Thank you for reviewing WipeAway. This page has been prepared specifically for the Google OAuth verification team. It contains everything needed to evaluate this application's use of Google APIs — scope justifications, data handling, security measures, and a full demonstration video.

OAuth Verification

WipeAway for Google Calendar

A web application that allows Google Calendar users to safely remove unwanted calendar events in bulk — without deleting or rebuilding the calendar itself.

What is WipeAway?

WipeAway is a web application that allows users to remove unwanted events from Google Calendar safely and quickly. Users sign in with their Google account via OAuth, select which of their calendars to clean, set a cut-off date, count the events that will be removed, and then — only if they choose to proceed — start the deletion process.

No action is taken automatically. WipeAway never deletes, modifies or reads calendar events without the user's explicit instruction. The deletion process begins only when the user reviews a count and clicks to confirm.

Why Google Calendar Access is Required

WipeAway's sole purpose is to manage Google Calendar events on behalf of the user. Google Calendar access is not an optional feature — it is the entire function of the application.

Without Google Calendar permissions, this application cannot perform its core function. There is no alternative mechanism for listing a user's calendars, counting their events, or deleting the events they select.

The application requires Google Calendar access in order to:

Requested Google Scopes

WipeAway requests exactly two Google API scopes. Both are listed below with their precise justification.

Google Calendar
https://www.googleapis.com/auth/calendar

Required because WipeAway must list calendars, count events, and delete the events the user selects. This scope is the minimum required to perform all three operations.

  • List the user's calendars so they can select which ones to clean
  • Count events in a selected calendar before deletion begins
  • Delete only the events the user has explicitly chosen, within the date range they set
User Email Address
https://www.googleapis.com/auth/userinfo.email

Required solely to lock a purchased licence key to the correct Google account, preventing a single key from being shared across multiple users. The email address is never used for marketing, never stored in a database, and never shared with any third party.

  • Read the user's Google account email address immediately after sign-in
  • Associate the email with a licence key to prevent key sharing
  • The email address is discarded at end of session — not retained long-term

Data Usage

WipeAway is designed with a minimal-data approach. The application accesses only what is necessary to perform the specific deletion the user has requested.

What we access

Calendar names and IDs — to populate the calendar selection list

Event IDs and dates — to count and delete events within the user's chosen date range

Google account email — to lock the licence key to the correct account

What we never do

Sell, share or transfer user data to any third party

Use calendar data for advertising, analytics or marketing

Access Gmail, Drive, Contacts or any other Google service

Read or store the content of calendar events

Access calendars the user has not explicitly selected

Data Storage

WipeAway does not permanently store Google Calendar contents.

During a deletion job

While a deletion is running, minimal job-state data (progress counters, continuation tokens) is held temporarily in Upstash Redis. This data contains no calendar event content — only metadata needed to track deletion progress across server invocations.

Once the deletion has completed, all job-state data is discarded. Calendar event data is never written to any of WipeAway's servers, databases or logs.

What is retained long-term

Only the following is retained after a session ends:

Licence key and associated purchase email — stored in a private Google Sheet, used solely for licence validation

Operational server logs — standard Vercel function logs, retained per Vercel's default retention policy

OAuth tokens are stored in a short-lived, Secure, HttpOnly session cookie (24-hour expiry) and are never written to any server-side store.

Calendar event data is used only while performing the deletion requested by the user. Once the deletion has completed, all calendar event data is discarded. It is never stored, logged, analysed or shared.

Security

OAuth 2.0
Authentication is handled exclusively via Google's OAuth 2.0 flow. WipeAway never asks for or stores the user's Google password.
HTTPS everywhere
All traffic is served over HTTPS. The application is hosted on Vercel, which enforces TLS across all endpoints. No unencrypted communication.
CSRF protection
The OAuth flow uses a cryptographically random state parameter, stored in a short-lived HttpOnly cookie and validated on callback, preventing cross-site request forgery attacks on the OAuth handshake.
Short-lived sessions
OAuth tokens are stored in a Secure, HttpOnly cookie with a 24-hour expiry. No passwords are collected or stored at any point.
No WebViews
Authentication uses a standard browser redirect, not an embedded WebView — confirmed in Google Cloud Console's Project Checkup.
Minimal scope
Only the two scopes listed above are requested. No access to Gmail, Drive, Contacts, Admin SDK or any other Google service.

Demonstration Video

The video below shows the complete user journey: signing in with Google, reviewing the OAuth consent screen, selecting a calendar, counting events, confirming the deletion, running the deletion to completion, and verifying the result with a recount.

Privacy Policy & Terms of Service

WipeAway's full Privacy Policy and Terms of Service are publicly available and linked from every page of the application.

Reviewer Test Access

To assist with Google's verification process, we have created three dedicated reviewer licences. These have been created specifically for Google's review team and have not been activated.

How to use:
  1. Visit https://wipeaway.app
  2. Click "Already a customer?" and enter one of the licence keys below
  3. Sign in with your own Google account
  4. The licence will automatically become linked to that Google account during activation
  5. You may then use the application normally for verification purposes
Google Review Licence A
WIPE-7RLN-MNM2-WBY3
NOT YET ACTIVATED
Google Review Licence B
WIPE-3DEK-9L5Q-SRKK
NOT YET ACTIVATED
Google Review Licence C
WIPE-8TDC-SSWM-S63E
NOT YET ACTIVATED

If the first licence has already been activated by a previous reviewer, please use Licence B or C. If you have any difficulty activating a key, please contact us at hello@wipeaway.app and we will issue a replacement immediately.

Contact

For any questions about this application or the verification process, please contact us directly. We aim to respond within one business day.

Max Alexander Ejogo
Operator — WipeAway for Google Calendar · Sole Trader, United Kingdom
hello@wipeaway.app
Hayloft Point
4–6 Middlesex Street
London E1 7JH
United Kingdom