Privacy Policy
media-backup · Effective September 27, 2026
media-backup is a personal, self-hosted backup tool operated by a single individual for their own use. This policy explains what data the application accesses through Google APIs and how it is handled.
Data accessed
media-backup requests one Google OAuth scope: https://www.googleapis.com/auth/drive.file.
This permits the application to create, read, update and delete only files that it has created
itself in the authorizing user's Google Drive. It cannot see or access any other files.
The application does not request access to email, contacts, profile details beyond what Google's
sign-in requires, or any other Google data.
How data is used
The application uploads encrypted backup files to Google Drive and later reads them back to verify integrity or restore data. Files are encrypted on the owner's server before upload; Google receives only encrypted content and encrypted file names.
Storage and security
The OAuth access token is stored only on the owner's own server, in a configuration file readable only by the owner's account. Encryption keys never leave the owner's control and are never sent to Google or anyone else.
Sharing
No data obtained through Google APIs is sold, shared with, or transferred to any third party. It is not used for advertising, analytics, profiling, or to train any machine learning or AI models.
Limited Use
media-backup's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and deletion
Backup files remain in the owner's Google Drive until the owner deletes them or they age out under the tool's retention settings. Access can be revoked at any time at myaccount.google.com/permissions, after which the application can no longer access Google Drive.
Changes
If this policy changes, the updated version will be posted on this page with a new effective date.