Privacy policy — mwololo-backup
Last updated: 10 October 2026
mwololo-backup is a personal backup utility. It runs on the operator's own computer and copies the operator's own files to the operator's own Google Drive account. This policy describes the one Google account it touches and what it does with the data it can reach.
What Google user data the app accesses
- The Drive files of the authorizing account. The app requests the
single scope
https://www.googleapis.com/auth/drive, which is the scope Google requires to create, list, download and delete files in Drive. The app itself creates the backup folder and the files inside it, and only ever reads and deletes files inside that one folder. - Basic account identity, as needed to authenticate. The OAuth handshake returns an account identifier and email address so the tool can show which account it is backing up to. The app requests no profile scopes and does not read name, photo or contact data.
The app requests no other Google service. It cannot and does not read Gmail, Calendar, Contacts, Photos, locations or device data.
How the data is used
- To upload the operator's encrypted and unencrypted backup archives to the account's Drive folder.
- To list those files, verify that an upload matches the local file by size, and delete archives that fall outside the retention window.
- To restore a backup on request. Restores are initiated by the operator.
No other use is made of the data.
Where the data is stored
Backup files live in the operator's own Google Drive; the app stores no copy of them anywhere else. The app runs entirely on the operator's computer and sends Google user data to no server other than Google's own APIs. Encrypted snapshots are additionally stored on the operator's configured remote using client-side encryption, so their contents are unreadable without the operator's password.
Sharing
- Google user data is not shared with, sold to, or transferred to any third party.
- The data is not used for advertising, profiling or credit decisions.
- The data is not used to train or improve any machine learning model.
- No human reads the data. There is one user, the operator, who is also the owner of the data.
Google API Services User Data Policy and Limited Use
mwololo-backup's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and deletion
- The app keeps archives according to a retention window configured on the operator's machine (7 daily, 4 weekly, 6 monthly). Older files it created are deleted by the app.
- The operator can delete any backup file directly in Google Drive at any time.
- Access can be revoked at any time at myaccount.google.com/permissions, which immediately ends the app's ability to reach the account. Nothing is retained after that, because the app keeps no server-side copy.
Security
OAuth tokens are stored on the operator's machine in a file readable only by the operator's user account. The tool talks to Google over HTTPS only. Encrypted snapshots use a password that is never uploaded anywhere.
Changes
Changes to this policy are published on this page with a new date above.