Privacy Policy
App: PhotoPut · Last updated: 15 June 2026
Short version: PhotoPut does not collect, store, or share any personal data on any server
we operate. Photos, videos, and credentials stay on your device. The only external communication is the
requests your device makes directly to Google Drive on your behalf.
1. What PhotoPut does
PhotoPut lets you capture photos and videos and upload them directly to a
Google Drive folder you choose. You create named roles
(destinations), sign in with your Google account, and the app handles the upload on your behalf.
2. Data stored on your device
The app stores the following data locally on your device only:
-
Google OAuth tokens — stored locally to authenticate with Google Drive without
requiring you to sign in each time. Tokens are never transmitted anywhere other than Google's
OAuth and Drive APIs.
-
Google account email — displayed in the app so you know which account is connected
to each role. Not transmitted to any server we operate.
-
Role configurations — names, icons, colours, folder paths, and preferences you set up.
Stored in local app storage.
-
Tile images — optional background images you select or photograph for role tiles,
stored in the app's private directory.
-
Upload queue — metadata about pending uploads (file paths, timestamps, status).
The actual photos and videos are stored in standard device storage until upload completes.
-
App settings — theme, display preferences, and donation reminder state. Stored in
standard app preferences. Not sensitive.
3. Network requests
The app makes HTTPS requests to Google's OAuth and Drive APIs on your behalf. These requests include
your OAuth credentials, exactly as if you were calling the API yourself. No other servers are contacted
by this app.
Google's own privacy policy governs how they handle your data:
policies.google.com/privacy.
4. Data we do not collect
- No analytics or usage tracking
- No crash reporting services
- No advertising identifiers
- No device identifiers
- No location data
There is no backend server associated with PhotoPut. No data ever leaves your device except
the API requests described in Section 3 and the files you explicitly upload to your own Google Drive.
5. Photos and videos
Photos and videos you capture are stored on your device and uploaded only to the Google Drive folder
you configure. Local files are deleted only after a successful upload (or at your request). PhotoPut
does not access, read, or upload any photos or videos other than those you capture within the app or
select as tile background images.
6. Permissions explained
Android:
- CAMERA — required to capture photos and videos.
- RECORD_AUDIO — required to record audio with video capture.
- INTERNET — required to communicate with Google Drive.
- POST_NOTIFICATIONS — required on Android 13+ to display upload progress and status notifications.
- FOREGROUND_SERVICE — keeps the OAuth sign-in flow alive while the browser is open.
- RECEIVE_BOOT_COMPLETED — allows pending uploads to resume automatically after a device restart.
- READ_MEDIA_IMAGES / READ_EXTERNAL_STORAGE — required to select existing images for role tile backgrounds.
iOS:
- Camera — required to capture photos and videos.
- Microphone — required to record audio with video capture.
- Photo Library — required to select existing images for role tile backgrounds.
7. Google API Services disclosure
PhotoPut requests only the minimum OAuth scope needed: drive.file, which limits access
to files and folders that the app itself creates in your Google Drive. PhotoPut cannot see, read, or
modify any other files in your Drive.
8. Children's privacy
PhotoPut is not directed at children under 13 and does not knowingly collect any information from them.
9. Changes to this policy
If the privacy practices of the app change materially, this page will be updated with a new date at
the top. Continuing to use the app after a change constitutes acceptance of the updated policy.
10. Contact
Questions about this privacy policy can be sent to
photoput@rdacted.com.