Who operates this service
ViP3R KERNELs, maintained by IamCOD3X, operates viperkernels.com: an Android kernel catalog, purchase and delivery service, device-request portal and journal. This policy applies to that website and its Google Sign-In integration. For privacy questions or rights requests, email contact@viperkernels.com.
Google information we access
Signing in is optional for browsing and submitting a device request, and required for purchases and account features. Google Sign-In requests only the openid, email and profile scopes. Google returns your account identifier, email address, verification status and basic profile information, which can include your name and profile-picture URL. We store your Google account identifier, name, email address and email-verification record to establish your ViP3R account. Google profile pictures are not stored or displayed; you can choose a local avatar preset instead. We do not request access to Gmail messages, Google Drive files, contacts, calendars or other Google account content.
How we use Google information
Your Google account identifier links sign-ins to the correct account; your verified email identifies that account and receives payment or build-ready notifications; your name identifies your profile and customer records. These details let you access your own purchases, receipts, delivery links and linked requests, and let authorized maintainers provide support and reconcile orders. Google OAuth access tokens are used transiently by the server to fetch your sign-in profile and are not saved in the database. We do not request or store Google refresh tokens. We never receive your Google password.
Other information you provide
Orders include your selected device, Android version, OS/build, billing country, payment method, amount, currency, order reference and payment status. PayU India checkout also asks for a phone number, which is passed to PayU and is not stored in our order database. Device requests include model, codename, chipset, source URL, software versions, requested features, engineering notes, name, email, country and an optional Telegram username. We record policy acceptance, electronic signature, policy version/hash and time. Support messages contain the information you choose to send. Do not include passwords, access tokens or unnecessary sensitive information in request notes or support messages.
Cookies, local preferences and security records
Essential cookies maintain your signed-in session, protect forms against cross-site request forgery and temporarily secure the Google sign-in flow. Session cookies expire at the configured session lifetime, between 1 and 90 days; sign-in-state cookies expire after 10 minutes and form-security cookies after one day. Local browser storage remembers your theme and temporarily keeps build selections while you sign in. Application session and security records include a hashed network identifier, browser user-agent information and timestamps; the hosting web server may also retain IP addresses and request metadata in operational logs. The website does not use advertising or behavioral-analytics trackers and does not track downloads from the admin's external delivery service. Google Fonts requests expose ordinary browser/network information to Google when loading the website's fonts.
Storage and protection
Account, order, request, policy-acceptance, session and audit records are stored in the website's PostgreSQL database on its hosting infrastructure. Production traffic uses HTTPS. Session tokens and application network identifiers are hashed, and authenticated account checks, administrator restrictions and form-security controls limit access. Only authorized maintainers and service providers supporting the disclosed functions should access the relevant information. No security measure can guarantee protection against every incident.
Sharing and service providers
Google handles your sign-in under its own privacy policy. Resend processes notification emails containing your name, email address, order reference and relevant order/build information; notifications point to your authenticated profile rather than including the private download URL. Hosting services process the data needed to run the website. PayU receives the checkout details needed for its payment flow, including name, email, phone, amount and transaction reference. Other payment providers, including PayPal, Ko-fi, Buy Me a Coffee and Wise, process the information you enter on their pages under their own policies; ViP3R keeps the references and status needed to reconcile your payment. We do not store full card or bank credentials. Authorized maintainers can inspect relevant account, request and order information to prepare builds, resolve issues and verify payments. Information may also be disclosed when required by law or necessary to investigate fraud or protect the service.
Google data limits
We do not sell Google user data or use it for advertising, data brokerage, credit decisions or training general-purpose AI models. ViP3R KERNELs uses Google Sign-In data only for the account, order, delivery and support functions disclosed here, following the Google API Services User Data Policy and its applicable Limited Use requirements. We do not transfer Google account content to unrelated applications.
External services and international processing
If you choose Telegram assistance, the link can prefill your selected device, Android version, OS and country as a draft; you decide whether to send it. Telegram, payment pages, Google and external download services have their own privacy practices. Opening an external delivery link can expose your IP address and browser details to that service, even though ViP3R does not track the download. Providers may process information in countries other than yours. Review their privacy policies before using them.
Retention and account deletion
We keep your account information while your account remains active and retain request, order and support records as needed to fulfill requests, resolve issues and meet applicable record-keeping duties. You can delete your profile in Account settings: this revokes all sessions, removes your stored Google identifier, replaces your name and email with an account tombstone, removes delivery links and anonymizes linked request contact details and notes. Financial, payment, policy-acceptance and relevant audit records remain where needed for record-keeping or disputes; deleting a profile does not erase those records. Expired sessions no longer authenticate and are cleaned up when you next sign in. Operational logs, backups and provider records can have separate retention cycles; deletion from the application does not instantly remove every backup or third-party record. Contact us about retention or deletion of a guest request, support message or retained record.
Your choices and privacy rights
You can browse or submit a device request without Google Sign-In, sign out, delete your ViP3R profile, and remove ViP3R's Google connection in your Google Account permissions. Revoking Google's connection prevents future authorized Google access but does not itself delete your ViP3R account, revoke an existing ViP3R session or erase order records; use Account settings or contact us for that. Email contact@viperkernels.com to request access, a copy, correction, deletion, restriction or objection where applicable. We may need to verify that you own the account before acting. Applicable rights depend on your country, and you may contact your local data-protection authority where that right is available.
Device requests sent to Telegram
When you submit a device request, its reference, device/source/software details, requested capabilities, engineering notes, name, email, country and optional Telegram username are forwarded to the maintainer's Telegram inbox through our Cloudflare Worker. The website stores the request and queues its notification; temporary delivery failures can be retried. This does not send Google access tokens, account identifiers, payment details or security records to Telegram. Cloudflare and Telegram process the notification under their own privacy practices. Deleting a website account cannot recall a message already delivered to Telegram; contact contact@viperkernels.com about those copies. The contact step discloses this transfer before you submit.
Policy updates and contact
This policy is effective 5 October 2026. We publish updates on this page with an updated date. If we propose using Google data for a new purpose, we will update the disclosure and obtain the required authorization before that use. Privacy and support contact: contact@viperkernels.com. Use your order or request reference where relevant, and avoid sending passwords or payment-card details.
Google information: Google API Services User Data Policy · Google Privacy Policy · Manage Google connections