Multiapp Server Backup
This policy describes how Multiapp Server Backup handles data when it connects to a Google account. It covers this tool only.
Google Drive is used for exactly one purpose: as an off-site destination for encrypted server backups. Nothing else.
drive.file.Backup payloads are encrypted before upload, on the server, using restic. The encryption key never leaves the operator's control and is not stored in Google Drive. What is uploaded to Google Drive is an encrypted repository.
OAuth credentials and refresh tokens are stored only in protected server configuration readable by the backup process alone. They are not stored in any database, source repository, application environment, log, or backup, and are never displayed in these pages.
The account owner can revoke this application's access at any time from Google Account security settings, under Security → Your connections to third-party apps & services. Doing so immediately stops the tool from reading or writing anything in Drive.
Encrypted backup files are retained in Drive according to the operator's backup retention schedule, and older ones are deleted automatically as newer ones replace them. No fixed legal retention period is claimed here.
This describes the controls actually implemented. It makes no claim to any security certification, audit, or compliance accreditation, because none is in place for this tool.
Questions about this policy: ilkin.tacan@gmail.com