Privacy Policy
Privacy Policy
Effective date: September 9, 2026
BatchHarbor is a static, frontend-only web application. It helps you select photos and videos on your device and upload them directly from your browser to Google Drive. The project does not operate an application server that receives or stores your media.
Information the app accesses
When you choose to connect Google Drive, the app requests the limited drive.file permission. It accesses only the Google Drive files and folders that the app creates or that you explicitly make available to it. During the current test phase, the app may access:
- Your Google account display name, email address, and Drive permission ID, to show which account is connected and prevent an interrupted upload from resuming under a different account.
- Names, IDs, and write capabilities of Drive folders available to the app, so you can choose a destination.
- Files you explicitly select on your device, including their names, sizes, media types, modification dates, and bytes needed for upload.
- Upload-session information and Google-confirmed progress needed to perform resumable uploads.
The app does not request your Google password. Google handles authentication and consent.
How information is used
The app uses this information only to provide the visible functions you request: connect your account, create or choose a destination, upload selected files, display progress, and safely resume supported interruptions.
The use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Where information goes
- Selected media bytes travel directly from your browser to Google Drive over HTTPS.
- Google receives authorization, folder, file, and upload requests as needed to provide Google Drive service.
- GitHub Pages serves the static website. Like other web hosts, GitHub may process ordinary request information such as an IP address and browser details under GitHub’s Privacy Statement. Media bytes and Google API requests are not routed through GitHub Pages.
The project has no advertising, analytics, data brokerage, or sale of user data. It does not share Google user data with third parties for advertising, surveillance, credit decisions, or training general-purpose AI models.
Storage and retention
In the current Phase 1 and Phase 2 tests, OAuth access tokens, live file references, folder choice, resumable session URLs, queue metadata, selection identities, and progress exist only in browser memory and are not intentionally persisted by the app. They are lost when the page is reloaded or closed. Phase 2 releases its source references for completed files while keeping completion metadata in memory to avoid reuploading them in the same tab. Google Drive retains files and folders you create according to your Google account settings and Google’s policies.
Future queue recovery may store limited upload metadata in your browser’s IndexedDB. This policy will be updated before that behavior is released.
Your choices and control
You choose which local files to select, when to connect Google, the destination, and when to begin or pause an upload. You can delete uploaded files or test folders in Google Drive and revoke the app’s access from your Google Account permissions. The app never deletes source media or existing Drive content.
Security and limitations
The site uses HTTPS, a restrictive Content Security Policy, short-lived access tokens held in memory, and the narrow drive.file scope. No system is perfectly secure. Browser and operating-system behavior can affect selected-file access, page restoration, and long-running uploads; current limitations are documented in the project repository.
Children
This application is not directed to children under 13 and is not intended for use where parental consent is legally required.
Changes and contact
Material changes will be published on this page with a new effective date before the changed data use is introduced. Questions or requests can be submitted through the project’s public issue tracker. Do not include access tokens, private filenames, or personal media in an issue.