Devaya Technologies
Privacy policy — PhotoBackup
Last updated: 14 September 2026
This policy covers PhotoBackup, the backup component of the Devaya Technologies photo server. PhotoBackup is the application that requests access to Google Drive, so this policy describes precisely what that access is used for.
The short version. PhotoBackup runs entirely on hardware you
own, signs in to your Google account, and uploads encrypted backup files to
your Google Drive. It asks for the drive.file scope only, so it
can touch only the files it created itself. Your files are encrypted on your machine
before they leave it. Nothing — no file, no filename, no key, no usage report — is
sent to Devaya Technologies. There is no Devaya Technologies server involved in the
backup path at all. The only thing that ever reaches me is an email, if you send
one.
1. Who this policy is from
PhotoBackup is published by Devaya Technologies, a sole proprietorship of Devendra Chouhan, based in the United Arab Emirates. Contact: [email protected].
Devaya Technologies does not operate any hosted service for PhotoBackup. There is no account system, no user database and no record kept here of who is running the software.
2. What PhotoBackup is
PhotoBackup is self-hosted software. You install it on your own computer or server. It reads photos from storage you control, encrypts backup data locally, and uploads that encrypted data to a Google Drive account that you authorise.
There is no account with Devaya Technologies, no login to any service of mine, and no cloud component that I operate. An installation runs independently, under the control of whoever installed it, using their own Google account. There is no central instance and nothing is shared between installations.
3. Google account access and the scope requested
When you connect PhotoBackup to Google Drive, you sign in through Google's own consent screen. PhotoBackup receives an access token from Google. That token is stored on your machine, by your installation. Devaya Technologies never receives it and has no way to obtain it.
The scope
PhotoBackup requests one Google OAuth scope:
https://www.googleapis.com/auth/drive.file- Per-file access to files that the application itself creates or that you explicitly open with it. This scope cannot be used to list, read, modify or delete any other content in your Drive.
In practical terms: PhotoBackup can create its own backup files in your Drive, and can read, update and delete those files in order to manage the backup set. It cannot see your documents, your other photographs, your spreadsheets, your shared drives or anything else in your account. That boundary is enforced by Google, not merely by the application's own code.
PhotoBackup does not request broad Drive scopes, does not request Gmail, Calendar, Contacts or Photos scopes, and does not request any scope beyond the one listed above.
4. Encryption before upload
Backup data is encrypted on your own machine before any upload takes place. The encryption key is generated on and held on your machine. It is not transmitted to Google, not transmitted to Devaya Technologies, and not escrowed anywhere.
Both file contents and original filenames are covered: what appears in your Google Drive is encrypted data under opaque names. The intent of that design is that the uploaded backup is of no use without your key. Devaya Technologies does not hold your key and has no way to obtain it.
Stated plainly: this software is early access and has not been independently audited, so treat the encryption as a design intention rather than as a verified guarantee. The design does mean that if you lose your key, nobody — myself included — can recover the backup for you. Keep the key safe, and keep a copy somewhere separate from the machine it was generated on.
5. What Devaya Technologies receives
Nothing. The software is not built to send anything back, and there is no endpoint here for it to send anything to. Specifically, Devaya Technologies does not receive:
- your photographs or any other file content;
- filenames, folder names, EXIF metadata, thumbnails or file listings;
- your encryption key or any part of it;
- your Google account identity, email address, OAuth tokens or Drive contents;
- usage statistics, telemetry, crash reports, heartbeat pings or licence checks;
- your IP address, device identifiers or network details.
PhotoBackup makes network connections to Google's APIs in order to perform the backup you asked for. It does not make network connections to Devaya Technologies.
6. The one thing that is held
The statement above is about the software. Separately, if you write to me, that correspondence exists: email [email protected] and your message and address sit in an ordinary email inbox. It is used to reply to you and nothing else. It is not added to a mailing list, not shared, and not sold. Ask and it will be deleted.
7. No analytics, tracking, advertising or sale of data
- PhotoBackup contains no analytics SDK, no tracking pixels and no third-party telemetry.
- No data obtained through Google APIs is used for advertising, ad targeting, profiling or personalisation of any kind.
- No data obtained through Google APIs is sold, rented, licensed or transferred to data brokers, information resellers or any other third party.
- No data obtained through Google APIs is used to train machine learning or artificial intelligence models, mine or anyone else's.
- I do not read your data, because none of it reaches me.
This website — devayatechnologies.com — carries no analytics, no cookies, no tag managers and no third-party scripts. It is static HTML and CSS served as files.
8. Google API Services Limited Use disclosure
PhotoBackup's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data received from Google APIs is used only to provide the backup function you requested, in the installation you control. It is not transferred to any other application, service or party.
9. Where your data lives, and for how long
Your original photographs remain on your own storage. Your encrypted backups remain in your own Google Drive, subject to Google's terms and your own account settings. Retention is entirely your decision: PhotoBackup keeps backup files in Drive until you or your configured retention rules remove them.
Because Devaya Technologies stores none of it, there is no retention period on this side to describe.
10. Revoking access
You can disconnect PhotoBackup from your Google account at any time from your Google Account security settings, under third-party access. Revoking access stops further uploads immediately. Files already uploaded stay in your Drive, and you can delete them yourself from Drive like any other file.
Because access is granted under the drive.file scope, revoking it also
removes PhotoBackup's ability to manage the files it previously created.
11. Children
PhotoBackup is not directed at children and is not intended for use by them.
12. Security, stated honestly
Local encryption before upload is the main protection this software provides. Beyond that, the security of your installation depends on the machine you run it on, the network it sits on, and the security of your own Google account. Those are outside my control.
This is early-access software. It has not been independently audited. If you find a security problem, please report it to [email protected].
13. Changes to this policy
If this policy changes, the revised version will be published at this address and the date at the top will be updated. Material changes to what the software does with your data will be described rather than quietly absorbed.
14. Contact
Questions about this policy, about what the software does, or requests relating to any correspondence held here: [email protected].
Devaya Technologies.