Introduction
Endpoints Health Check is a comprehensive security assessment and optimization platform designed specifically for organizations leveraging the Google ecosystem. In an era of evolving digital threats, we provide administrators with a centralized, automated interface to monitor, analyze, and enhance the utilization of Chrome Enterprise, ChromeOS, and Google Workspace security policies.
The primary value of our tool lies in its ability to translate complex administrative configurations into a clear Health Check Score, pinpointing gaps in policy enforcement and providing actionable remediation insights—all through a secure, read-only connection that respects your organization's data integrity.
1. Scope of This Policy
This Privacy Policy applies to all data collected and processed by the Endpoints Health Check Tool when an administrator connects their Google Workspace domain. It governs our commitment to transparency regarding what data we access, how it is used, and the measures we take to protect it during the security assessment process.
2. Information We Collect
As a diagnostic tool, we collect metadata through authorized Google APIs. We categorize the information collected as follows:
Collected Metadata Categories:
- Organizational Metadata: OU hierarchies, domain names, and administrative role assignments.
- Device & Telemetry Data: Enrolled mobile and ChromeOS device metadata (enrollment status, OS version, last check-in) and basic health telemetry.
- Policy Configuration Data: Settings related to Safe Browsing, URL filtering, extension controls, and Cloud Identity policies.
- Audit & Usage Information: Security-related audit logs (Admin activity, OAuth usage) and license assignment statistics.
- Managed Profile Data: Managed Chrome browser profiles and lists of installed applications/extensions.
- Administrative Identity: Basic profile info (name, email) of the connecting administrator for session management.
3. How We Use Your Information
The information retrieved is used solely to generate security insights for your organization:
- To calculate comprehensive Health Scores for selected Organizational Units (OUs).
- To identify orphaned or underutilized licenses (CEP, Workspace, ChromeOS).
- To provide descriptive evidence and remediation paths for security policy gaps.
- To power the Ask Gemini AI feature for natural language security queries. Users have the option to enable or disable this feature at any time based on their preferences.
4. Data Sharing & Disclosure
We do not sell your data. Information is only shared in the following limited circumstances:
- Infrastructure: Secure hosting on Google Cloud Platform (GCP).
- AI Insights: Policy metadata processed via Gemini API for natural language explanations.
- Legal Compliance: Only if required by law or in response to valid public authority requests.
5. Data Retention
We retain your organization's health assessment reports to allow you to track security improvements over time. You may request the deletion of your account and all associated assessment data at any time, which will be purged according to our internal security protocols.
6. Security Measures
Your data security is our top priority:
- Strict Read-Only Access: The tool lacks the technical capability to modify or delete your Google configurations.
- Encryption: Data is secured using AES-256-GCM at rest and TLS in transit.
- Enterprise Infrastructure: Hosted on GCP, leveraging enterprise-grade security features.
7. Your Rights
- Right to Access: Review all data collected via the tool's downloadable reports.
- Right to Erasure: Request total deletion of organizational data from our system.
- Right to Revoke: Revoke access at any time through your Google Account security settings.
8. Third-Party Links & Integrations
We provide direct navigation links to the Google Admin Console. We are not responsible for the privacy practices of third-party platforms beyond our own data processing agreements with them.
9. Changes to This Privacy Policy
We reserve the right to update this policy as we transition from Beta to full release. Users will be notified of material changes through the application interface.