BILOOU

Privacy Policy

What Biloou collects, why, who else ever sees it, and how to make it go away. Short, because there is not much of it.

Last updated 28 July 2026

The short version

We keep your name, your email address, an opaque id for your Google account, and the portfolio you wrote. That is the whole list.

We do not sell it, we do not share it for advertising, and there is no analytics script, tracker or advertising network anywhere on this site. We never see a password, because the service does not have any.

The photobooth is not on that list at all: it needs no account and uploads nothing. Your pictures are read, decorated and saved by your own browser and never reach this server.

The rest of this page is the same thing said carefully. If you would rather ask a person, the address is at the bottom.

Who we are

VCorps operates Biloou and is the data controller for the information described here. Contact: admin@biloou.com.

What we collect

From Google, when you sign in

Your email address
Identifies your account and is where we would write to you.
Your name
Used only to pre-fill the name field when you first sign up. You can change it to anything, and after that it is your text and not Google’s.
Your Google account id (sub)
An opaque string that means “this Google account” and nothing else. Your account is keyed on it rather than on your email address, so changing your address at Google does not lose your portfolio.

That you type in

Everything on your portfolio: your job title, location, availability, the introduction, skills, services, links, projects, work history, anything you were recognised for, your profile picture and any project pictures, and how you arranged them.

You choose all of it. None of it is required, and a field you leave empty stays empty.

That the software creates

  • An account creation date, an account status, and whether you are an administrator.
  • If you tick Keep me signed in on this device: a random token. Only its SHA-256 hash is stored, so the stored value cannot be used to sign in as you.
  • A count of how many CV imports you have run today, for the daily cap.
  • If you are an administrator: a log of the administrative actions you take, including the IP address they came from. This exists so that changes to other people’s accounts are accountable.
  • Ordinary web server logs kept by our host, and PHP error log entries when a sign-in fails, so that a broken sign-in can be diagnosed.

The photobooth

Nothing. The photobooth needs no account and takes no upload: the pictures you choose are read by your own browser, drawn onto a canvas there, and saved back to your own device. They are never sent to this server, so there is nothing here to store, to share, to keep or to delete. Closing the tab is what deletes them.

Visiting the page is an ordinary web request and appears in our host’s server logs like any other, but what it records is that the page was fetched not what you put on it.

What we never collect

  • A password. There is none to collect.
  • Payment details. The service is free and takes no payments.
  • Anything else in your Google account not your mail, files, calendar, contacts, photos or location. We do not have permission to read them and never ask for it.
  • Behavioural or advertising data. No analytics, no pixels, no fingerprinting, no third-party cookies.

Google user data, specifically

Signing in uses OAuth 2.0 with OpenID Connect and requests exactly three scopes:

Scope Gives us Used for
openid A signed token identifying the Google account. Knowing which account is signing in.
email Your email address and whether Google has verified it. Identifying your account, and contacting you.
profile Your display name. Pre-filling the name field on signup.

None of these is a sensitive or restricted scope. We request no others, and a Google account’s data outside them is not reachable by this application.

An unverified email address is refused. If Google has not confirmed you own the address, we will not let it identify an account here otherwise somebody could claim an existing account by putting its address on a fresh Google account.

Limited Use

Biloou’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice that means we use this data only to provide the sign-in and the portfolio you asked for; we do not transfer it to anyone except as described below; we do not use it for advertising; and no human reads it except where you ask us to, where it is needed for security, or where the law requires it.

You can withdraw our access at any time from your Google account’s permissions page. Doing so stops you signing in here; it does not delete what is already stored, which needs the deletion request described below.

Why we hold it

To run the service you asked for, and for nothing else. Where a legal basis has to be named: performing our contract with you for your account and portfolio; our legitimate interest in keeping the service secure and accountable for the administrative log; and your consent for the optional CV import, which you give each time by choosing to use it.

What you make public yourself

A portfolio is private until you publish it. An unpublished one returns the same “not found” as an address that never existed, so nobody can probe for drafts.

Publishing makes it public to anyone with the address. It can be found by search engines, cached and archived by parties we do not control. If your email address, telephone number or location is on the page, publishing publishes them. That is not a side effect it is what publishing means but it is worth saying plainly.

Unpublishing takes it off the service at once. It cannot reach into somebody else’s cache.

Who else sees it

We share your information with nobody, with three unavoidable exceptions.

Google sign-in
Google knows you signed in to this application, because Google performs the sign-in. We send them no information about you; they send us the three fields above. Their handling is covered by Google’s privacy policy.
OpenAI only if you use the CV import
The text of a CV you upload is sent to OpenAI so that it can be sorted into portfolio fields. That includes anything personal printed on it, such as a home address or telephone number. This happens only when you upload a file for that purpose, the dashboard says so on the page before you do, and the PDF itself is never written to disk it is read in memory and gone when the page finishes. If you would rather not, type the fields in instead; every one of them can be filled by hand.
Our hosting provider
The service runs on rented hosting, so the provider necessarily stores the database and the uploaded files, and keeps ordinary server logs. They act on our instructions and do not use the data for their own purposes.

We would also disclose information if the law required it a valid court order, for example. We have not been asked to date. We do not sell personal information, and we do not share it for advertising or for anybody else’s marketing.

These providers may process data outside your country. Where that involves personal data leaving a region with transfer rules, the providers’ own standard contractual protections apply.

Cookies

Two, both strictly necessary. No third-party cookies of any kind.

Cookie What it does Lasts
biloou_session Keeps you signed in while you work, and carries the token that protects forms from being submitted from another site. Up to two weeks, or until you sign out.
biloou_remember Set only if you tick Keep me signed in on this device. Holds a random value; the database stores only its hash. 30 days. Replaced on each visit, and deleted when you sign out.

Both are HttpOnly and SameSite=Lax, and marked Secure over HTTPS. Because neither is used for tracking or advertising, there is no consent banner to click past.

How long we keep it

  • Your account and portfolio: until you ask us to delete them.
  • Remember-me tokens: 30 days, and each one is replaced the moment it is used, so a stolen cookie stops working as soon as you visit again. Signing out deletes the current one.
  • The administrative log: kept as an audit trail, and deliberately not erased when an account is deleted otherwise deleting an account would erase the record that it was deleted. It holds the email address the action concerned, not the portfolio.
  • Server and error logs: as long as our host keeps them, typically a few weeks.
  • Backups: deleted data can persist in backups for up to 90 days before those are rotated out.

Your rights, and deleting your account

You can ask us to:

  • Show you what we hold. Most of it is already on your own dashboard; ask and we will send the rest.
  • Correct it. You can edit almost everything yourself. Your email address follows your Google account and updates itself when you change it there.
  • Delete it. Email admin@biloou.com from the address on the account and we will remove the account, its portfolio, its uploaded pictures and its sign-in tokens within 30 days. This cannot be undone and there is no export afterwards, so take a copy of anything you want first.
  • Object, restrict, or take it elsewhere, where the law where you live gives you those rights.

We do not charge for any of this and we will not ask you to justify it. If you think we have handled your data badly, tell us first and you are entitled to complain to your local data protection authority regardless.

How it is protected

  • Served over HTTPS. Cookies are marked Secure, HttpOnly and SameSite=Lax.
  • No password exists to be stolen. Sign-in uses the OAuth authorisation code flow with PKCE, plus one-use anti-forgery values, and the identity token’s claims are checked in full before any account is touched.
  • Every database query is a prepared statement, and every value that reaches a page is escaped, so neither your content nor anybody else’s can become code.
  • Uploaded pictures are re-encoded on the way in and stored outside the web root, so a stored file can never be requested as a URL in its own right.
  • Session ids are regenerated whenever you sign in.

No service can promise perfect security, and we are not going to. If we ever discover a breach affecting your data, we will tell you and the relevant authority as the law requires.

Children

The service is not directed at children under 13, and we do not knowingly collect their information. If you believe a child has created an account, write to us and we will remove it.

Changes to this policy

We will update this page when the software changes. The date at the top says when it last did. If a change materially affects how we handle your information, we will write to the address on your account before it takes effect.

Contact

VCorps admin@biloou.com. Questions about this policy, requests to see or delete your data, and complaints all go to the same place, and a person reads them.

Back to top