한국어

DavRoll Privacy Policy

Effective date: August 22, 2026

DavRoll (the "App") is a personal app that backs up photos and videos, contact backup files, and user-selected PDF documents from your device to a backup destination you configure yourself (WebDAV, Amazon S3-compatible storage, SMB, SFTP, Google Drive, OneDrive, a Dropbox App Folder, iCloud Drive, or an Android SAF folder you select). This policy explains what information the App processes and how.

1. Information We Process

ItemDetailsWhere stored
Backup destination credentials WebDAV/S3/SMB connection details; SFTP server, account, absolute path, host-key algorithm, and SHA-256 fingerprint; Google Drive, OneDrive, Dropbox & iCloud Drive target metadata; OneDrive and Dropbox OAuth refresh tokens; and the Android SAF folder display name and persisted URI permission token. OneDrive and Dropbox access tokens are memory-only and refresh tokens are excluded from settings exports On-device secure storage during normal operation (flutter_secure_storage). Included only in a passphrase-protected export file when you create a full settings export
Settings export files Backup destination configuration, backup range, background sync, notification, language, and theme settings. Full exports include encrypted credentials; configuration-only exports exclude credentials Local files created only by explicit user action
Media encryption settings Encrypted-backup profile, key derivation settings, and on-device derived key material needed for restore On-device secure storage (flutter_secure_storage)
JPEG XL compression setting Whether lossless JPEG recompression is enabled for WebDAV/S3 (off by default) On-device secure storage (flutter_secure_storage)
XMP sidecar setting Whether photo tag labels are exported in plaintext XMP files for new backups (off by default) On-device secure storage (flutter_secure_storage)
Upload queue metadata Photo asset IDs, remote paths, file names, payload mode, sanitized original-fallback status, original size and dimensions, status, retry counts/timestamps, failure messages, S3 multipart resume metadata On-device local database
Local photo tags Up to eight general object or scene labels and confidence values generated by an on-device classifier for a new upload. OCR text is not generated Stored only in an app-private local database by default. If you enable XMP export, labels are sent to your configured backup destination in a plaintext .xmp file beside each newly backed-up tagged photo and can be read by the storage provider and external photo apps. They are never written to the original, logs, Analytics, or Crashlytics. See the separate Android ML Kit diagnostics row below
Android ML Kit SDK diagnostics Device and app information, an app-scoped installation identifier, performance, API configuration, feature input/output sizes, version, events, and error codes Processed by Google for image-labeling SDK diagnostics and usage analytics over HTTPS. Photo bytes and generated label contents are not transmitted
Photo and video originals Photo and video files to upload to your destination The original photo or video is not separately stored by the App and is transmitted only to your configured destination at upload time. If background new-media discovery, which is off by default, is enabled, the App checks at most 80 items at a time within the previously authorized media access and saved backup scope. JPEG XL applies only to new WebDAV/S3 JPEG photos. If media encryption is on, uploads leave the device as encrypted .droll objects. The paired MOV of a Live Photo is not currently backed up
Contacts backup file A vCard (.vcf) file created from device contacts when you run contacts backup. Contact photo bytes are excluded Created only as a temporary upload file and deleted after handling. Transmitted only to your configured backup destination
PDF document backup files PDF files found inside a folder you select for document backup The selected folder access token is stored in on-device secure storage. PDFs are copied only to temporary upload files and deleted after handling. Transmitted only to your configured backup destination
Optional organizer inputs Your natural-language organization instruction and app locale when you explicitly request a preview or name suggestion. Event-name suggestions include only a local-calendar date range, a broad media-count bucket, and whether the cluster contains images, videos, or both Used only while an approved HTTPS DavRoll backend and self-hosted LLM process the request; request and response bodies are not stored or logged. Media bytes, thumbnails, file names, asset IDs, paths, tags, albums, exact times, EXIF, locations, backup destinations, and credentials are never sent
App integrity information Firebase App Check integrity evidence and a short-lived token used to protect the optional organizer. Android uses Play Integrity and iOS uses App Attest Processed by Firebase (Google) and the applicable platform provider. The token remains in app memory and is never placed in a URL, device storage, Analytics, Crashlytics, or general logs. Organizer instructions and media information are not included in attestation requests
Diagnostics / analytics Crash logs (device model, OS/app version, stack traces), aggregate usage events and screen views Processed by Firebase (Google)

2. How We Use Information

3. Photo Library, Contacts, and Document Access

The App requests photo library access to identify photos and videos selected for backup. On Android it uses image and video media read permissions. The App never deletes original files from your photo library.

Search tags for new uploads are generated only on device with iOS Vision or Android ML Kit. Tags stay in an app-private local search index by default and do not modify the photo or its metadata. If you enable the default-off XMP sidecar option, labels for newly backed-up tagged photos are sent to the same destination in a plaintext .xmp companion. The storage provider and external apps that read XMP can see those labels, but the developer does not receive them. Existing sidecars are not overwritten and existing backups are not automatically converted. Plaintext XMP export is disabled and blocked while media encryption is enabled. OCR is not supported so sensitive text from screens or documents is not separately indexed. The bundled Android ML Kit model does not send photos for server inference, but Google processes the SDK diagnostics and usage data listed above.

Background new-media discovery is a separate optional feature from manual backup and existing queue processing, and it is off by default. Only after you enable it does the App non-interactively check up to 80 of the newest items at a time within the media access you already granted in the foreground and the backup scope saved in the App. The App never asks for new media permission from the background. If more than 80 media items are added between runs or imported in bulk, use Back up now to check the saved scope directly. On iOS, automatic discovery is skipped when limited media access and an album backup scope are used together; you can open the App to review access or the scope and run a manual backup. Each discovered photo or video is added only once to the duplicate-safe queue for every compatible enabled backup destination. Actual discovery and upload timing is best effort and depends on the background execution time granted by Android or iOS; immediate execution is not guaranteed.

When you explicitly confirm an action in Restore Center, the App can add selected supported photos and videos to the device photo library. It uses add-only access on iOS and the legacy write permission only on Android 9 or lower. Import progress and results expose aggregate counts only; local paths and photo-library identifiers are not stored or logged. Local restored files remain available after import.

When you run contacts backup, the App requests read-only contacts access. It does not modify or delete contacts and does not declare contacts write permission.

When you configure PDF document backup or an Android folder backup target, the App opens the system folder picker and accesses only the folder you select. Android uses a persistent Storage Access Framework URI grant, and iOS uses the document picker bookmark flow. An Android SAF backup target can access only the selected folder and its children; the App does not store or log real file-system paths or child document URIs. The App does not request broad file-system access.

4. Sharing and Processors

5. Network Traffic Scope

Runtime network traffic is limited to the WebDAV/S3 endpoints, SMB/SFTP servers, Google OAuth/Drive endpoints, Microsoft OAuth/Graph OneDrive endpoints, Dropbox OAuth/API endpoints, Files/iCloud Drive and Android SAF provider operations you configure, platform document picker/provider operations, platform background sync, Firebase, Android ML Kit diagnostics (Google), and—only when the feature is enabled and you explicitly request it—the approved HTTPS DavRoll organizer backend. WebDAV URLs and S3 endpoints require HTTPS in the app UI. SFTP uses SSH encryption and verifies the SHA-256 host-key fingerprint entered by the user. OneDrive requests only Microsoft's least-privilege delegated Files.ReadWrite.AppFolder permission and accesses only DavRoll's app folder in your OneDrive. Dropbox uses App Folder content access and only account_info.read, files.metadata.read, files.content.read, and files.content.write, so it can access only DavRoll's private Dropbox app folder. Organizer requests send the Firebase App Check token only in a header, never in the URL or request body.

6. Retention and Deletion

7. Your Rights

You can revoke photo, contacts, document-folder, and notification permissions at any time in device settings, disable background new-media discovery, and delete stored credentials and destination settings within the App. You may choose not to use the organizer in a release where it is available; no organizer input is transmitted until you explicitly request a suggestion. Uninstalling the App removes all on-device local data.

8. Children's Privacy

The App is not directed at children and does not knowingly collect children's personal information.

9. Changes to This Policy

If this policy changes, we will post the updated content and effective date on this page.

10. Contact

Privacy inquiries: me@nine20.net
Operated by: nine20