Effective September 9, 2026

Privacy & Google Drive data use

AutoVault is a self-hosted vehicle maintenance application. This policy explains what it stores and how its optional Google Drive backup integration uses Google user data.

Data stored by AutoVault

Vehicle details, maintenance metadata, reminders, file hashes, audit events, and synchronization state are stored in SQLite on the user’s home server. Original photos, receipts, invoices, and other evidence are stored as ordinary files on that server, outside SQLite.

Google user data accessed

AutoVault requests the non-sensitive Google Drive drive.file permission. It accesses the content and metadata of AutoVault files that it creates, or files the user explicitly makes available to it. It does not request access to unrelated files in the user’s Drive.

How Google user data is used

Google Drive access is used only to create a second backup copy, update AutoVault’s human-readable manifests, download AutoVault-created files for SHA-256 integrity verification, and support recovery. AutoVault does not use Google user data for advertising, profiling, credit decisions, or training generalized machine-learning or artificial-intelligence models.

Sharing and transfer

AutoVault does not sell Google user data or share it with third parties. Data is transmitted to Google Drive only as necessary to provide the backup and verification features the user requested. AutoVault’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Storage, protection, and retention

The user’s primary evidence copy remains on the home server, and the second copy remains in the user’s Google Drive. OAuth credentials and tokens are stored on the home server with restricted operating-system permissions. Evidence remains until the user removes it. Local database backups retain the newest 30 copies by default.

Deletion and revocation

The user can revoke AutoVault’s access at any time from Google Account permissions and can delete the AutoVault folder from Google Drive. The user can also remove local AutoVault data from the home server. Revocation stops future Drive synchronization but does not automatically delete files already stored locally or in Drive.

Contact

Questions about consent or this policy can be sent to the user-support email displayed on AutoVault’s Google OAuth consent screen.