How this application handles your information.
Last updated: 31 August 2026 · Applies to: 9ThirtyOne
9ThirtyOne stores everything in a Google Drive folder belonging to the organisation that installed it. It has no server of ours, no database of ours, and no account with us. The people who publish this software receive none of your data and have no technical means of obtaining it. Nothing is sold, shared, or used for advertising, and there are no analytics or tracking of any kind.
Two different parties are involved, and they have very different roles.
| Party | Role |
|---|---|
| Your organisation (for example, an AFROTC detachment) |
Installs 9ThirtyOne into a Google account it owns, decides who is on the roster, decides what feedback is collected, and controls the Drive folder holding every record. Your organisation is the data controller. Questions about your own feedback, corrections, or deletion go to them first. |
| Us (David Gaspar, publisher of the software) |
Writes the software and serves its files from a public web address. Your organisation creates and operates its own Google OAuth client, so even signing you in runs on its credentials rather than ours. We do not host your data, do not receive it, and cannot access it. |
This policy describes what the software does. Your organisation may have its own policies about how it uses the feedback it collects; those are separate from this document and we are not party to them.
When you sign in with Google, the app receives your email address, name, and profile picture from Google. Your email address is matched against your organisation's roster to decide whether you may use the app and what you may see. Your name is shown in the interface so people know who is signed in on a shared device.
We never receive a password. 9ThirtyOne has no passwords of its own and stores none.
The app reads and writes files inside one folder in your organisation's Google Drive — a folder the app created during setup. This is where forms, the feedback requests issued from them, responses, the roster, and the activity log live. Every one of those files belongs to your organisation's Google account, not to us.
The app cannot see anything else in that Drive. Its permission covers files it created itself, so the rest of the account is not merely off-limits by policy — it was never granted, and the app has no way to request it.
Ratings and written answers you submit are stored in that folder. On a form marked anonymous, the app stores no link between you and your answers — the record of who has submitted is kept as a separate file from the answers themselves, so completion can be tracked without attributing content to a person.
Removing names cannot change what someone wrote. If a written answer describes circumstances that identify its author — a role only one person holds, an incident only one person witnessed — that answer identifies them regardless of what fields were stored. Please keep that in mind when writing, and if you are handling this data, treat it as feedback rather than as anonymous statistics.
Every written answer is checked automatically against word lists covering hazing, harassment, discrimination, threats of violence, self-harm, substance misuse and academic integrity. A match is shown to cadre so that someone can read it quickly. This happens inside your organisation's own installation — the check runs on your device against a word list shipped with the app. Nothing is sent anywhere to perform it, and no such match ever reaches us.
A flagged answer can be shown to cadre immediately, including on a form whose results are otherwise withheld. That is deliberate: a disclosure that needs a person to see it should not wait for two more people to answer. It does mean that if you write something the screen matches, it may be read sooner, and by cadre rather than in aggregate.
The screen matches words, never meaning. It cannot understand context, sarcasm or quotation, so it raises some matches that turn out to be nothing — and a clear result is never proof that nothing was reported.
The app keeps some data in your browser so it works offline and remembers your preferences:
None of this leaves your device except to reach your organisation's own Google Drive or its own submission server. 9ThirtyOne sets no cookies.
We request the minimum access needed for the app to function. Each permission and what it is used for:
| Permission | Used for |
|---|---|
openid, email, profile(Sign in with Google) |
Confirming who you are, matching your email to your organisation's roster, and showing your name in the app. Nothing else. |
https://www.googleapis.com/auth/drive.file |
Reading and writing the feedback records inside the folder this app created in your organisation's Drive. This permission covers only files the app made itself. It gives the app no access to anything else in your Google Drive, and no way to ask for any. |
Google account data is used only to provide the features described above, visible to you in the app. It is not used for any other purpose.
9ThirtyOne's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we confirm that:
The app sends data to exactly three places, all of them Google's or your organisation's: Google's sign-in service, Google Drive (your organisation's account), and — if your organisation deployed one — a submission server running inside your organisation's own Google account. There is no fourth destination. There are no analytics, no error reporting services, no advertising networks, and no third-party components of any kind. (Fetching the app's own files from where they are published is a separate matter — see section 10.)
If you contact us for support, we keep a record of who is using the software so we can help: the name and email address of the administrator who contacted us, and the name of the organisation running it. We do not ask for and do not want your Drive location, your roster, or any feedback content. We keep support records for as long as the organisation uses the software, and delete them on request.
The app includes an anonymised export so that a backup kept off-site does not carry names. That feature exists for your protection, not ours. Nobody working on this software will ever ask you to send us that file or any other export. If you are ever asked for detachment feedback by someone claiming to work on this app, the request is not legitimate — please refuse it and tell us.
We do not sell, rent, or share your information with anyone. We have none to share.
Within your organisation, who can see what is decided by your organisation's own roster and by Google Drive's sharing settings. Broadly: cadets see only what is assigned to them and never see anyone's responses; instructors see the detachment's feedback; restricted spaces are visible only to the roles your organisation grants. On an anonymous form, results are withheld entirely until three responses exist, so no single answer can be picked out by elimination. Below that line, only the count of who has taken part is shown.
Your organisation controls retention, because your organisation holds the data. Records stay in its Drive folder until someone there deletes them or deletes the folder.
When an administrator removes someone from the roster, the app permanently anonymises what that person left behind: their responses lose any attribution and become genuinely anonymous, and the records of who submitted are replaced with records that name nobody. This is irreversible.
The activity log keeps an entry recording that the removal happened, and that entry contains the removed person's email address. This is kept on purpose: a log that can be emptied by the person it implicates is not a log. If you need that entry removed as well, the owner of the Drive folder can delete it directly in Drive — your organisation controls this, not us.
You can revoke 9ThirtyOne's access to your Google account at any time at myaccount.google.com/permissions. Signing out inside the app also revokes the Drive token it was holding. Revoking access stops the app working for you; it does not delete feedback already submitted, which belongs to your organisation's records.
To remove the local copy, sign out and clear site data for this address in your browser settings, or uninstall the app if you added it to your home screen.
No system is perfectly secure. If you believe you have found a security problem, please tell us at the address below rather than disclosing it publicly, and we will respond.
9ThirtyOne is used by cadets enrolled at university and by detachment staff. It is not directed at children and we do not knowingly collect information from anyone under 13. If your organisation enrols anyone under 18, it is responsible for obtaining whatever consent applies in its jurisdiction before asking them to use the app.
In your organisation's Google account, on Google's infrastructure, subject to Google's own privacy policy. We operate no servers and store none of it.
The app's own files — the page, its code and its icons — are served to your browser from GitHub Pages. Loading any web page reveals your IP address and browser to whoever serves it, and that is true here too; those request logs belong to GitHub, are outside our control, and are subject to GitHub's privacy statement. No feedback, roster or Drive content travels that path. Once the page has loaded it talks directly to Google, so what you write never passes through the address that served it.
If this policy changes we will update the date at the top of this page. Because the app receives no data from you, we have no way to email you about it — please check here if it matters to you. Substantive changes will also be noted in the application's release notes.
David Gaspar
Email: david.mark.gaspar@gmail.com
If your question is about feedback you submitted — what was recorded, correcting it, or removing it — please contact your own organisation's administrator. They hold the data; we do not.