Privacy Policy

Your data, your Drive.

PGVault moves your PostgreSQL and storage backups to your own Google Drive. This policy explains what we hold — and, just as important, what we never do — with your information.

Overview

PGVault (“we”, “us”) is a backup service that moves PostgreSQL and object storage archives to your own Google Drive. This policy explains what information we collect when you use the service, how it is used and protected, and the choices available to you.

By using PGVault you agree to the collection and use of information as described here. We keep this page up to date, and material changes will be reflected here and announced in-app or by email where practical.

The core promise

Your backup archives live in your own Google Drive. PGVault only instructs your Drive to upload the archive files you generate — we do not store copies of your databases or object storage payloads on our servers. Backups belong in your Drive, not on an application server.

What we collect

Account information: when you sign in with Google, we receive the name and email address Google grants. We use them to identify your account and to contact you when necessary.

Configuration metadata: the targets, schedules, and destination settings you create, together with the job history (such as run times and status) that the service records for you.

Encrypted connection details: connection URLs you provide for sources are encrypted at rest before storage. Plaintext credentials never appear in worker logs.

Diagnostics: operational data collected so we can keep the service running, repair failures, and improve reliability.

What we never collect

We never collect the contents of your databases or object storage, beyond the files you ask us to upload to your Drive.

We do not scan or monitor the other files in your Google Drive, and we do not track your browsing or activity on other websites.

We do not sell or rent your information to anyone, and we do not build advertising profiles about you.

Google Drive access

Connecting Google Drive asks for the narrow scope PGVault needs to place backup files on your behalf. All uploads go into a private PGVault folder that the service creates and manages.

Access is established through Google’s standard OAuth flow, so you can review and revoke permissions at any time from your Google Account security settings or by connecting or disconnecting the integration in the dashboard.

Disconnecting or revoking stops future uploads immediately. Archives already in your Drive are not deleted by this action — they remain under your control.

Google API Services User Data Policy

PGVault complies with the Google API Services User Data Policy, including the Limited Use requirements.

We never use your Google data or the data you back up to serve ads, to build ad targeting, to enrich or expand a profile we hold about you, or to sell or share it with third parties. We use it only to provide and maintain the backup service you asked us to run. Users cannot request or transfer this data to other services through PGVault.

How we use information

The information we collect is used only to provide the service: authentication, running the backups you configure, generating the archives you request, sending the notifications you choose, fixing breakages, and responding to your support requests.

Sharing and disclosure

We do not sell, rent, or share your personal information with third parties for their own purposes.

Limited, task-specific sharing happens only with the providers the service depends on — Google for authentication and for your Drive, our hosting infrastructure, and, if you enable it, Telegram for notifications. Each receives only the data strictly needed for its task.

We may disclose information where the law requires it, to protect the rights, property, or safety of PGVault or our users, or in connection with a change of control (for example, a merger or acquisition) — in that case, the acquirer inherits this policy.

Retention and deletion

Configuration and account data is retained while your account is active and is deleted when your account is deleted or you ask us to delete it.

Backup archives in your Drive follow the retention settings you configure on each schedule. You retain control of every copy of your backup data.

You can revoke Google Drive access at any time, which immediately stops new uploads. You can also disconnect the integration from the dashboard.

Security

Connection credentials are encrypted at rest, transport is protected with TLS, and authentication secrets are rotated and never committed to source control or logs.

No service is perfectly secure. If you use cloud-hosted databases you can reduce risk by following the provider’s security guidance and by observing the archives we write to your Drive.

Your rights

You may request access to, correction of, or deletion of the personal information we hold about you at any time by contacting us at the address below.

Where applicable by law, you may also have the right to object to or restrict certain processing of your personal information, to data portability, or to lodge a complaint with your local data protection authority.

Policy changes

We may update this policy from time to time. When information practices change, we will post the revised policy on this page and make it visible from the footer of the site.

Contact

If you have questions or concerns about privacy or this policy please contact us at pgvault@bayah.app.