Privacy Policy

Last updated: August 25, 2026

ORVAL Runner is a private desktop utility. It is not a public SaaS product and does not operate a central user-data database.

1. Scope

This policy describes how ORVAL Runner accesses, uses, stores, and shares data obtained through Google APIs, including Google Drive data.

2. Google user data accessed

When authorized by the user, ORVAL Runner may access Google Drive file metadata and file content necessary to perform user-directed operations. Depending on the workflow, those operations may include resolving a file by Drive ID, reading metadata, downloading exact file bytes, creating a new authorized text file, reading back a newly created file, and checking for naming conflicts in a target folder.

3. How Google user data is used

Google Drive data is used only to execute the operator's explicit workflow, including:

Google user data is not used for advertising, profiling, marketing, sale, or unrelated analytics.

4. Storage and retention

OAuth client configuration and tokens are intended to be stored locally on the operator's device and outside the application's source-code repository. ORVAL Runner does not intentionally transmit OAuth tokens to a separate ORVAL Runner server because no such server is required for the desktop utility.

Local manifests may contain non-secret operational metadata such as Drive IDs, file names, byte counts, hashes, timestamps, and execution results. They are retained locally for as long as the operator chooses. Files created in Google Drive remain in the user's Google Drive until the user removes them.

5. Sharing and disclosure

ORVAL Runner does not sell Google user data and does not share it with advertisers or data brokers. Data is exchanged with Google only as necessary to perform the Google Drive API operations authorized by the user. The public website for ORVAL Runner is hosted through Cloudflare, which may process ordinary network metadata needed to deliver web pages under Cloudflare's own terms and privacy practices; the website does not intentionally send Google Drive content or OAuth tokens to Cloudflare.

6. Security

The application is designed to keep credentials outside the repository, avoid secrets in manifests and logs, prevent overwrite by default, verify created artifacts by Drive ID and cryptographic hash, and stop when a material state cannot be verified conclusively.

7. User control and revocation

Users can revoke ORVAL Runner's Google access at any time through the security and third-party access settings of their Google Account. A user can also delete the locally stored token file to require a new authorization before future Drive access. Files created in Drive can be managed or removed directly by the user in Google Drive.

8. Google API Services User Data Policy

ORVAL Runner's use of information received from Google APIs is limited to the functionality disclosed in this policy and is intended to comply with the Google API Services User Data Policy, including its Limited Use requirements.

9. Changes to this policy

This policy may be updated if ORVAL Runner's functionality or data practices materially change. The current version will remain available at this URL.

10. Contact

Privacy or support questions may be directed to the support contact shown on the Google OAuth consent screen for ORVAL Runner.