Privacy Policy
This Privacy Policy explains how Sync Bridge for Google Drive ("App") handles, protects, and stores your personal information and device data.
1. Information Handled and Collection Methods
Sync Bridge for Google Drive accesses or stores the following data solely to enable Google Drive file synchronization:
- Google Drive Auth Tokens: OAuth 2.0 Access/Refresh Tokens for Google Drive (Encrypted locally on device).
- File & Storage Metadata: Local folder trees and Google Drive target folder paths configured by the user for sync tasks.
- Anonymous Analytics & Crash Reports: Diagnostic runtime logs and error statistics to improve stability via Firebase Analytics & Crashlytics.
2. Data Protection Mechanisms for Sensitive Information
Sync Bridge for Google Drive implements robust technical and administrative security measures to protect sensitive user data and Google API data:
- Encryption in Transit: All data transmitted between the App and Google Drive APIs is encrypted in transit using industry-standard Transport Layer Security (TLS 1.2 or higher) and secure HTTPS protocols. Plaintext network communication is strictly prohibited.
- Encryption at Rest: Sensitive authentication credentials, including OAuth 2.0 Access Tokens and Refresh Tokens, are encrypted using Android Keystore-backed hardware encryption (EncryptedSharedPreferences utilizing AES-256-GCM). Tokens and secret keys are never stored in plaintext.
- Direct Architecture (No Intermediary Servers): The App does not operate external intermediary servers, databases, or proxy relays. All file contents and metadata are transmitted directly between your Android device and official Google Drive API endpoints.
- Principle of Least Privilege: The App accesses only the local and cloud directories explicitly selected and authorized by the user for synchronization. The App does not inspect, scan, or access unselected files.
3. Google API Services User Data Policy Compliance (Limited Use)
Sync Bridge for Google Drive strictly adheres to Google's policies regarding user data obtained via Google APIs:
- Limited Use Disclosure: Sync Bridge for Google Drive's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- No Sale of Data: User data received through Google Drive APIs is never sold, rented, or monetized to third parties.
- No Advertising or AI Training: Google user data and file contents are never utilized for personalized advertising, marketing profiling, or training generalized artificial intelligence (AI) or machine learning (ML) models.
4. Third-Party Data Transmission & Storage
Sync Bridge for Google Drive does NOT operate external servers to store or inspect your files or credentials. All file transfers occur directly between your Android device and official Google Drive APIs.
5. Android App Permissions Usage
- Storage Access (Scoped Storage): Read, upload, download, and write files in user-selected directories.
- Network Access (INTERNET / ACCESS_NETWORK_STATE): Transfer files directly to Google Drive API and verify Wi-Fi/cellular connection status.
- Notifications & System Startup (POST_NOTIFICATIONS / RECEIVE_BOOT_COMPLETED): Show sync status alerts and reschedule background tasks upon reboot.
- Foreground Service (FOREGROUND_SERVICE / FOREGROUND_SERVICE_DATA_SYNC): Prevent data sync tasks from being interrupted in the background and provide real-time progress notifications.
6. Data Retention, Revocation, and Destruction
Users maintain full control over their data and account connections:
- Immediate Local Erasure: When you unlink a Google Drive account or uninstall the application, all locally stored authentication tokens, task configurations, and local logs are immediately and permanently erased from the device.
- Revoking Access via Google: You can revoke the App's access to your Google Drive at any time through Google Account Third-Party Connections (https://myaccount.google.com/connections). Once revoked, all subsequent API requests are immediately invalidated.
7. Contact & Effective Date
For inquiries regarding this Privacy Policy or data protection practices, please contact developer support at contact@sov.kr.
Effective Date: September 9, 2026