schpro policy · effective 2026-10-09
HDR

schpro

Privacy policy

Applies to the schpro backup application and this website · Last updated 9 October 2026

0x0000

The short version. schpro is software that runs on your own machine. It reads the files you point it at, encrypts them locally, and uploads ciphertext to a folder in your own Google Drive. There is no schpro account, server, database, or analytics. We cannot see your files, your backups, your credentials, or your usage, because nothing is sent to us at any point.

This policy states what that means in detail: what data exists, who holds it, why, for how long, and how you destroy it.

0x1000

1 · What we collect

1.1 From you, directly: nothing

schpro has no sign-up, no account system, no contact form, and no telemetry. We do not collect your name, email address, phone number, mailing address, payment details, device identifiers, IP address, geolocation, crash reports, usage events, or diagnostic logs. There is no build of schpro that phones home; the program has no network destination other than the Google endpoints named in §2.

1.2 Data the app handles on your machine

While running, schpro reads and processes data on your hardware. That data never leaves your machine except as encrypted backup chunks sent directly to your own Drive. It comprises:

  • The files you designate for backup — read from disk paths you specify in your own configuration file.
  • Your configuration file — holds the backup paths, the target Drive folder, and your OAuth token. Stored on your machine only, written with owner-only permissions (0600).
  • Local run logs — written to your machine's local storage so you can see what was transferred. These are for you alone; they are not transmitted, and you can disable or delete them.

1.3 This website

This site is a static page. It sets no cookies, uses no cookie-based tracking, embeds no third-party analytics, advertising, or social-media scripts, loads no externally hosted fonts or scripts, and runs no fingerprinting. It does not require you to log in. Server operators retain standard web-server access logs (requested path, timestamp, HTTP status) for the purpose of keeping the server running and diagnosing outages; these are not shared, sold, or combined with any profile of you.

0x2000

2 · Your Google account — what it is used for

schpro talks to Google with OAuth 2.0 using your own Google account. The purpose is single and narrow: to place and retrieve your encrypted backups in a Drive folder you chose.

2.1 What Google's APIs are used for

Google APIPurpose in schpro
Google Drive API
read / write files you create or open
Upload encrypted backup chunks into the backup folder you selected; download them again when you run a restore. schpro addresses only paths within that folder.
Google Drive API
view / manage files you open or upload
List and delete schpro's own earlier backup chunks so the retention rules you configured can prune old revisions.

2.2 What we explicitly do not do

In line with the Google API Services User Data Policy, including the Limited Use requirements:

  • [-]We do not sell Google user data, and there is no third party to whom we transfer it — schpro has no server in the data path.
  • [-]We do not use Google user data for advertising, ad targeting, or ad measurement.
  • [-]We do not use Google user data for machine-learning model training, generic or product-specific.
  • [-]We do not human-read your Drive content. No support access exists that would let us open it: backups are encrypted client-side and we hold no keys.
  • [-]We do not use Drive data for any purpose other than the backup and restore feature you invoked.
  • [-]We do not share Google user data with anyone, including for legal purposes, without first notifying you where legally permitted — again, we hold nothing to disclose.

2.3 How tokens are handled

Your OAuth access token and refresh token are issued to your account and written only to the configuration file on your own machine. They are transmitted solely over TLS to oauth2.googleapis.com and the Google Drive API endpoints. They are never sent to any schpro-controlled host, because no such host exists. Anyone holding that file holds your access, so protect the machine and revoke at myaccount.google.com/permissions if it is lost.

0x3000

3 · Where data lives, and retention

DataWhere it livesHow long
Your original filesYour machine onlyUntil you delete them.
Encrypted backup chunksYour Google Drive account onlyUntil you delete them or your retention rules prune them.
OAuth tokens, configurationYour machine only — one file, 0600Until you delete the file or revoke access.
Local run logsYour machine onlyUntil you delete them.
Anything at all, on our sideNothing exists on our siden/a
0x4000

4 · Access, correction, deletion, portability

Because schpro stores nothing about you on our infrastructure, there is no personal-data record for us to export, correct, or erase — deletion is entirely in your hands, and it is total:

  1. Revoke access: remove schpro at myaccount.google.com/permissions. API calls stop succeeding immediately.
  2. Delete the backups: delete schpro's folder in your Google Drive. Nothing is mirrored elsewhere, so that is a complete deletion.
  3. Delete the credentials: delete the configuration file from your machine.
  4. Delete the program: uninstall it. No leftover registration, subscription, or server-side state remains.

If you would like written confirmation of any of the above for your own compliance records, ask at the address in §8 and we will provide it.

0x5000

5 · Security measures

  • All network traffic uses HTTPS/TLS. No credentials or tokens travel in plaintext.
  • Backup content is encrypted before upload; the keys stay on your machine.
  • The configuration file holding your tokens is written with owner-only permissions.
  • This website is served over HTTPS with HSTS and sets no cookies.
  • Least privilege: schpro requests only the Drive scopes named in §2.1 — no Gmail, no Contacts, no Calendar, no Drive-wide administrative scope.

6 · Children

schpro is a system administration and backup tool intended for adults managing their own storage. It is not directed at children, and we knowingly collect no data from anyone, including children.

7 · Changes to this policy

If this policy changes, the effective date in the header changes and the new version is published at this URL before the change takes effect. Material changes to how Google user data is handled will additionally be announced on the homepage. Continued use of the app after a change takes effect means the new version applies.

0x6000

8 · Contact and data-controller notice

schpro is developed and distributed as free, open-source software by an individual maintainer operating as the data controller for this website. For privacy questions, a written compliance statement, or a complaint:

Email: support@schpro.in

Response target: privacy enquiries answered within 7 days.

Homepage: https://verify.schpro.in

9 · Relationship to Google

This application uses Google APIs. It is not affiliated with, endorsed by, or sponsored by Google LLC. Google Drive and Google are trademarks of Google LLC. Your use of Google Drive remains subject to Google's own terms of service and privacy policy; this document describes only schpro's handling.