Privacy Policy
Effective date: 10 October 2026
This Privacy Policy explains how G-Drive Content Poster accesses, uses, stores, transfers and protects information when authorized users connect the application to Google Drive and use the Telegram-based interface of the application.
Purpose of G-Drive Content Poster
The purpose of G-Drive Content Poster is to help authorized users manage their own content workflow: locate configured content folders in Google Drive, prepare publication bundles, upload source materials and perform user-requested media operations. Google APIs are used only to provide these file and folder operations requested by authorized users.
Who operates the application
G-Drive Content Poster is a private operational tool controlled by the bot owner/administrator. It is intended for a limited number of authorized users who work with content folders and publication materials stored in Google Drive.
What Google user data may be accessed
- Google Drive file and folder metadata, including names, identifiers, folder structure, timestamps and configured locations required to locate content.
- Content of files stored in Google Drive only when required to assemble a delivery bundle, upload incoming source materials, validate image files, or process media explicitly requested by an authorized user.
- OAuth credentials and refresh tokens associated with the configured Google account or Google Cloud OAuth client, solely to maintain authorized access to Google Drive.
- Verified Google email, permanent Google account identifier (sub), and Telegram ID are used to match the manually allowed account to its administrator and workspace.
Google permissions and their purpose
Google sign-in requests openid and email to verify the account identifier and email. The Drive permission https://www.googleapis.com/auth/drive allows viewing, creating, editing and deleting Drive files accessible to the connected account. This is a broad account permission, not a Google-enforced restriction to one folder. The application uses it to find existing configured content folders, read publication bundles, upload source files and request attachments, and maintain workflow manifests or remove files when an authorized user requests it. The current workflow locates existing folders by their configured identifiers rather than selecting individual files through Google Picker.
Telegram and workflow information
The service records Telegram user identifiers, available names and usernames, client and assistant access assignments, message identifiers, source files and request attachments, comment text, approvals and revision-request status. These records support delivery, request journals, permissions and notifications. Selected content can be delivered to the connected account's workspace administrator, assigned assistants and assigned clients. Publication to a configured Telegram channel requires a user request and the bot's publication confirmation.
How Google user data is used
Google user data is used exclusively to provide the application's requested content-workflow features, including the following:
- Discovering configured client folders and publication-date folders on Google Drive.
- Building delivery bundles for Telegram, such as covers, stories, carousels, videos and post text files.
- Uploading source materials sent by an authorized user to Google Drive folders selected by that user.
- Performing user-requested media operations, including temporary download, validation and splitting of large video files into parts before re-uploading them to Google Drive.
- Generating operational metadata such as cached availability dates, content stock calculations, task status and queue status used by the bot's internal workflows.
What the application does not do
- It does not sell Google user data.
- It does not use Google user data for advertising, unrelated profiling, or training general-purpose AI models.
- It does not transfer Google user data to unrelated third parties for independent use.
- It does not use Google APIs to generate or facilitate AI-generated non-consensual intimate imagery (AI NCII) or other abusive sexual content.
Google API use and safety
- Google APIs are used for Google Drive file and folder operations that support the application's content workflow.
- Google user data is not used to train general-purpose AI models, for advertising, or for unrelated profiling.
- The application does not use Google APIs to create, edit, facilitate or distribute AI-generated non-consensual intimate imagery (AI NCII) or other abusive sexual content.
Where data is stored
- Operational settings, client configuration, social-network mappings, schedules, allow-list information, content-date cache and task metadata may be stored in the application's persistent SQLite database on the hosting environment.
- Downloaded media files are stored only temporarily on the application server while a requested operation is being completed.
- Bot tokens and OAuth client secrets remain protected deployment secrets. Per-account access and refresh tokens are encrypted in a restricted server database with a separate private key. Workspace databases and media caches are separate.
- Workspace SQLite databases also retain post text and previews, comments in revision requests, Drive file identifiers and versions, Telegram file identifiers used to reuse uploads, and delivery, request, queue and audit history. Media bytes are held in working caches while processing or a queued retry needs them. Delivery also creates messages and file copies in Telegram; they are not an exclusively local temporary cache.
Retention and deletion
- Temporary media is removed once it is no longer needed by an active operation or queued retry, including periodic or restart cleanup. Workflow records, cached text, file identifiers and operational history remain for continuity until removed or reset by the workspace administrator or service operator. Deletion of service-side records, caches and relevant backups can be requested through the contact below; there is no automatic expiry promised for these records. Revoking Google access stops further authorized Drive operations but does not automatically delete content on Google Drive, delivered Telegram messages or the workspace history. Google and Telegram copies must be removed separately by users with permission on those services.
- Removing an administrator deletes its Google connection secrets and disables workspace access. Workspace data remains for deliberate restoration and can be deleted by the operator on request. Google access can also be revoked in Google account permissions.
Sharing and transfers
For the requested workflow, files, text and operational metadata are processed on the application's hosting infrastructure, including Amvera. Selected files and text are sent through Telegram to the workspace's authorized administrators, assigned assistants or assigned clients, or to a configured channel after publication confirmation. Incoming source materials, request attachments and workflow manifests are uploaded to the connected Google Drive. Google and Telegram process transmitted data under their own service policies. Data is not sold or shared with unrelated parties for advertising or independent profiling.
Security and access control
- The installation owner manages permitted Google-account administrators; each administrator manages client and assistant access in a separate workspace. Application checks restrict operations to the user's assigned clients. Google access and refresh tokens are encrypted with a separate server key; ordinary workflow records are stored in restricted server databases, not described as end-to-end encrypted. OAuth login uses expiring state and requires confirmation in the initiating Telegram account.
- The public website serves information and the Google OAuth callback. It does not provide public access to Drive files, request journals, workspace settings or credentials. Hosting and application logs may contain technical request information needed for operation and troubleshooting; the application's public handler omits OAuth query parameters from its access log.
Limited Use compliance
The application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide or improve user-facing features that are visible to and requested by authorized users of the application. Google API Services User Data Policy.
User choices and requests
Authorized users may stop using the application at any time. The bot owner may revoke a user's access to the bot. To request deletion of application-side operational data associated with your authorized use, or to ask a privacy-related question, contact solomka3008@gmail.com.
Changes to this policy
This Privacy Policy may be updated when the application's features or data practices change. The current version of the policy will remain published at this URL.
Contact
Privacy and data-use questions: solomka3008@gmail.com.
