Privacy Policy

Your library stays between you and your chosen storage.

Effective September 18, 2026

1. Scope

This policy explains how the HammyBackup iOS app and this website handle information. HammyBackup is designed to transfer photos and videos from your iPhone directly to a backup destination you control or select.

2. Information the app accesses

  • Photos and videos: media you authorize through Apple Photos, plus metadata needed to plan, name, upload, verify, and display backup status.
  • NAS/SMB settings: server address, share, folder, username, and password you provide.
  • Google Drive information: your Google account email, OAuth authorization, and identifiers for folders and files created or accessed by HammyBackup.
  • On-device records: destination settings, backup progress, verification records, cleanup selections, and a rolling diagnostic log retained for up to seven days and limited to approximately 5 MB.
  • Optional diagnostic reports: only after you tap “Agree and Upload,” the app sends its version and build, device model family and iOS version, locale, power and thermal state, backup destination type, recent redacted errors, Apple-provided crash or hang diagnostics when available, an optional comment, and a random app-install identifier used for rate limiting.

Diagnostic reports do not include your photos or videos, media contents, passwords, OAuth tokens, email address, or full file paths. Known sensitive values are redacted on the device and checked again by the receiving service.

3. How information is used

Information is used only to connect to your selected destination, copy media, resume interrupted work, verify backup results, show status, and perform cleanup actions that you approve.

4. Backup destinations

NAS/SMB: Media and credentials are used to communicate directly with the server you configure, normally over your local network.

Google Drive: HammyBackup requests the non-sensitive drive.file scope. This limits access to files the app creates or that you explicitly make available to it. HammyBackup does not request access to all files in your Drive.

Our handling of information obtained through Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

5. Storage and security

  • HammyBackup does not operate a developer-owned cloud service for your photo library.
  • Your media is sent only to the NAS/SMB server or Google Drive account you choose.
  • Non-secret settings, backup records, and short-lived diagnostics are stored on your device.
  • User-initiated diagnostic reports are encrypted in transit and stored in a private Cloudflare KV namespace that is not publicly readable.
  • SMB passwords are stored in the iOS Keychain.
  • Google authorization tokens are managed by Google Sign-In and protected using iOS security facilities.

6. Sharing, advertising, and analytics

We do not sell personal information or use data for advertising tracking. HammyBackup does not operate its own advertising or analytics SDK. When you choose Google Drive, the Google Sign-In SDK may collect account contact details (including name, email address, and phone number), account and device identifiers, approximate location derived from network information, usage information, and other data for sign-in functionality and the SDK provider’s analytics, as declared in its bundled privacy manifest. Google receives the information needed to provide sign-in and Drive access. Media goes only to the NAS/SMB service or Google Drive destination you choose; Cloudflare receives a diagnostic report only when you voluntarily submit one, except as otherwise required by law. See Google Sign-In’s App Store disclosure guidance and Google’s privacy policy for more information.

The public website uses no analytics, advertising trackers, cookies, forms, or server-side account system. It stores only your language preference in your browser. Its private API accepts only user-initiated in-app diagnostic reports.

7. Retention and deletion

Local settings and records remain on your device until you sign out, clear a destination, or remove the app, subject to normal iOS Keychain behavior. Local diagnostic logs are automatically limited to seven days and approximately 5 MB. Submitted diagnostic reports are retained for no more than 30 days and then deleted. Backup files remain on your selected destination until you delete them there. Signing out of Google does not automatically delete Drive files or revoke prior authorization; you can revoke access from your Google Account security settings.

8. Your choices

You control Photos permission, local-network permission, the destination used, whether cellular backup is allowed, which items are selected, and every cleanup action. Diagnostic reports are optional and are never uploaded until you explicitly agree in the report screen. You can stop using Google Drive or NAS/SMB at any time.

9. Children

HammyBackup is not directed to children under 13, and we do not knowingly collect personal information from children through a developer-operated service.

10. Changes and contact

We may update this policy when the app changes or legal requirements evolve. The effective date above will be updated. Questions can be sent to support@hammybackup.fingull.com.