← AbaGin Infisical Backup

Privacy Policy

Last updated: 21 September 2026

This policy describes how the Google OAuth client named AbaGin Infisical Backup, operated by AbaGin Consulting Limited, accesses and uses Google Drive data for private backup and disaster-recovery purposes.

1. Google API access

The application requests only the Google Drive https://www.googleapis.com/auth/drive.file scope. This permission allows the application to create, read, update, and delete Google Drive files that it creates or that are explicitly used with the application. The application does not request unrestricted access to the connected account's entire Google Drive.

2. Data processed

The application processes OAuth authorization tokens needed to authenticate to Google Drive, file and folder metadata needed for backup operations, and the encrypted backup files themselves. It does not request Google profile, contacts, Gmail, Calendar, or unrelated Google account data.

3. Purpose of processing

Google Drive access is used solely to create, verify, retrieve, and manage encrypted offsite backups of the operator's self-hosted Infisical environment, including restore and disaster-recovery testing.

4. Encryption and security

Backup content is encrypted on the client side before upload. OAuth credentials, refresh tokens, and encryption credentials are kept outside this public website repository and are not published in source control. Access is restricted to the backup environment and authorized operators.

5. Data sharing

Google API data obtained through this application is not sold, used for advertising, or shared with unrelated third parties. Data is transferred only as needed to operate the backup workflow and the selected Google Drive storage service.

6. Retention and deletion

Backup files are retained according to the operator's backup and disaster- recovery policy and may be deleted when they expire or are no longer required. OAuth tokens are retained only while the Google Drive connection is required. Access can be revoked at any time from the connected Google Account's security settings; stored OAuth credentials can also be removed from the backup environment.

7. Limited use

The application's use of information received from Google APIs is limited to the functionality described in this policy: private encrypted backup, integrity verification, restore, and disaster recovery.

8. Contact

Questions about this OAuth client or its handling of Google Drive data can be sent to abagin.consulting@gmail.com.

This policy covers the Google OAuth client and backup workflow described above.