Privacy Policy

Effective September 22, 2026. This policy covers the private, owner-operated Josie House Encrypted Backup utility.

Google Drive access

The utility requests Google's drive.file permission. That permission can cover files the app creates and files the owner explicitly opens or shares with the app. It does not provide blanket access to Drive. This utility's current workflow creates, reads, and updates only its own backup repository; it does not use a Drive file picker. The utility may delete its repository objects when the owner directs a retention or removal operation. It does not request Gmail, contacts, or broad Drive-read access.

Backup data and encryption

Local snapshots may contain private records. Restic encrypts backup contents and original filenames on the owner's computer before rclone uploads repository objects. The recovery passphrase is not uploaded to Drive. Google can see encrypted repository-object metadata, including object names and paths, sizes, and upload or access activity, but not the original backup contents or filenames inside the encrypted repository.

Credentials and storage

Encrypted repository objects are stored in the owner's Google Drive. OAuth access and refresh tokens are stored in an access-restricted local configuration file. A workstation-protected passphrase copy supports unattended local use; separate password-manager and offline copies are needed for recovery after loss of the workstation. This public site does not hold those credentials or backups. The site host may process ordinary request data needed to serve these pages.

Sharing, retention, and deletion

The utility is not offered to other users, does not sell Google user data, does not use it for advertising, and does not send backup contents to an AI inference provider. Backups remain until the owner removes them or applies a retention rule. Revoking Google access prevents future use of the grant but does not delete repository objects already in Drive; those must be removed separately. Deletion of a backup can permanently remove a recovery version.

Security and changes

Client-side encryption protects contents when the passphrase remains secret. It does not hide the existence of repository objects or guarantee the availability of Drive, the workstation, or the OAuth connection. This policy will be updated before any material change in access or sharing.

For questions, use the support contact shown on the Google authorization screen.

Home · Terms