Privacy Policy

Bofan Personal Drive Sync

Last updated: 21 September 2026

Scope and operator

This policy applies to Bofan Personal Drive Sync, a personal rclone configuration operated solely by BoFan Zhang to synchronize and back up the owner’s Google Drive files. It is not a public service and does not accept other users. This policy does not cover unrelated applications hosted on subdomains of bofanzhang.uk.

Data access and purpose

The configuration uses Google OAuth authorization to access Google Drive. Depending on the granted permissions and the operations requested by the owner, rclone can access file contents and metadata, including names, folder structure, sizes, and modification times, and can upload, download, update, or delete files.

This access is used only to carry out the owner’s file transfers, synchronization, and backups. OAuth access and refresh tokens allow rclone to perform authorized operations without requiring a new sign-in for every transfer. The configuration does not request or store the owner’s Google password.

Storage and retention

Files are stored in Google Drive and in the destinations selected by the owner. OAuth tokens are held in the rclone configuration or other credential storage on the computers or servers running rclone. If logging or caching is enabled, those systems may also retain file metadata, operational logs, or cached content.

The owner controls these systems, their access permissions, and their retention settings. Files, credentials, caches, and logs remain until removed by the owner or by configured retention rules. This public GitHub Pages website hosts documentation only and does not receive Drive files or OAuth tokens through the synchronization process.

Sharing and use restrictions

Google Drive data is not sold, used for advertising, or used to train AI models. Transfers are limited to Google and the storage destinations or hosting providers selected by the owner to perform the requested operations. Those providers process data under their own applicable policies.

Use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements.

Revoking access and deleting data

The owner can stop synchronization and revoke this application’s access through Google Account connections. Local credentials can also be removed from the rclone configuration.

Revoking access prevents future authorized access but does not delete existing copies, backups, logs, or caches. These must be removed separately from Google Drive and the relevant computers, servers, or storage destinations, including any trash or retained backups.

Changes and contact

This policy will be updated if the configuration’s purpose or data handling changes. Questions can be sent to BoFan Zhang at bofan.zhang@kcl.ac.uk.

Application home · Terms of Service