Privacy Policy
Last updated: September 4, 2026
Notice: This Privacy Policy governs the personal, self-hosted integration between OpenList and Google Drive, as well as this informational documentation website (oauth.121815.xyz). This is a personal, non-commercial project and is not an official Google or OpenList product.
1. Information We Access
- The application may access Google Drive files and folders only after explicit OAuth authorization by the account owner via the official Google OAuth consent screen.
- Depending on the specific Google Drive scopes granted by the user (such as
drive.fileordrive), accessed data may include file and folder names, directory structures, file metadata (e.g., MIME types, file sizes, modification timestamps), and file contents. - No data access is initiated without the user's prior informed consent and active configuration.
2. How Google User Data Is Used
- Google Drive data is used solely to provide file management functionality explicitly requested by the authorized user through their self-hosted OpenList instance.
- Permitted functions include: listing files and directories, searching, uploading new files, downloading stored files, creating folders, renaming, moving, copying, and deleting files and folders where explicitly authorized.
- Google user data is never used for advertising, marketing, user profiling, analytics, machine learning or artificial intelligence model training, creditworthiness decisions, or any other unrelated purposes.
3. Data Storage
- Informational Website: The static documentation website hosted at
oauth.121815.xyzdoes not receive, process, or store Google Drive data, OAuth access tokens, refresh tokens, passwords, or Google account credentials. The website has no database, no backend application server, and no user-data storage mechanisms. - Self-Hosted Storage: OAuth credentials, access tokens, and refresh tokens required for API communication are stored, encrypted, and processed exclusively on the user's independently operated, self-hosted OpenList server instance.
4. Data Sharing and Transfer
- Google user data is never sold, rented, leased, transferred, or shared with advertisers, data brokers, commercial partners, or unrelated third parties.
- Data transmission occurs solely and directly between Google's official API servers and the user's private self-hosted OpenList server via secure TLS-encrypted channels, strictly as necessary to perform the file actions requested by the user.
5. Data Retention and Deletion
- The website
oauth.121815.xyzdoes not retain any Google user data. - All files and folders stored in Google Drive remain entirely subject to the user's own Google Drive retention, lifecycle, and deletion settings.
- Revocation: OAuth authorization can be revoked by the user at any time through Google Account → Security → Third-party apps & services. Revoking access immediately halts the integration's ability to communicate with the user's Google Drive.
- Local Deletion: The user may permanently remove the Google Drive storage mount and delete associated OAuth client credentials and tokens directly from their self-hosted OpenList administrative interface.
6. Security
- The documentation website at
oauth.121815.xyzis statically hosted on Cloudflare Pages without dynamic script execution, backends, or credential storage, eliminating server-side credential compromise vectors. - The user is responsible for maintaining the physical, system, and network security of their self-hosted server environment, as well as protecting their private OAuth client secrets and credentials.
7. Google API Limited Use Disclosure
OpenList Google Drive Integration's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Contact Information
For any inquiries, questions, or clarification regarding this Privacy Policy or this integration, please contact the maintainer at:
Email: YOUR_EMAIL_HERE