schpro█
Encrypted on your machine. Stored in your Drive. Held by nobody else.
schpro is a self-hosted backup utility. It reads the files you designate, encrypts them locally, and writes ciphertext into a folder in your own Google Drive, using your own Google account. There is no schpro server, no account, no telemetry. Everything below is what the program actually does — inspect it, then read the privacy policy.
What schpro is — and what it is not
A backup program, not a service. You run it; it talks to Google on your behalf and to nothing else.
| Runs on | Hardware you control — your own machine or server. |
| Reads | Disk paths you name in a local config file. Nothing else. |
| Writes | Encrypted chunks into one Google Drive folder you choose. |
| Talks to | oauth2.googleapis.com and the Google Drive API. Those are the program's only network destinations. |
| Has | No account system, no hosted dashboard, no analytics, no crash reporting, no update pinger. |
Because there is no server in the path, the ordinary privacy question inverts. There is no record of you to breach, sell, or hand over: the data, the keys, and the credentials all sit inside your own perimeter.
The data path — end to end, in one pass
Plaintext exists only on your side of the encryption stage. What leaves your machine is ciphertext; what arrives in Drive is unreadable without the keys, which never leave.
00000000 ┌──────────────┐ 00000010 │ YOUR MACHINE │ plaintext ▓▓▓▓▓▓▓▓ your files, your disk 00000020 │ encrypt │ ────────────▶ ciphertext ▒▒▒▒▒▒▒▒ keys stay local 00000030 └──────────────┘ TLS 00000040 ┌──────────────────┐ 00000050 │YOUR GOOGLE DRIVE│ the folder you picked 00000060 └──────────────────┘ 00000070 [!] no schpro server exists at any hop above
Restore reads the same chunks back and decrypts them locally, on a machine holding the key. Delete the folder and the backups are gone — nothing was copied anywhere else, because nothing could have been.
What schpro asks Google for — and what it refuses
Authorization is OAuth 2.0 against your own account, for one job: putting your chunks in your folder and taking them out again.
| Google API | Granted purpose |
|---|---|
| Google Drive API read / write files you create or open |
Upload encrypted backup chunks into the backup folder you select, and download them again when you run a restore. schpro addresses only paths inside that folder. |
| Google Drive API view / manage files you open or upload |
List and delete schpro's own earlier chunks, so the retention rules you configured can prune old revisions. |
Verdicts, in the open
- [+]All traffic to Google uses HTTPS/TLS. No credentials or tokens travel in plaintext.
- [+]Tokens are stored only on your machine, in one file written with owner-only
0600permissions. - [+]Content is encrypted client-side before upload; the maintainers hold no key that can read it.
- [-]No sale of Google user data — and no third party exists to transfer it to.
- [-]No advertising, ad targeting, or ad measurement use of Drive content.
- [-]No machine-learning training on Google user data, generic or product-specific.
- [-]No human access to your Drive content — no support path exists that could open it.
- [-]No Gmail, Contacts, Calendar, or Drive-wide administrative scope is ever requested.
This handling follows the Google API Services User Data Policy, including the Limited Use requirements. The authoritative version of these terms is the privacy policy.
Privacy policy — the short read
The full policy is at /privacy, public without login. Summary of its substance, because a summary you can check beats a banner you cannot:
Collected from you: nothing. No sign-up, no email, no name, no device identifier, no IP logging by the application, no analytics, no cookies. The program has no destination to send any of it to.
Handled on your machine: the files you designate, one config file holding your tokens, and local run logs you can delete. None of it is transmitted.
Held by us: nothing. Retention, export, correction, and deletion are therefore entirely in your hands — and total.
Destroy it, in four steps
- Revoke schpro at myaccount.google.com/permissions. API calls stop succeeding immediately.
- Delete schpro's folder in your Google Drive. Every backup is gone.
- Delete the config file on your machine. Every credential is gone.
- Uninstall the program. No registration or server-side state remains, because none exists.