Boundary notes / plain language
Privacy through separation.
01 / What apps receive
Each Xeer app receives a stable identifier scoped only to that app, plus roles and permissions assigned for that app. Apps do not receive your Google subject or global Xeer identity.
02 / What Xeer stores
Xeer stores provider identity data in the protected auth service, session and revocation state, app-scoped identities, consent, and security audit events. Generated app code cannot access the auth database.
03 / Your controls
You can inspect authorized apps, revoke sessions, export your portal data, and delete your portal identity from the account screen.