Bola de Cristal
Google OAuth Verification
This page documents the public identity, data usage, and verification URLs for the Bola de Cristal Google OAuth client.
Requested Google Scopes
openid— authenticates the user with Google OpenID Connect.email— reads the email address used to create or access the account.profile— reads the display name and profile photo shown in the account.
The application does not request Google birthday, contacts, calendar, Drive, Gmail, or other sensitive Google API scopes for the standard login flow.
Data Use
Google OAuth data is used only for account authentication, account linking, profile display, and session continuity. Users can review, update, export, or delete their account data from their profile and through the privacy contact.
Birth date, birth time, and birth city are optional astrological profile fields collected inside Bola de Cristal after explicit in-app consent. They are not requested from Google OAuth scopes.
Optional Zelfy account federation, when enabled by the user, exchanges only opaque tokens, authorized scopes, and minimized derived signals. It does not share Google IDs, emails, raw location, raw birth data, free text, or sensitive health/financial records.
Google Cloud Console URLs
- Application home page
- https://boladecristal.com.br/
- Privacy policy
- https://boladecristal.com.br/privacidade
- Terms of service
- https://boladecristal.com.br/termos
- OAuth callback
- https://boladecristal.com.br/auth/google/callback
- OAuth verification page
- https://boladecristal.com.br/oauth/google-verification
- Machine-readable verification
- https://boladecristal.com.br/.well-known/google-oauth
Support contact: [email protected]