Data Controller and EU Representative
Data Controller: Aliaksandr Kasabutski, contact: m-apps@m-apps.net.
EU Representative: not required, since the controller is located within an EU Member State (Poland). For GDPR inquiries, please contact the Data Controller.
This Privacy Policy describes how SyncGallery (package net.mapps.mgallery) processes personal data. We comply with the EU GDPR and applicable laws.
1. Summary
- The app is free to download. Ads and paid features may be enabled later.
- You may purchase a subscription and/or ad removal via Google Play Billing.
- Access to connected cloud storage and servers is optional and begins only after you connect an account or configure a server.
- The gallery, file manager, and synchronization features can work with photos, videos, and other file types that you choose.
- Optional AI-powered editing features (background blur, removal, replacement) process your photos locally on your device using on-device machine learning.
2. Data we process
2.1. Data you provide
- Account information and OAuth credentials provided by Google Drive, Microsoft OneDrive, Dropbox, or Yandex Disk after you authorize the app.
- Connection details and credentials you enter for Nextcloud, WebDAV, FTP/FTPS, SFTP, or SMB servers.
- Files and metadata you browse, organize, edit, transfer, or synchronize.
- Settings, preferences, subscription status, purchase receipts from Google Play.
- Storage and sync configuration: connected locations, folder selections, sync rules, and preferences you create.
2.2. Data collected automatically
- Technical data: device model, OS version, language, country, advertising identifiers (if enabled), IP (shortened where possible), crash and performance logs.
- Anonymous installation identifier: a randomly generated ID unique to each app installation, used to measure app usage frequency and improve our services. This ID is not linked to your identity or advertising profile.
- Diagnostics: feature usage, stability, crash reports (via Firebase Crashlytics if enabled).
2.3. Data from third parties
- Purchase/subscription info from Google Play Billing (not full payment card data).
- Ad networks (Google AdMob) to show ads under their policies.
- Connected storage providers (Google Drive, Microsoft OneDrive, Dropbox, and Yandex Disk) to display the connected account and perform the file operations you request.
3. Purposes and legal bases
- App functionality — contract performance (Art. 6(1)(b) GDPR) and legitimate interests (Art. 6(1)(f)).
- Advertising/analytics (when enabled) — consent (Art. 6(1)(a)).
- Payments/subscriptions — contract performance (Art. 6(1)(b)).
- Security/fraud prevention — legitimate interests (Art. 6(1)(f)).
4. Advertising and analytics
- Google AdMob — ads (personalized with consent). More: policies.google.com/technologies/ads.
- Firebase (Analytics / Crashlytics) — aggregated analytics, crash reporting: firebase.google.com/support/privacy.
In the EU, consent is obtained via User Messaging Platform (UMP) before loading ads.
5. Connected storage and synchronization
SyncGallery can browse, transfer, and synchronize files between your device and Google Drive, Microsoft OneDrive, Dropbox, Yandex Disk, Nextcloud, WebDAV, FTP/FTPS, SFTP, and SMB 2/3 locations. Connecting storage and creating sync rules are optional.
5.1. How synchronization works
- You select a folder on your device and a folder in connected storage, then choose a sync mode (upload only, download only, or two-way sync).
- The app lists, reads, uploads, downloads, and, if configured by you, deletes files according to your actions and sync rules.
- Sync may run in the background using a foreground service so you are always informed when it is active.
5.2. Sharing and invite links
Where supported by a connected provider, you may create or import a sharing link. A link may contain:
- A display label or name used to identify the sender or connection.
- The storage provider and file or folder name or identifier.
- A provider-generated URL that gives the recipient access to the shared content.
Information included in a URL may be visible in browser history, messaging apps, and server access logs. Share links only with intended recipients and manage or revoke them through the storage provider or, where available, within the app.
5.3. Google Drive — data accessed
When you connect a Google account, the app requests access to your Google Drive via OAuth 2.0. The following data is accessed:
- File and folder metadata: names, sizes, modification dates, MIME types, folder hierarchy, checksums (MD5) — used to detect changes and avoid duplicate transfers.
- File contents: files are uploaded to or downloaded from Google Drive according to your actions and sync rules.
- Account information: your Google email address and display name — used to identify the connected account within the app.
- Storage quota: total and used storage — displayed so you can manage your cloud space.
- Sharing permissions: if you choose to share a synced folder, the app manages sharing invitations on your behalf.
Access is limited to the permissions you authorize and is used to browse locations you open and to perform the file operations and sync rules you configure.
5.4. Microsoft OneDrive — data accessed
When you connect a Microsoft account, the app uses the Microsoft Graph API via OAuth 2.0. It accesses account information, storage quota, and file or folder metadata and contents as needed to browse OneDrive and perform the actions and sync rules you configure.
5.5. Dropbox and Yandex Disk — data accessed
When you connect Dropbox or Yandex Disk, the app uses the provider's OAuth service. It accesses basic connected-account information and file or folder metadata and contents as needed to browse storage and perform the actions and sync rules you configure.
5.6. Nextcloud and network servers
For Nextcloud, WebDAV, FTP/FTPS, SFTP, and SMB connections, the app communicates directly with the server address you configure. It stores the connection details required to reconnect, which may include a server address, port, username, domain, password or app password, private key and passphrase, client certificate, host key, or certificate trust settings. The app accesses only the server resources permitted by those credentials and the file operations you request.
Transport security: plain FTP does not encrypt credentials or file transfers. Prefer FTPS, SFTP, WebDAV over HTTPS, or another appropriately secured connection. The security and privacy practices of a self-hosted or third-party server are controlled by its operator.
5.7. Authentication and credential storage
Connection records and credentials are stored within the app's private storage on your device. OAuth credential handling varies by provider; some credentials are additionally protected using Android Keystore-backed keys or the provider's authentication library. Passwords, private keys, and other secrets for supported server connections are encrypted using Android Keystore-backed keys before being stored. These credentials are not sent to m-apps.net.
Removing a connection deletes its local record and credentials. It does not necessarily revoke an OAuth authorization at the provider or invalidate credentials on a server. Where applicable, revoke provider authorization or change/delete server credentials separately in the provider's or server operator's security settings.
6. AI and machine learning features
SyncGallery offers optional AI-powered editing tools. These features are clearly labeled as beta and require your explicit action to use.
6.1. On-device processing
- Face detection (Google ML Kit) — detects faces in photos for portrait enhancement and face-aware background blur. All processing occurs on your device. No facial data is sent to any server.
- Subject segmentation (Google ML Kit) — separates foreground subjects from background for background removal and blur effects. Processed entirely on-device.
All AI-powered editing features run entirely on your device. No photos are sent to external AI services for editing purposes.
7. Device permissions
- Photos/media (READ_MEDIA_IMAGES, READ_MEDIA_VIDEO) — to display, organize, and edit your photos and videos within the gallery.
- All files access (MANAGE_EXTERNAL_STORAGE) — required for the file manager and synchronization of folders and file types outside Android's standard media collections. This includes folders created by messaging apps, custom camera applications, and downloaded content. You grant this permission manually in system settings. The app uses it to display and manage device files and to perform the file operations and sync rules you request.
- Media management (MANAGE_MEDIA) — allows the app to modify or delete media files during sync and editing operations without requiring individual confirmation for each file.
- Media location (ACCESS_MEDIA_LOCATION) — to read GPS coordinates embedded in photo EXIF data, used to display photo locations on a map.
- Internet/network — connected storage and server access, ads, billing, analytics, and app configuration.
- Foreground service — to keep sync operations running reliably when the app is in the background. A persistent notification is shown while sync is active.
- Notifications — to inform you about background sync progress and completion (optional).
- Boot completed — to resume scheduled sync tasks after device restart (optional).
8. Storage and retention
- Connection profiles and credentials remain in the app's private local storage until you remove the connection, clear app data, or uninstall the app. Additional encryption varies as described in Section 5.7.
- Logs/diagnostics retained max 180 days. Anonymous installation identifiers and associated usage data are retained for the same period.
- Billing records retained as required by law.
- Sync metadata (file mappings and session data) is stored locally and deleted when you remove the corresponding sync rule or connection.
9. Data sharing/transfers
The app communicates with our own servers (m-apps.net) for app configuration, localized content delivery, and anonymous usage analytics. It also communicates with the following third-party services:
- Google Drive, Microsoft OneDrive, Dropbox, and Yandex Disk — connected-account information and your files and metadata, as directed by your actions and sync rules.
- User-configured Nextcloud, WebDAV, FTP/FTPS, SFTP, and SMB servers — connection authentication data and your files and metadata are sent directly to the server you configure.
- Google Play Billing — subscription and purchase data.
- Google AdMob — device identifiers and ad interaction data (with consent).
- Firebase (Analytics, Crashlytics, Messaging) — aggregated analytics, crash reports, push notifications.
Cross-border transfers follow GDPR safeguards (e.g., SCCs). We do not sell your personal data.
10. Data deletion
You can delete your data in the following ways:
- OAuth connections: remove your Google Drive, Microsoft OneDrive, Dropbox, or Yandex Disk connection within the app. This deletes the local connection record and credentials. Revoke the authorization separately in the provider's security settings if you also want to invalidate provider-side access.
- Server connections: remove a Nextcloud, WebDAV, FTP/FTPS, SFTP, or SMB profile within the app. To invalidate the credentials themselves, change or revoke them with the server operator.
- Sync data: delete individual sync rules to remove all associated file mappings and session data from the device.
- App data: clearing the app's storage or uninstalling the app removes its locally stored preferences, databases, credentials, and cached files.
- External data: removing a connection or uninstalling the app does not delete an account, server user, or files stored at a connected provider. File deletions that you initiate or configure through a sync rule may be propagated to connected storage.
- Analytics/diagnostics: data collected by Firebase is retained for up to 180 days and then automatically deleted.
- Advertising data: you can reset your advertising identifier or opt out of personalized ads in your device settings.
- Request deletion: you may contact m-apps@m-apps.net to request erasure of any personal data we can identify as associated with you.
11. Your rights (GDPR)
- Access, rectification, erasure, restriction, portability, objection.
- Withdraw consent anytime (does not affect prior processing).
- Complain to EU supervisory authority (residence/work).
12. Children
The app is not directed to under-13s and does not knowingly collect their data.
13. Security
We apply organizational/technical measures (encryption in transit, access controls, monitoring). 100% security not guaranteed.
14. Google API Services User Data Policy
SyncGallery's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- The app only uses Google Drive data to provide and improve the cloud synchronization features you request.
- The app does not transfer Google Drive data to third parties, except as necessary to provide the sync functionality, comply with applicable laws, or as part of a merger, acquisition, or asset sale with prior notice.
- The app does not use Google Drive data for serving advertisements.
- The app does not allow humans to read your Google Drive data unless you provide affirmative consent, it is necessary for security purposes, or it is required to comply with applicable law.
15. Changes
New version effective upon posting at: https://m-apps.net/syncgallery/html/en/syncgallery_privacy.html. Major changes may be notified in-app.
16. Contact
Privacy contact: m-apps@m-apps.net.