Privacy policy
Privacy policy for Tejas Vermani
This policy describes how the personal website Tejas Vermani (https://tejasvermani.com/portfolio) collects, uses, and stores information. The operator is Tejas Vermani, reachable at tejasvermani@gmail.com. Last updated September 3, 2026.
What this site is
Tejas Vermani is a public personal portfolio. It does not offer user accounts, sign-in, comments, or a consumer product. Visitors are not asked to connect Google, Fitbit, or Strava. Health and fitness data shown on the site belongs to me, the site owner.
Information from visitors
This site does not use advertising cookies, does not run a marketing pixel, and does not build profiles of visitors. The host (Vercel) may process standard request logs such as IP address, user agent, and requested URL for security, uptime, and abuse prevention. Those logs are not used to identify visitors for advertising.
Google user data (Fitbit via Google Health)
To display my own activity on the Pulse section, this site uses the Google Health API with OAuth. The only Google account authorized is mine. The application requests this scope:
googlehealth.activity_and_fitness.readonly— read-only access to activity and fitness data such as exercises, distance, duration, and step counts synced from Fitbit and other Google Health sources linked to my account.
From that API, the site may read and publicly display:
- Latest workout or exercise type and display name
- Distance and active or moving time
- Weekly step total
- Activity date
The site does not request sleep, heart-rate, location, nutrition, contacts, Gmail, Drive, or calendar scopes. It does not write, delete, or modify Google Health data.
How Google user data is used
Google user data is used only to provide the user-facing Pulse card on this portfolio: a snapshot of my latest activity. It is not used for advertising, credit decisions, or profiling other people. It is not sold. It is not transferred to third parties except as needed to host and render the public website (Vercel build and CDN).
Access tokens are obtained at site build time using a refresh token I store as an encrypted environment variable on Vercel. The refresh token is not published in the website source. The public HTML may contain the summarized activity fields listed above until the next deploy.
This use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements. Human access to the underlying tokens is limited to me, for security, debugging, and operating this site.
Strava data
The Pulse section may also show my latest Strava activity (name, sport, distance, moving time, elevation, and a link to the activity on Strava) using Strava OAuth credentials I control. That data is already available on Strava according to my Strava privacy settings.
Retention and deletion
OAuth refresh tokens remain until I revoke them in Google or Strava account settings, rotate the environment variables, or take the Pulse cards down. Public snapshots on this site are replaced when the site is rebuilt. To request deletion of the Google connection, email tejasvermani@gmail.comor revoke access under your Google Account's third-party app settings. Because the only connected account is mine, I can revoke access at any time.
Contact
Privacy questions: tejasvermani@gmail.com.