Privacy Policy — SyncGallery

Effective date: 2026-08-12

Owner/Operator: Aliaksandr Kasabutski (m-apps@m-apps.net)

Data Controller and EU Representative

Data Controller: Aliaksandr Kasabutski, contact: m-apps@m-apps.net.

EU Representative: not required, since the controller is located within an EU Member State (Poland). For GDPR inquiries, please contact the Data Controller.

This Privacy Policy describes how SyncGallery (package net.mapps.mgallery) processes personal data. We comply with the EU GDPR and applicable laws.

1. Summary

2. Data we process

2.1. Data you provide

2.2. Data collected automatically

2.3. Data from third parties

3. Purposes and legal bases

4. Advertising and analytics

In the EU, consent is obtained via User Messaging Platform (UMP) before loading ads.

5. Connected storage and synchronization

SyncGallery can browse, transfer, and synchronize files between your device and Google Drive, Microsoft OneDrive, Dropbox, Yandex Disk, Nextcloud, WebDAV, FTP/FTPS, SFTP, and SMB 2/3 locations. Connecting storage and creating sync rules are optional.

5.1. How synchronization works

5.2. Sharing and invite links

Where supported by a connected provider, you may create or import a sharing link. A link may contain:

Information included in a URL may be visible in browser history, messaging apps, and server access logs. Share links only with intended recipients and manage or revoke them through the storage provider or, where available, within the app.

5.3. Google Drive — data accessed

When you connect a Google account, the app requests access to your Google Drive via OAuth 2.0. The following data is accessed:

Access is limited to the permissions you authorize and is used to browse locations you open and to perform the file operations and sync rules you configure.

5.4. Microsoft OneDrive — data accessed

When you connect a Microsoft account, the app uses the Microsoft Graph API via OAuth 2.0. It accesses account information, storage quota, and file or folder metadata and contents as needed to browse OneDrive and perform the actions and sync rules you configure.

5.5. Dropbox and Yandex Disk — data accessed

When you connect Dropbox or Yandex Disk, the app uses the provider's OAuth service. It accesses basic connected-account information and file or folder metadata and contents as needed to browse storage and perform the actions and sync rules you configure.

5.6. Nextcloud and network servers

For Nextcloud, WebDAV, FTP/FTPS, SFTP, and SMB connections, the app communicates directly with the server address you configure. It stores the connection details required to reconnect, which may include a server address, port, username, domain, password or app password, private key and passphrase, client certificate, host key, or certificate trust settings. The app accesses only the server resources permitted by those credentials and the file operations you request.

Transport security: plain FTP does not encrypt credentials or file transfers. Prefer FTPS, SFTP, WebDAV over HTTPS, or another appropriately secured connection. The security and privacy practices of a self-hosted or third-party server are controlled by its operator.

5.7. Authentication and credential storage

Connection records and credentials are stored within the app's private storage on your device. OAuth credential handling varies by provider; some credentials are additionally protected using Android Keystore-backed keys or the provider's authentication library. Passwords, private keys, and other secrets for supported server connections are encrypted using Android Keystore-backed keys before being stored. These credentials are not sent to m-apps.net.

Removing a connection deletes its local record and credentials. It does not necessarily revoke an OAuth authorization at the provider or invalidate credentials on a server. Where applicable, revoke provider authorization or change/delete server credentials separately in the provider's or server operator's security settings.

6. AI and machine learning features

SyncGallery offers optional AI-powered editing tools. These features are clearly labeled as beta and require your explicit action to use.

6.1. On-device processing

All AI-powered editing features run entirely on your device. No photos are sent to external AI services for editing purposes.

7. Device permissions

8. Storage and retention

9. Data sharing/transfers

The app communicates with our own servers (m-apps.net) for app configuration, localized content delivery, and anonymous usage analytics. It also communicates with the following third-party services:

Cross-border transfers follow GDPR safeguards (e.g., SCCs). We do not sell your personal data.

10. Data deletion

You can delete your data in the following ways:

11. Your rights (GDPR)

12. Children

The app is not directed to under-13s and does not knowingly collect their data.

13. Security

We apply organizational/technical measures (encryption in transit, access controls, monitoring). 100% security not guaranteed.

14. Google API Services User Data Policy

SyncGallery's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

15. Changes

New version effective upon posting at: https://m-apps.net/syncgallery/html/en/syncgallery_privacy.html. Major changes may be notified in-app.

16. Contact

Privacy contact: m-apps@m-apps.net.