ShotBox Privacy Policy

Last updated: 22 July 2026

In short: your photos and videos stay in your own Google Drive. ShotBox never uploads, copies or stores them on our servers. We keep a small amount of account information — your email address, your subscription status and a notification token — so that sign-in, subscriptions and notifications work. We do not sell your data or use it for advertising.

Who we are

ShotBox ("the app", "we", "us") is an Android photo album app that stores your albums in your own Google Drive. This policy explains what information the app handles and why.

Contact for privacy questions: redskyroad@gmail.com

Google user data we access

When you connect Google Drive, ShotBox requests the following OAuth scope:

https://www.googleapis.com/auth/drive

Google presents this as "See, edit, create and delete all of your Google Drive files." That wording is Google's, and it is accurate: Google grants this level of access on an all-or-nothing basis. We want to be direct about that rather than imply the access is narrower than it is.

What ShotBox actually does with that access

ShotBox does not read, modify, or delete any other file in your Drive.

Why a narrower permission is not used

Google offers a narrower alternative (drive.file) that limits an app to files it created. We tested whether ShotBox could work within it, and it cannot: that permission cannot discover folders that other people have shared with you, and selecting a shared folder through the Google Picker grants access to the folder itself but returns none of the photos inside it. Receiving shared albums is a core feature of ShotBox, so the broader permission is required for the app to function.

Information we store on our servers

ShotBox uses Google Firebase. The following is stored under your account identifier:

WhatWhy
Email address and Google account identifier (Firebase Authentication) To sign you in and link your subscription to your account
Subscription status and Google Play purchase token (Cloud Firestore) To verify your subscription with Google Play and unlock paid features
Notification token (Firebase Cloud Messaging) To notify your device silently when a subscription changes or lapses
App usage and device information (Firebase Analytics) To understand crashes and which features are used, in aggregate
Your photos are not in that list, and never will be. Photos and videos are transferred directly between your device and your own Google Drive. They do not pass through, and are not stored on, any server we control.

Information stored on your device

Uninstalling ShotBox removes all of this from your device.

What we never do

Limited Use disclosure

ShotBox's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Keeping and deleting your data

Revoking Drive access

You can withdraw ShotBox's access to your Google Drive at any time at myaccount.google.com under Data & privacy → Third-party apps & services. Your albums remain in your Drive; ShotBox simply stops being able to reach them.

Deleting your ShotBox account and data

To request deletion of your ShotBox account and its associated data, email redskyroad@gmail.com from the email address associated with your account, with the subject "Delete my ShotBox account". No other steps are required.

What is deleted: your email address and Google account identifier, your subscription record and Google Play purchase token, and your notification token. All of it is removed within 30 days of your request.

What is kept: records we are required to retain for tax or legal reasons, for the period the law requires.

What is not affected: the photo albums in your own Google Drive. Those belong to you, are stored in your Drive rather than by ShotBox, and are left untouched. You can delete them yourself in Google Drive at any time.

Children

ShotBox is not directed at children under 13, and we do not knowingly collect information from them.

Changes to this policy

If this policy changes materially — particularly regarding what data we access or why — we will update this page and revise the date at the top.