Privacy Policy

        jester.click (“we,” “our,” or “us”) provides tools for music, fitness and learning that lets you back-up and share files to your personal Google Drive.
        We take privacy seriously and comply with:

        Google API Services User Data Policy—including the Limited Use requirements

        Google OAuth 2.0 Policies

        Applicable data-protection laws (e.g., GDPR, CCPA)

        This document explains what data we collect, how we use it, how we keep it safe, and the choices you have.

        2. What we access from Google Drive
        Scope	Why we request it
        https://www.googleapis.com/auth/drive.file	Create, open, update and delete only the files/folders our app creates so you can store DB exports, photos or backup archives.

        We do not request full-Drive (…/drive) or read-only (…/drive.readonly) scopes.

        3. Information we collect
        Category	Details	Source
        Google Drive metadata	File ID, name, MIME type, modified time—only for files created through jester.click	Google Drive API
        File content	DB changes JSON / PDF / images generated by you	Uploaded by you
        OAuth tokens	Short-lived access token and refresh token	Google OAuth
        App analytics (optional)	Anonymous crash logs / basic usage counts	Local device + Analytics provider (optional)

        We do not collect your full Drive file list, photographs, contacts, Gmail, or other Google data.

        4. How we use the data
        Core functionality

        Store your database export or backup to a folder named /MnemonicMaster-Backups (or similar).

        Retrieve those files when you choose “Restore from Drive.”

        Improve the service (optional, anonymised analytics)

        Diagnose crashes and measure feature adoption—never linked to personal Drive content.

        No advertising, no sale

        We do not sell or rent any user data, for ads or otherwise.

        5. How we share the data
        We do not share your Google Drive content or metadata with any third party, except:

        Cloud hosting provider (smarterasp.net) that runs our back-end; bound by strict confidentiality.

        If required by law (e.g., valid court order).

        6. User controls & choices
        Action	How to do it
        Revoke Drive access	Visit https://myaccount.google.com/permissions → remove “[Your App Name]”.
        Delete local data	In-app: Settings › Data › Clear local cache.
        Delete cloud backups	Open Google Drive → /Tracksups-Backups → delete files/folder.
        Request full deletion	Email privacy@jester.click; we will erase server-side tokens & related logs within 30 days.

        7. Security measures
        OAuth 2.0 flow with PKCE (web/native) or secure server-side exchange (confidential clients).

        All network traffic encrypted via HTTPS/TLS 1.2+.

        Refresh tokens stored encrypted at rest (AES-256) with environment-scoped keys.

        Principle of least privilege: Drive scope limited to app-created files.

        8. Data retention
        Data type	Retention period
        Access tokens	Minutes—auto-expired
        Refresh tokens	Until you revoke access or after 90 days of inactivity
        Back-up files on Drive	Controlled by you; we never delete without explicit request
        Crash logs / analytics	12 months, then aggregated or erased

        9. Children’s privacy
        [jester.click] is not directed to children under 13. We do not knowingly collect personal data from children.

        10. International transfers
        Data may be processed on servers in the United States or other regions where we or our providers operate, always under equivalent security safeguards.

        11. Changes to this policy
        We will post any privacy-policy changes here and update the “Last updated” date. Material changes will be emailed to registered users 30 days in advance.

        12. Contact us
        Questions or requests?
        Email: privacy@jester.click


        Summary in plain language
        We only touch the Drive folder that you let us create, keep all tokens encrypted, never sell data, and you can revoke access or delete everything at any time.