Privacy Policy
Last updated: August 25, 2026
1. Scope
This policy describes how ORVAL Runner accesses, uses, stores, and shares data obtained through Google APIs, including Google Drive data.
2. Google user data accessed
When authorized by the user, ORVAL Runner may access Google Drive file metadata and file content necessary to perform user-directed operations. Depending on the workflow, those operations may include resolving a file by Drive ID, reading metadata, downloading exact file bytes, creating a new authorized text file, reading back a newly created file, and checking for naming conflicts in a target folder.
3. How Google user data is used
Google Drive data is used only to execute the operator's explicit workflow, including:
- verifying file identity and metadata;
- computing integrity hashes over downloaded bytes;
- evaluating deterministic preconditions;
- creating authorized text artifacts without overwriting existing files;
- re-downloading created artifacts to verify content and metadata; and
- producing local manifests and telemetry about the execution.
Google user data is not used for advertising, profiling, marketing, sale, or unrelated analytics.
4. Storage and retention
OAuth client configuration and tokens are intended to be stored locally on the operator's device and outside the application's source-code repository. ORVAL Runner does not intentionally transmit OAuth tokens to a separate ORVAL Runner server because no such server is required for the desktop utility.
Local manifests may contain non-secret operational metadata such as Drive IDs, file names, byte counts, hashes, timestamps, and execution results. They are retained locally for as long as the operator chooses. Files created in Google Drive remain in the user's Google Drive until the user removes them.
5. Sharing and disclosure
ORVAL Runner does not sell Google user data and does not share it with advertisers or data brokers. Data is exchanged with Google only as necessary to perform the Google Drive API operations authorized by the user. The public website for ORVAL Runner is hosted through Cloudflare, which may process ordinary network metadata needed to deliver web pages under Cloudflare's own terms and privacy practices; the website does not intentionally send Google Drive content or OAuth tokens to Cloudflare.
6. Security
The application is designed to keep credentials outside the repository, avoid secrets in manifests and logs, prevent overwrite by default, verify created artifacts by Drive ID and cryptographic hash, and stop when a material state cannot be verified conclusively.
7. User control and revocation
Users can revoke ORVAL Runner's Google access at any time through the security and third-party access settings of their Google Account. A user can also delete the locally stored token file to require a new authorization before future Drive access. Files created in Drive can be managed or removed directly by the user in Google Drive.
8. Google API Services User Data Policy
ORVAL Runner's use of information received from Google APIs is limited to the functionality disclosed in this policy and is intended to comply with the Google API Services User Data Policy, including its Limited Use requirements.
9. Changes to this policy
This policy may be updated if ORVAL Runner's functionality or data practices materially change. The current version will remain available at this URL.
10. Contact
Privacy or support questions may be directed to the support contact shown on the Google OAuth consent screen for ORVAL Runner.