Privacy Policy — bootyhole

Effective date: 2026-09-14

This Privacy Policy describes how the bootyhole application ("the application", "this app") handles data. bootyhole is a personal, single-user tool operated by Eric Voong ("the operator") for private use on the operator's own homelab infrastructure. It is not offered as a product or service to the public, and no one other than the operator uses or authorizes it.

1. What Google user data this app accesses

The application requests the Google Drive API scope https://www.googleapis.com/auth/drive. Through this scope it can access:

This access is granted only to Google accounts that the operator personally owns, and only the operator ever completes the OAuth consent flow for this application.

2. How this data is used

Data accessed via the Drive API is used solely to:

Drive data is not used for any advertising, profiling, analytics, machine-learning model training, or any purpose unrelated to the file-storage and backup functionality described above.

3. Where data is processed and stored

All processing happens locally on the operator's own server infrastructure. OAuth credentials (refresh tokens) are stored in a local configuration file on that server, protected by filesystem permissions, and are never transmitted anywhere other than to Google's own OAuth and Drive API endpoints. Drive file contents pass through the operator's server only as needed to perform sync/copy operations and are not persisted outside of the Google Drive accounts themselves except for standard local caching inherent to the sync tooling.

4. Data sharing and disclosure

No data obtained through this application is sold, rented, shared, or disclosed to any third party, for any purpose, at any time. No data is shared with advertisers. No data is used for purposes outside what is described in this policy.

5. Data retention and deletion

Files remain in the operator's own Google Drive accounts, under the operator's control, and can be modified or deleted by the operator at any time using standard rclone commands. OAuth tokens are retained locally only for as long as the application remains in active use, and are deleted if the application is decommissioned.

6. Compliance

This application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. Revoking access

Access can be revoked at any time from Google Account → Security → Third-party access on any connected account. Revoking access immediately stops this application from being able to access that account's Drive data.

8. Changes to this policy

This policy may be updated from time to time to reflect changes in the application's functionality. The effective date above reflects the most recent update.

9. Contact

Questions about this policy can be directed to the operator via github.com/evoong.