schpro read-only · no backend 0 · telemetry 0

schpro█

Encrypted on your machine. Stored in your Drive. Held by nobody else.

schpro is a self-hosted backup utility. It reads the files you designate, encrypts them locally, and writes ciphertext into a folder in your own Google Drive, using your own Google account. There is no schpro server, no account, no telemetry. Everything below is what the program actually does — inspect it, then read the privacy policy.

0:0  IDENTITY width 0x10 read-only ● no writes
00000000 73 63 68 70 72 6f 20 3a 3a 20 73 65 6c 66 2d 68 schpro :: self-h 00000010 6f 73 74 65 64 20 62 61 63 6b 75 70 2e 20 70 6c osted backup. pl 00000020 61 69 6e 74 65 78 74 20 6e 65 76 65 72 20 6c 65 aintext never le 00000030 61 76 65 73 20 79 6f 75 72 20 6d 61 63 68 69 6e aves your machin 00000040 65 3b 20 63 69 70 68 65 72 74 65 78 74 20 6c 61 e; ciphertext la 00000050 6e 64 73 20 6f 6e 6c 79 20 69 6e 20 74 68 65 20 nds only in the 00000060 67 6f 6f 67 6c 65 20 64 72 69 76 65 20 66 6f 6c google drive fol 00000070 64 65 72 20 79 6f 75 20 63 68 6f 6f 73 65 2e 20 der you choose. 00000080 6e 6f 20 73 65 72 76 65 72 2c 20 6e 6f 20 61 63 no server, no ac 00000090 63 6f 75 6e 74 73 2c 20 6e 6f 20 74 65 6c 65 6d counts, no telem 000000a0 65 74 72 79 2e 20 72 65 76 6f 6b 65 20 61 74 20 etry. revoke at 000000b0 6d 79 61 63 63 6f 75 6e 74 2e 67 6f 6f 67 6c 65 myaccount.google 000000c0 2e 63 6f 6d 2f 70 65 72 6d 69 73 73 69 6f 6e 73 .com/permissions 000000d0 2e . 000000d1 # 209 bytes · one app name · zero endpoints but Google
0x0000

What schpro is — and what it is not

A backup program, not a service. You run it; it talks to Google on your behalf and to nothing else.

Runs onHardware you control — your own machine or server.
ReadsDisk paths you name in a local config file. Nothing else.
WritesEncrypted chunks into one Google Drive folder you choose.
Talks tooauth2.googleapis.com and the Google Drive API. Those are the program's only network destinations.
HasNo account system, no hosted dashboard, no analytics, no crash reporting, no update pinger.

Because there is no server in the path, the ordinary privacy question inverts. There is no record of you to breach, sell, or hand over: the data, the keys, and the credentials all sit inside your own perimeter.

0x1000

The data path — end to end, in one pass

Plaintext exists only on your side of the encryption stage. What leaves your machine is ciphertext; what arrives in Drive is unreadable without the keys, which never leave.

Restore reads the same chunks back and decrypts them locally, on a machine holding the key. Delete the folder and the backups are gone — nothing was copied anywhere else, because nothing could have been.

0x2000

What schpro asks Google for — and what it refuses

Authorization is OAuth 2.0 against your own account, for one job: putting your chunks in your folder and taking them out again.

Google APIGranted purpose
Google Drive API
read / write files you create or open
Upload encrypted backup chunks into the backup folder you select, and download them again when you run a restore. schpro addresses only paths inside that folder.
Google Drive API
view / manage files you open or upload
List and delete schpro's own earlier chunks, so the retention rules you configured can prune old revisions.

Verdicts, in the open

  • [+]All traffic to Google uses HTTPS/TLS. No credentials or tokens travel in plaintext.
  • [+]Tokens are stored only on your machine, in one file written with owner-only 0600 permissions.
  • [+]Content is encrypted client-side before upload; the maintainers hold no key that can read it.
  • [-]No sale of Google user data — and no third party exists to transfer it to.
  • [-]No advertising, ad targeting, or ad measurement use of Drive content.
  • [-]No machine-learning training on Google user data, generic or product-specific.
  • [-]No human access to your Drive content — no support path exists that could open it.
  • [-]No Gmail, Contacts, Calendar, or Drive-wide administrative scope is ever requested.

This handling follows the Google API Services User Data Policy, including the Limited Use requirements. The authoritative version of these terms is the privacy policy.

0x3000

Privacy policy — the short read

The full policy is at /privacy, public without login. Summary of its substance, because a summary you can check beats a banner you cannot:

Collected from you: nothing. No sign-up, no email, no name, no device identifier, no IP logging by the application, no analytics, no cookies. The program has no destination to send any of it to.

Handled on your machine: the files you designate, one config file holding your tokens, and local run logs you can delete. None of it is transmitted.

Held by us: nothing. Retention, export, correction, and deletion are therefore entirely in your hands — and total.

Destroy it, in four steps

  1. Revoke schpro at myaccount.google.com/permissions. API calls stop succeeding immediately.
  2. Delete schpro's folder in your Google Drive. Every backup is gone.
  3. Delete the config file on your machine. Every credential is gone.
  4. Uninstall the program. No registration or server-side state remains, because none exists.
→ read the full privacy policy