orange_sync / Privacy
Privacy policy
Last updated: 8 October 2026
orange_sync is a personal file synchronization utility operated by Sidney Sun Xu. This policy describes the utility and these application information pages, rather than other XFaiR LLM projects.
1. Information accessed
With the account owner's Google OAuth authorization, the utility accesses Google Drive file contents and metadata needed for synchronization: file and folder names, identifiers, sizes, modification times, checksums, and folder relationships. It may read the account's email address and identifier to confirm that a connection uses the intended account.
The Drive OAuth scope permits access across the authorized account's Drive, including reading, creating, updating, and deleting files. Synchronization is configured to operate on the owner's designated folders; those folder settings are operational limits, not a narrower OAuth permission.
2. How information is used
Data is used to authenticate the connection, compare local and remote files, transfer files, verify transfers, and diagnose synchronization failures. A mirror job may remove remote files that are absent from its configured local source; a copy job retains destination-only files. The owner controls which jobs run.
The utility itself does not analyze files for advertising, profile users, or train AI models. Any separate research use of the owner's files is outside this synchronization utility.
3. Storage, access, and sharing
Files are stored on owner-controlled devices and in the owner's Google Drive. OAuth credentials and tokens are stored in restricted configuration files on the owner's devices. Local diagnostic logs may contain file paths, transfer status, and error messages.
The utility transfers data to Google to provide the requested storage and synchronization functionality. It does not sell Google user data or transfer it to advertising, data-broker, or model-training services. This public website does not receive synchronized file contents or OAuth tokens.
orange_sync's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Retention and deletion
Files remain on the configured devices and in Drive until the owner removes them or the configured synchronization rules remove them. Deleting a file in one location does not necessarily delete every copy, log entry, or version retained elsewhere.
Configuration files and local synchronization logs remain until the owner removes them. The owner can stop scheduled jobs, delete local credentials and logs, and manage stored files and trash directly in Google Drive.
5. Revoking access
The owner can revoke the application's access in Google Account third-party connections. Revocation prevents future authorized access by that connection; it does not delete files already stored locally or in Drive. Synchronization can also be stopped on the computer running the jobs.
6. This website
These application information pages do not include advertising, analytics scripts, or sign-in forms. The hosting provider, Cloudflare, processes normal web-request information, such as IP addresses and request metadata, to deliver and protect the website. See Cloudflare's privacy policy.
7. Contact and policy changes
For questions about orange_sync or its handling of data, contact Sidney Sun Xu at sunxusidney@gmail.com. Changes to this policy will be published on this page with an updated date.