Fork Guy Backups — Privacy Policy

Last updated: 28 September 2026

Who operates this application

Fork Guy Backups is operated by Fork Guy. Contact: [email protected]. This is an internal tool, not a public product; it is used by Fork Guy's own systems and personnel only.

What Google data this application accesses

This application requests exactly one Google API scope:

https://www.googleapis.com/auth/drive.file — "See, create, and delete only the specific Google Drive files you use with this app."

Google's own definition of this scope covers two ways an app can gain access to a file: files the app creates itself, and files a user explicitly opens or selects with the app (for example through a file picker). This utility does not present a file picker or request access to unrelated files. It creates backup files in a dedicated folder and retrieves those files for recovery. In this application's actual, specific use, that means:

What data this application stores, and how

This application uploads encrypted backup archives to one dedicated Google Drive folder. Every archive is encrypted (using the open-source age encryption format) on the source system before it is ever uploaded — unencrypted (plaintext) backup content is never transmitted to Google and never stored in Google Drive. Plaintext backup files remain in protected local staging on Fork Guy's own server until encryption and verified upload both succeed; failed runs retain staging files for investigation and retry rather than deleting them. The backup process handles plaintext locally; the upload step sends only encrypted archives. The production decryption key is held separately by the account owner, outside Google Drive and the automated upload process. Decrypting an archive requires the corresponding key.

This application's OAuth access token is stored locally on the machine that runs the backup process, and is also transmitted to Google's own servers on each request, as required to authenticate that request — this is how OAuth authentication works for any Google API call. The token is not transmitted to, or shared with, any party other than Google, and is used solely to upload and retrieve files within the one dedicated Drive folder described above.

Data retention and deletion

Automatic retention deletion is not yet enabled. The proposed policy is 14 daily, 8 weekly, and 6 monthly recovery points (28 recovery points at any one time) — each recovery point may contain multiple archive files (for example, a Fork Guy backup cycle produces a separate database dump and a separate media archive), so this is not the same as 28 archive files. The proposed policy will be reviewed as usage is measured. No automated retention or routine manual deletion is claimed to be active; this section will be updated when retention is implemented. Fork Guy's account owner can also view, download, or delete any file in the dedicated folder directly through Google Drive at any time, independent of this application.

No sale or advertising use of data

No data handled by this application is sold, rented, or used for advertising, profiling, or any purpose other than storing and retrieving Fork Guy's own encrypted backups.

How to revoke this application's access

Google Account → Security → "Third-party apps with account access" → find this application → Remove access. This withdraws the app’s authorization to your Google account. Revoking authorization does not delete backup archives already stored in Drive.

Changes to this policy

If what this application does changes in a way that affects the data it accesses, this page will be updated and the "Last updated" date above will change accordingly.

Contact

[email protected]