ZakAI Deterministic Backup CI

Privacy notice — ZakAI Deterministic Backup CI

ZakAI Deterministic Backup CI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

The Google authorization requests only https://www.googleapis.com/auth/drive.file. This scope allows the utility to access files it creates and files or folders explicitly authorized for use with the utility. It does not grant general access to the owner's entire Google Drive.

The utility uses the selected folder's identity and permissions to verify that backups can be stored there. It creates encrypted backup files and verification metadata, reads and downloads its backup files, and lists its accessible backup files to calculate retention. When retention is enabled after successful recovery verification, older eligible files created by the utility may be moved to Drive Trash. It does not permanently empty Trash.

Google OAuth credentials and other sensitive configuration values are stored in GitHub Actions encrypted secrets associated with the private repository. They are not stored in repository source files. Tokens are used by the backup scripts to access the authorized Drive files. Credential values, plaintext backup contents and private encryption keys are not published in repository files or Actions logs. Google Drive receives encrypted backup files; plaintext source exports and restored files exist temporarily on the GitHub runner during backup and verification and are cleaned up afterward.

Backup encryption uses AES-256-GCM with a fresh data key, wrapped using RSA-OAEP-SHA-256. The recovery private key is held in GitHub Actions encrypted secrets for verification and in a locally stored password-encrypted recovery file. The owner is responsible for keeping the recovery password and an additional safe copy of that encrypted recovery file.

Backup data and Google user data are used only to store, verify and manage the owner's backups. They are not used for advertising or AI training. Google Drive, GitHub and Cloudflare provide the storage and execution services involved in this process.

The configured retention policy keeps representatives for 7 UTC days, 4 ISO weeks and 12 calendar months, with overlaps deduplicated. Unverified generations are excluded from automatic pruning. Retention is subject to successful verification; scheduling or deletion is enabled only after the applicable verification and credential gates pass.

The owner can revoke the Google grant through Google Account permissions, remove the repository secrets, and manage backup files directly in Drive. Revocation prevents future authorized Drive operations; it does not by itself delete existing backup files or restore application data. Privacy questions: dikatom@gmail.com.

This notice describes the backup utility. It does not introduce new contractual terms or change the ZakAI application's existing policies.