AUTENIC · INTEGRATION LAB

Privacy notice

For Autenic Integration Lab, operated by Lukas Disterhoft.

Notice prepared September 19, 2026. This notice covers the private Google-connected tool and its public information website.

Information accessed and why

The tool requests the Google Tag Manager read-only permission, https://www.googleapis.com/auth/tagmanager.readonly, to read the published version of an operator-approved container. This can include account and container identifiers, tags, triggers, variables, templates, configuration values and version metadata.

That information is used to verify configuration identity, detect differences from the expected implementation and prepare controlled integration-test evidence. Container configuration can contain sensitive values even though the permission is read-only. Captures are treated as private operational records.

This Google connection does not request permission to modify or publish containers, or to access Gmail, Drive, CRM records or visitor-event databases.

Credentials and storage

The OAuth client credentials and refresh token are stored in the operator's 1Password Environment and injected into the capture process when it runs. Short-lived access tokens are obtained from Google immediately before a read and held in process memory. Credential values are not included in public evidence or this website.

The raw configuration response and associated evidence are stored in local operational files on the operator-controlled computer, outside tracked source files. Sanitized outputs and non-secret digests support authorized review. Excluding files from source control is not itself encryption or an automatic deletion policy.

Access, sharing and service providers

Google processes authorization and API requests. 1Password stores the configured credentials. Captured configuration is used for the integration work described here; it is not sold, used for advertising or used to train general-purpose AI models. Review records are intended to contain sanitized evidence rather than raw configuration or credentials. Access to private operational records is limited to authorized operators.

Use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements where applicable.

Retention and deletion

The tool does not automatically expire captured configuration or audit evidence. Records are retained for the authorized validation work, investigation and traceability, and deletion requires an operator action. There is no fixed automatic deletion period.

To request deletion or ask what is retained, contact the operator below. Requests are reviewed against the operational records and any applicable retention obligations; any limitation will be explained. Revoking Google access prevents future authorized reads but does not delete records already captured.

Revoking access

You can remove the application's access through your Google Account connections. The operator can also remove the corresponding stored credentials. Further reads require valid authorization.

This website

The public information pages contain no application analytics, advertising scripts, forms or Google sign-in. Google tokens and configuration captures are not uploaded to this website.

Cloudflare hosts the pages and processes connection information, such as IP addresses and request metadata, to deliver and secure the site. See Cloudflare's privacy policy. Email sent to the contact address is handled by the operator and the email service provider to respond to your request.

Contact and changes

Contact Lukas Disterhoft at lukas.collect@gmail.com for privacy, deletion or access questions. Do not send credentials or raw configuration by email.

This notice will be updated before materially different uses of Google data are introduced, with renewed consent where required.