That's a fine security page (except that it needs to be clear that you're holding on to gmail passwords). But, please remember: if you don't have a security response page, which tells people how to contact you if they find a horrible security problem in your application, they are within our cultural norms to write a very unpleasant blog post about you.