Last updated: 22 July 2026
ShotBox ("the app", "we", "us") is an Android photo album app that stores your albums in your own Google Drive. This policy explains what information the app handles and why.
Contact for privacy questions: redskyroad@gmail.com
When you connect Google Drive, ShotBox requests the following OAuth scope:
https://www.googleapis.com/auth/drive
Google presents this as "See, edit, create and delete all of your Google Drive files." That wording is Google's, and it is accurate: Google grants this level of access on an all-or-nothing basis. We want to be direct about that rather than imply the access is narrower than it is.
_config.json and _themes.json)
alongside your albums, holding preferences such as cover photos and theme choicesShotBox does not read, modify, or delete any other file in your Drive.
Google offers a narrower alternative (drive.file) that limits an app to files it
created. We tested whether ShotBox could work within it, and it cannot: that permission cannot
discover folders that other people have shared with you, and selecting a shared folder through
the Google Picker grants access to the folder itself but returns none of the photos inside it.
Receiving shared albums is a core feature of ShotBox, so the broader permission is required for
the app to function.
ShotBox uses Google Firebase. The following is stored under your account identifier:
| What | Why |
|---|---|
| Email address and Google account identifier (Firebase Authentication) | To sign you in and link your subscription to your account |
| Subscription status and Google Play purchase token (Cloud Firestore) | To verify your subscription with Google Play and unlock paid features |
| Notification token (Firebase Cloud Messaging) | To notify your device silently when a subscription changes or lapses |
| App usage and device information (Firebase Analytics) | To understand crashes and which features are used, in aggregate |
Uninstalling ShotBox removes all of this from your device.
ShotBox's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can withdraw ShotBox's access to your Google Drive at any time at myaccount.google.com under Data & privacy → Third-party apps & services. Your albums remain in your Drive; ShotBox simply stops being able to reach them.
To request deletion of your ShotBox account and its associated data, email redskyroad@gmail.com from the email address associated with your account, with the subject "Delete my ShotBox account". No other steps are required.
What is deleted: your email address and Google account identifier, your subscription record and Google Play purchase token, and your notification token. All of it is removed within 30 days of your request.
What is kept: records we are required to retain for tax or legal reasons, for the period the law requires.
What is not affected: the photo albums in your own Google Drive. Those belong to you, are stored in your Drive rather than by ShotBox, and are left untouched. You can delete them yourself in Google Drive at any time.
ShotBox is not directed at children under 13, and we do not knowingly collect information from them.
If this policy changes materially — particularly regarding what data we access or why — we will update this page and revise the date at the top.