadiy, and it may not immediately end an existing Leadiy session. Sign out in Leadiy to end the current session, then request account deletion if you also want stored data removed.