In short
FolderVault backs up folders from your phone to your own Google Drive. Your files, your encryption password, and the record of what's been backed up all stay on your device and in your own cloud account. The developer never receives your file contents or your password. The only data that can leave for the developer is anonymous, redacted crash diagnostics — and you can turn that off.
This policy explains, in plain terms, what data FolderVault touches, where it goes, and what control you have over it. It reflects how the app is built.
What data we handle, and where it lives
Your backed-up files
The files inside the folders you choose are uploaded to a folder FolderVault creates in your Google Drive. They travel from your device to your Google account. They are never sent to the developer or to any other party. If you enable encryption, they are sealed on your device first (see Encryption).
Your file and folder names
To keep your archive navigable, FolderVault mirrors your folder structure and keeps the original file names in Drive — adding a .crypt suffix to encrypted files. Encryption protects the contents of files, not their names. If a name or folder path is itself sensitive, be aware it will be visible to anyone with access to your Drive account.
A local index on your device
FolderVault keeps a private record on your device of what it has already uploaded — relative file paths, modification dates, sizes, and the cloud identifiers of uploaded copies. This index, along with your backup settings and the in-app activity log, is stored locally only. It is what makes incremental backup possible (only new or changed files are sent).
A plaintext manifest in your Drive folder
Alongside your backup, FolderVault may store a small plaintext file listing the names, folder structure, sizes, and modification dates of your files. This is stored in your own Drive folder only, never sent to the developer. It contains no file contents and no secrets — only information already visible from listing the folder.
Encryption and your password
- Optional, client-side. When you enable encryption for a backup, each file is encrypted on your device before it is uploaded, using AES-256-GCM with a key derived from your password (PBKDF2, 310,000 iterations, a unique nonce per file). Google Drive only ever stores the encrypted result.
- Your password stays on your device. It is wrapped using a key held in the Android KeyStore and stored only locally. It is never uploaded, never sent to the developer, and never written in readable form.
- There is no recovery. If you forget your password, your encrypted backup cannot be decrypted — by you, by the developer, or by anyone. This is a deliberate consequence of the encryption being yours alone. Keep your password somewhere safe.
Google Drive access
FolderVault connects to Google Drive using Google's official sign-in and authorization. You grant access through Google's own consent screen, and you can revoke it at any time from your Google Account's security settings.
- Limited scope. The app requests access only to files and folders it creates in your Drive (the
drive.filescope). It does not request, read, or have access to your other Drive files. - Your account identifier. The app reads your account's email address so it can show you which account a backup uses. This is stored locally with that backup's settings.
- No third-party copy. Your files move directly between your device and your Google account. The developer operates no servers that receive or store your backups.
Crash and error reporting
Because FolderVault runs unattended in the background, it uses Google Firebase Crashlytics (and its associated Analytics component) to report crashes and errors so the app can be improved.
- On by default, opt-out anytime. You can disable anonymous error reporting in Settings. Doing so turns off both Crashlytics and Analytics collection entirely.
- File contents are never logged — not on your device, not in any report.
- File names and paths are redacted before any report leaves your device. A name is reduced to its first letter and extension before being included in a crash report — for example,
report.pdfbecomesr***.pdf. This redaction is built into the reporting path and applies even when error reporting is enabled. Full, unredacted names only ever appear in on-device logs that never leave your phone. - What a report may contain: diagnostic information about the crash (such as the type of error, app version, and device model) and redacted file references. It does not contain your files, your file contents, your readable file names, or your password.
Permissions the app asks for
- Folder access. You explicitly pick each folder to back up through the system folder picker. FolderVault keeps read access to those folders so it can upload new files; it requests no broad storage permission.
- Network access. Used to upload your files to Google Drive, honoring your per-backup choice of Wi-Fi-only or any connection.
- Notifications (Android 13 and later, optional). Used to tell you when a backup needs attention — for example, if authorization expires or a folder becomes unreadable. If you decline, the app still works; the in-app activity log remains your record, and you can enable notifications later in Settings.
Sharing and selling your data
The developer does not sell your data and does not share it with advertisers or data brokers. The only parties involved are the services that make the app work:
- Google Drive — stores the backups you send to your own account, under Google's terms and privacy policy.
- Google Firebase (Crashlytics & Analytics) — receives anonymous, redacted crash diagnostics, only while error reporting is enabled.
Retention and deleting your data
- In the cloud: FolderVault never deletes your backups on its own. Backups remain in your Drive until you remove them yourself, or until a retention rule you have explicitly enabled trims older versions of a file (it always keeps the current version).
- On your device: deleting a backup in the app removes its local index, settings, and activity log, and stops its scheduled runs. It does not touch anything in Google Drive — your backed-up files remain. You can delete the Drive folder yourself using the Google Drive app if you wish.
- Uninstalling the app removes all of FolderVault's local data, including your stored (wrapped) encryption password. Your backups in Drive are unaffected.
- Revoking access: you can disconnect FolderVault from your Google account at any time via your Google Account security settings.
Children
FolderVault is a general-purpose backup utility and is not directed at children. It does not knowingly collect personal information from children.
Changes to this policy
If this policy changes, the updated version will be published here with a new "last updated" date. Material changes will be reflected in the app where appropriate.
Contact
Questions about privacy or this policy can be directed to the app's developer through the contact details listed on the app's store page. (Replace this with your support email or contact link before publishing.)