Privacy Policy for RomCloud
This Privacy Policy describes in detail how RomCloud ("we", "our", or "the application") accesses, collects, uses, stores, and protects your information, with special emphasis on Google User Data accessed via Google APIs and Google OAuth 2.0.
RomCloud is a specialized handheld retro gaming library manager designed for handheld devices (including TrimUI Brick). We believe that privacy is a fundamental right. RomCloud does not run advertising, does not engage in behavioral profiling, and does not operate central user accounts or databases that store your personal files.
1. Google User Data We Access and Collect
When you explicitly connect your Google Account to RomCloud using the Google OAuth 2.0 Device Authorization flow, RomCloud requests permission to access the following Google user data:
-
Google Account Information (Email and Profile Identifier):
Scope: https://www.googleapis.com/auth/userinfo.email, openid
Purpose: To authenticate your session and display your connected Google email address within the application settings so you can identify which account is currently active.
-
Google Drive Application Files:
Scope: https://www.googleapis.com/auth/drive.file (and optionally https://www.googleapis.com/auth/drive if requested for dedicated directory synchronization).
Purpose: To upload, download, and synchronize your personal game ROM files, save-game states (.sav, .srm, .state), screenshots, and backup configuration archives between your handheld console SD card and your personal Google Drive storage. RomCloud only accesses, modifies, or deletes files and folders created by RomCloud or files you specifically designate for synchronization.
-
OAuth Credentials (Access & Refresh Tokens):
Purpose: Temporary authentication tokens issued directly by Google's OAuth servers to maintain your authorized session without requiring you to re-authenticate on every backup or sync action.
Google API Services User Data Policy Compliance (Limited Use Disclosure)
RomCloud's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
2. How We Use and Restrict Google User Data
We strictly govern our use of Google user data as follows:
- Solely for User-Facing Features: Google user data is accessed solely to provide, maintain, and execute user-requested features—specifically cloud backup and synchronization of user gaming saves and ROM libraries.
- No Advertising or Marketing: Google user data is NEVER used to serve advertisements, retarget users, build advertising profiles, or monetize user activity in any way.
- No Sale or Commercial Transfer: We NEVER sell, rent, lease, or transfer your Google user data to data brokers, advertisers, or any commercial third parties.
- No Machine Learning or AI Model Training: Google user data is NEVER used to train, retrain, fine-tune, or develop generalized artificial intelligence (AI) models, large language models (LLMs), or machine learning systems.
- Human Access Restrictions: Humans will NOT inspect or read your Google user data, files, or tokens, except under the following strict conditions:
- You provide explicit, affirmative written consent (such as requesting developer assistance to inspect a specific corrupted sync archive);
- It is strictly necessary for security purposes (such as diagnosing a critical bug or investigating malicious abuse);
- It is required to comply with applicable legal obligations, subpoenas, or court orders; or
- The data is aggregated and anonymized for internal system operational metrics.
3. How Google User Data is Stored, Protected, and Transferred
- Client-Side Local Storage: All OAuth tokens (access tokens, refresh tokens) and account metadata are stored locally on the user's handheld device in an encrypted/protected local SQLite database (
data/library.db) located on your local SD card.
- No Intermediate Cloud Servers: RomCloud operates NO intermediary servers that store, cache, or intercept your Google Drive files or Google OAuth credentials. Communication occurs directly between your handheld console and Google's official API endpoints (
https://oauth2.googleapis.com and https://www.googleapis.com) via industry-standard TLS/HTTPS encryption.
- Secure Transmission: All data in transit between your device and Google's servers is encrypted using modern TLS (Transport Layer Security) cryptographic protocols.
4. Data Retention and Deletion (Your Rights)
You maintain complete control over your data at all times:
-
In-App Disconnect / Sign Out: You can disconnect your Google account at any time in RomCloud settings by selecting "Đăng xuất" (Sign Out). This immediately deletes all stored OAuth access tokens, refresh tokens, and account emails from your device's local database.
-
Revoking Permissions via Google: You can immediately revoke RomCloud's access to your Google account at any time by visiting Google's official Security permissions portal:
https://myaccount.google.com/permissions
Once revoked, RomCloud can no longer access your Google Drive or account data.
-
Deleting Cloud Backups: Because RomCloud stores files directly in your personal Google Drive, you can view, download, or permanently delete your backed-up ROMs and save files at any time by opening Google Drive in any web browser or mobile app.
-
Deleting Local Device Data: You can erase all local settings, cached databases, and credentials by deleting the
/mnt/SDCARD/Apps/RomCloud/data/ directory on your SD card.
-
Requesting Data Deletion: If you have submitted any diagnostic logs or inquiries and wish to have them deleted from our records, email us at bun2it@gmail.com, and we will fulfill your request within 30 days.
5. Other Non-Google Information We Collect
To ensure system stability across handheld hardware revisions, the following non-Google diagnostic information may be collected:
- Anonymous Device Identifier: A non-reversible SHA-256 hash (e.g.
RC-xxxxxxxx) generated on initial launch to differentiate anonymous bug reports. It cannot be reverse-engineered to identify your hardware serial number or personal identity.
- Anonymous Crash / Error Telemetry: When an unhandled exception or system crash occurs, diagnostic information (application version, device model, free memory, display resolution, error code) may be relayed to a private GitHub bug tracker to fix software defects. These reports never include Google passwords, OAuth tokens, or Google Drive file contents.
- GitHub Token (Optional): If you provide a personal GitHub token to report bugs directly to your own repositories, it is stored strictly locally on your device.
6. BrickDrop Protocol (Local-Only Transfers)
The companion utility BrickDrop facilitates offline peer-to-peer file transfers between your local devices over Wi-Fi using the open LocalSend protocol. BrickDrop operates entirely offline within your local area network (LAN), requires no user accounts, sends no telemetry to cloud servers, and does not touch your Google account.
7. Website Privacy (romcloud.linkpc.net)
Our official website (https://www.romcloud.linkpc.net/) is a static website hosted via GitHub Pages. We do not use tracking cookies, analytics trackers, or third-party advertising scripts. Standard web server access logs collected by GitHub Pages are governed by the GitHub Privacy Statement.
8. Children's Online Privacy Protection (COPPA)
RomCloud is a general-audience retro gaming utility and does not knowingly solicit or collect personal information from children under the age of 13. If you believe a child has provided us with personal information, please contact us immediately, and we will delete the data.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable legal requirements. When updates occur, we will revise the "Effective Date" at the top of this page. We encourage users to periodically review this page for the latest privacy practices.
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, your Google User Data, or our privacy practices, please contact the developer directly:
RomCloud Development Team
Email: bun2it@gmail.com
Website: https://www.romcloud.linkpc.net/
Project Repository: https://github.com/bun2it/RomCloud