Privacy Policy
Effective 7 September 2026
Scope
This policy applies to Hermes Drive Backup, a private, personal-use application operated solely for the owner of this domain. The application is not available to the public.
Google Drive access
Google Drive is the application’s required storage provider. When the owner authorizes the application, Google OAuth grants permission to view and manage files in the owner’s Google Drive. The application is configured and intended to use that access only to:
- create and identify the owner’s dedicated Hermes backup folder;
- upload encrypted VPS backup files and their checksum files;
- verify uploaded file identifiers, names, sizes and checksums;
- list backup files created by this application; and
- delete only application-created backup files under a retention policy explicitly approved by the owner.
The application does not request access to Gmail, Calendar, Contacts, Docs or Sheets.
Backup data
When backup operation is enabled, VPS backup contents are encrypted before they are uploaded. Google Drive stores the encrypted backup, its checksum, and associated file metadata solely for backup and recovery. The private recovery key is not uploaded to Google Drive.
Use and sharing
Google Drive data is not sold, rented, used for advertising, or shared with data brokers. It is not used for analytics, profiling or training models. Transfer or disclosure would occur only when required by law or necessary to protect the security of the owner’s systems.
The application’s use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements.
Storage, security and retention
OAuth credentials are kept on the owner’s secured VPS and are not exposed through this website. Backups remain in the owner’s Google Drive until removed by the owner or by the owner-approved backup retention process. The website itself does not collect form submissions, set cookies, run analytics or include tracking technology.
Control and deletion
The owner can revoke the application’s Google access from the Google Account permissions page and can delete the application-created backup files directly from Google Drive. Privacy or deletion questions can be directed to the support contact displayed on the application’s Google OAuth consent screen.
Changes
This policy will be updated if the application’s actual data practices change. The effective date above identifies the current version.