Digiroids turns a Google Drive folder of photos into a shareable album. This policy explains what information Digiroids handles, why, where it goes, and the choices you have. We have tried to write it in plain language.
The short version
- Digiroids runs in your browser and talks directly to your Google Drive. We do not run a database of your photos, albums or accounts.
- Your photos stay in your Drive. The only file Digiroids creates is
album.json, in the folder you choose, and only when you tap Publish. - Viewers never need to sign in. Creators sign in with Google.
- No ads, no analytics, no tracking, and we never sell or rent your information.
1. Who we are
Digiroids (“we”, “us”, “the app”) is the web app available at digiroids.pages.dev. For any privacy question or request, write to bkdev307@gmail.com.
2. Information the app handles
| Information | Why it is needed | Where it lives |
|---|---|---|
| Your Google name, email address and profile picture | To show who is signed in | Your browser tab only (session storage) |
| A Google sign-in access token | So your browser can use Google Drive on your behalf | Your browser tab only, for about an hour |
| Names and modified dates of your Drive folders | To build the “Your albums” list | Browser memory while the page is open; not saved |
| Photos in a folder you open | To display them and let you caption them | Browser memory while open; the originals stay in your Drive |
| Album details you enter: title, description, captions, dates, places, and which photos are selected | To build your album | Your Drive, inside album.json, only after you tap Publish |
| Folder sharing setting | So viewers can open the album, if you leave that option on | Your Drive (folder permissions) |
Digiroids does not ask for, and does not collect, your password, payment details, contacts, location, or device identifiers.
3. What the Google permissions are used for
When you sign in, Google asks you to approve the following access. You can see and change it at any time (see section 9).
- Profile, email and OpenID. Used only to show your name, email and picture inside the app.
- Google Drive. Used to (a) list your folders and check which ones already contain an
album.json, so we can mark them Published; (b) read the photos and thealbum.jsonin a folder you open; (c) create or updatealbum.jsonin that folder when you tap Publish; and (d) if you leave the option ticked, set that folder to “anyone with the link can view”.
Digiroids only acts on the folder you open. It does not read the contents of your other files, and it never deletes, moves or renames your files or photos. When it lists your folders and looks for published albums it reads only names, IDs, parents and modified times, never file contents.
The app's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. In particular, we do not use Google user data for advertising, we do not sell it, we do not transfer it to others except as needed to provide the features you use or to comply with law, and no person reads your data.
4. How we use information
- To sign you in and show your account details.
- To let you browse, caption, select and publish photos from your own Drive.
- To show a published album to people you share it with.
- To keep the app secure and working. We do not build advertising profiles or analyse your behaviour.
5. Published albums and sharing
An album is just your folder plus album.json. If you leave “Anyone with the link can view” on when publishing, anyone who has the link can see the photos in that folder and the details saved in album.json (title, description, captions, dates and places). Please do not publish anything you would not want others to see. Share links contain your folder's ID, so treat the link like a key.
Viewers do not sign in. Their browser fetches your photos straight from Google Drive using a read-only API key, so Google, like any website host, receives their request (for example their IP address). To stop sharing an album, remove the link-sharing setting from the folder in Google Drive, or delete album.json.
6. Who else is involved
- Google provides sign-in, Google Drive and Google Fonts. Their handling of your data is covered by Google's Privacy Policy. Google may set its own cookies when you sign in.
- Cloudflare hosts this website. Like any host, it may process standard request data such as IP address, browser type and the pages requested, to deliver and protect the site. See Cloudflare's Privacy Policy.
- Sharing apps. If you tap WhatsApp, Telegram, Facebook, X, LinkedIn, Messages or Email in the share sheet, the album link is passed to that service, which has its own privacy policy.
We do not sell, rent or trade personal information, and we do not share it with advertisers or data brokers.
7. Cookies and browser storage
Digiroids does not set advertising or tracking cookies. It uses your browser's session storage to keep you signed in while the tab is open. That data is removed when you sign out or close the tab. Photos you are editing are held in temporary browser memory and are discarded when you leave the page.
8. Retention
We keep no copy of your photos, account details or albums. Sign-in details disappear from your browser when you sign out or close the tab, and tokens expire on their own after about an hour. album.json stays in your Drive until you delete it. Hosting providers may keep short-lived technical logs under their own policies.
9. Your choices and rights
- Sign out in the app. This also asks Google to revoke the token.
- Remove access at any time at myaccount.google.com/permissions.
- Unpublish by deleting
album.jsonfrom the folder, or turn off link sharing in Google Drive. - Access, correction and deletion. Because we do not hold your data, there is normally nothing for us to export or erase, as everything is in your Drive and under your control. If you believe we hold information about you, contact us and we will respond.
Depending on where you live (for example under the EU and UK GDPR, California privacy law, or India's Digital Personal Data Protection Act, 2023) you may have additional rights, including to access, correct, delete or object to the use of your personal data, and to complain to your local data protection authority. We will honour valid requests.
10. Security
All traffic uses HTTPS. Sign-in uses Google's OAuth, so Digiroids never sees your Google password. Your access token is kept only in the current browser tab. No online service can be guaranteed completely secure, so please use a trusted device, sign out on shared computers, and take care who you share links with.
11. Children
Digiroids is not directed at children under 13 (or the minimum age in your country). We do not knowingly collect personal information from children. If you think a child has used the app and you want help, contact us.
12. International use
Google and Cloudflare operate globally, so information handled by those services may be processed in countries other than your own, under their own safeguards.
13. Changes to this policy
We may update this policy as the app changes. The “Last updated” date above will change, and for significant changes we will make a visible notice in the app.
14. Contact
Questions or requests? Email bkdev307@gmail.com.