ShotBox Privacy Policy
Last updated: 10 August 2026
In short: your photos and videos stay in your own Google Drive. ShotBox never
uploads, copies or stores them on our servers. We keep a small amount of account information —
your email address, your subscription status and a notification token — so that sign-in,
subscriptions and notifications work. We do not sell your data or use it for advertising.
Who we are
ShotBox ("the app", "we", "us") is an Android photo album app that stores your albums in your
own Google Drive. This policy explains what information the app handles and why.
Contact for privacy questions: redskyroad@gmail.com
Google user data we access
When you connect Google Drive, ShotBox requests the following OAuth scope:
https://www.googleapis.com/auth/drive
Google presents this as "See, edit, create and delete all of your Google Drive files."
That wording is Google's, and it is accurate: Google grants this level of access on an
all-or-nothing basis. We want to be direct about that rather than imply the access is narrower
than it is.
What ShotBox actually does with that access
- Creates its own album folders in your Drive and works inside them
- Uploads photos and videos from albums you choose to back up
- Reads albums that other people have shared with you, so you can view and save them
- Shares your albums with people you choose, and revokes that sharing when you ask
- Stores two small settings files (
_config.json and _themes.json)
alongside your albums, holding preferences such as cover photos and theme choices
- Downloads photos you open or save, to your device
ShotBox does not read, modify, or delete any other file in your Drive.
Why a narrower permission is not used
Google offers a narrower alternative (drive.file) that limits an app to files it
created. We tested whether ShotBox could work within it, and it cannot: that permission cannot
discover folders that other people have shared with you, and selecting a shared folder through
the Google Picker grants access to the folder itself but returns none of the photos inside it.
Receiving shared albums is a core feature of ShotBox, so the broader permission is required for
the app to function.
Information we store on our servers
ShotBox uses Google Firebase. The following is stored under your account identifier:
| What | Why |
| Email address and Google account identifier (Firebase Authentication) |
To sign you in and link your subscription to your account |
| Subscription status and Google Play purchase token (Cloud Firestore) |
To verify your subscription with Google Play and unlock paid features |
| Notification token (Firebase Cloud Messaging) |
To notify your device silently when a subscription changes or lapses |
| App usage and device information (Firebase Analytics) |
To understand crashes and which features are used, in aggregate |
Your photos are not in that list, and never will be. Photos and videos are
transferred directly between your device and your own Google Drive. They do not pass through,
and are not stored on, any server we control.
Information stored on your device
- Cached copies of photos and thumbnails you have viewed, to avoid re-downloading them
- Your app settings and preferences
- Photos you explicitly choose to save, written to your device's normal Photos storage
Uninstalling ShotBox removes all of this from your device.
How we protect your data
We use security procedures to protect the confidentiality and integrity of the information
ShotBox handles, including your Google user data.
- Encryption in transit. All communication between the app, Google Drive and
our Firebase backend is encrypted using HTTPS/TLS. ShotBox makes no unencrypted network
requests.
- Encryption at rest. The account information we hold (see above) is stored in
Google Cloud Firestore and Firebase Authentication, which encrypt stored data at rest by
default using Google-managed encryption keys.
- Encryption on your device. Sensitive local state, including your
subscription entitlement, is stored using Android's
EncryptedSharedPreferences (AES-256), so it is encrypted in the app's private
storage rather than held in plain text.
- Authenticated access only. Server-side data can only be reached through
authenticated Cloud Functions that verify the signed-in user's identity and reject
unauthenticated requests. Each user's record is keyed to their own account identifier, so one
user's data cannot be requested by another.
- OAuth tokens. ShotBox uses Android's Google Sign-In and Credential Manager
to obtain access tokens. Tokens are held only in memory for the life of the session and are
never written to our servers or to persistent storage.
- Least access. The Firebase project holding this data is accessible only to
ShotBox's developer; no other person or company has access to it.
- Your photos are not exposed to us at all. Photos and videos move directly
between your device and your own Google Drive over TLS. Because they are never transmitted to
or stored on any server we operate, they cannot be accessed, read or disclosed by us.
No method of transmission or storage is completely secure, but these measures are intended to
protect your information against unauthorised access, disclosure, alteration and destruction.
How long we keep your data
- Your account information (email address and account identifier), subscription record and
notification token are retained for as long as your ShotBox account exists, because they are
needed to sign you in and to keep your subscription working.
- Analytics data is retained in aggregate, in line with Firebase Analytics' standard retention
period, and is not used to identify you individually.
- If you ask us to delete your data, we remove it within 30 days, other than records we are
required to keep for tax or legal reasons, which are held only for the period the law
requires.
- When a retention period expires for a given type of data, that data is deleted.
- Photos and videos in your Google Drive are not subject to our retention: they are yours, held
in your own Drive, and remain there until you delete them.
What we never do
- We do not sell your personal information
- We do not transfer your Google user data to third parties, except as needed to provide the
app's features or where required by law
- We do not use your Google user data for advertising
- We do not use humans to read your data, except with your explicit permission for support,
for security purposes, or where required by law
Limited Use disclosure
ShotBox's use and transfer of information received from Google APIs to any other app will adhere
to the
Google
API Services User Data Policy, including the Limited Use requirements.
Keeping and deleting your data
Revoking Drive access
You can withdraw ShotBox's access to your Google Drive at any time at
myaccount.google.com
under Data & privacy → Third-party apps & services. Your albums remain in your Drive;
ShotBox simply stops being able to reach them.
Deleting your ShotBox account and data
To request deletion of your ShotBox account and its associated data, email
redskyroad@gmail.com from the email address associated
with your account, with the subject "Delete my ShotBox account". No other steps are required.
What is deleted: your email address and Google account identifier, your
subscription record and Google Play purchase token, and your notification token. All of it is
removed within 30 days of your request.
What is kept: records we are required to retain for tax or legal reasons, for
the period the law requires.
What is not affected: the photo albums in your own Google Drive. Those belong
to you, are stored in your Drive rather than by ShotBox, and are left untouched. You can delete
them yourself in Google Drive at any time.
Children
ShotBox is not directed at children under 13, and we do not knowingly collect information from
them.
Changes to this policy
If this policy changes materially — particularly regarding what data we access or why — we will
update this page and revise the date at the top.