Effective 2 September 2026
Privacy Policy
This policy describes how the private SWP Hermes Encrypted Backup utility (the “Utility”) uses Google user data.
Operator and scope
The Utility is operated privately by the owner of this site for a single backup account. It is not offered to customers or the public. Privacy and support enquiries can be sent to the support address displayed on the Utility's Google OAuth consent screen.
Google data accessed
The Utility may process:
- Google Drive folder and file identifiers;
- file names, sizes, parent-folder references, and modification times;
- Google Drive storage-quota information;
- encrypted Hermes backup archives and SHA-256 checksum files; and
- OAuth credentials needed to maintain authorized access.
Although Google categorizes the requested Drive permission as broad, the Utility's behavior is limited to the designated backup folder and the backup files it creates there. It does not intentionally read unrelated Drive file contents.
How data is used
Google user data is used only to:
- locate and verify the designated backup folder;
- create a server-specific subfolder;
- upload encrypted backups and checksum files;
- verify uploaded file identifiers, names, and sizes;
- calculate storage-aware retention; and
- delete eligible old backups after a newer backup succeeds.
Storage, security, and retention
OAuth credentials and operational status are stored only on the operator-controlled server with restricted access. Hermes backup archives are encrypted locally before upload. The recovery private key is not kept on that server. Unencrypted temporary archives are removed after encryption, including when an upload fails.
Encrypted backups are retained according to a storage-aware policy. The Utility deletes only its own eligible backup files in its designated folder and only after a newer upload has been verified successfully.
Sharing and prohibited uses
Google user data is not sold, used for advertising, transferred to data brokers, or used to train AI or machine-learning models. It is not shared with third parties except as necessary for Google Drive storage and the operator's hosting infrastructure, or when legally required.
Use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Revocation and deletion
The operator can revoke the Utility's Google access from the Google Account security settings. Encrypted backup files can be removed from the designated Drive folder, and local OAuth credentials can be revoked and deleted.
This website
This informational site contains no account system, advertising, analytics, tracking scripts, or forms and sets no application cookies. Its hosting provider may process ordinary web-server logs for delivery and security.