Effective date: 20 September 2026
1. About isap
isap is managed by the isap team for authorized internal users. This policy covers the isap website, support communications, and personal information handled in isap’s rclone-based Google Drive workflows. For privacy enquiries, contact hello@isap.vn.
2. Information accessed
Google Drive connections use OAuth. You authorize access on Google’s consent screen; isap does not ask you to provide your Google password.
Depending on the permissions granted and the operation selected, rclone may access file and folder names, identifiers, paths, sizes, modification times and file contents. Access and refresh tokens are used to authorize requests to Google.
Permissions displayed during authorization determine the access granted. Broad Drive permissions can allow reading, creating, updating and deleting files beyond those created by the app. Users and administrators must review permissions and use the minimum access needed for their workflow.
Support requests include the email address and information you choose to send. Do not send passwords, tokens, client secrets or unnecessary private file contents.
3. How information is used
Google user data is used to perform user-directed file operations, identify changes, report transfer results and troubleshoot requested workflows. Support information is used to respond to enquiries and handle access, security and deletion requests.
Google user data must not be sold, used for advertising, or used to develop, improve or train generalized AI or machine-learning models. Human access is limited to circumstances permitted by Google’s policy, including explicit consent for support, necessary security investigations or legal obligations.
4. Storage and security
Rclone configuration and OAuth credentials are held in the environment where the client is configured, which may be a workstation or an internal server. Transferred files are stored in the source and destination chosen for the operation.
Administrators must restrict access to configuration files, credentials, logs and backups to authorized personnel, protect credentials from disclosure, and use appropriate security controls for the managed environment. Tokens and private file contents must not be included in ordinary diagnostic logs or support messages.
This website does not accept or store Drive tokens or transferred files. It provides information and links to setup instructions; Google authorization and file transfers take place in the configured rclone environment.
5. Sharing and disclosure
File operations exchange information with Google Drive and the authorized destination selected by the user. Administrators must not configure transfers to unauthorized destinations. Support correspondence is processed through the support mailbox and its email service.
Information may be disclosed when necessary to fulfill a legal obligation or address a security incident, subject to applicable law and Google’s permitted uses. Access by service providers must be limited to the work needed to provide the relevant service and subject to appropriate confidentiality and security controls.
6. Retention
Credentials are retained in the configured environment until removed or replaced. Revoking Google access and deleting locally stored credentials are separate steps. Copied files remain in their chosen destinations until deleted by the user or administrator under applicable organizational retention rules.
Operational logs and support records must be retained only as long as needed for troubleshooting, security, request resolution or legal obligations. Administrators must review and remove records that are no longer needed. Backup retention and any legally required exceptions must be considered when handling deletion requests.
7. Your choices and deletion requests
You may decline permissions, stop using the workflow, or revoke access through your Google Account. Revocation stops future use of that authorization but does not remove files already copied.
Contact hello@isap.vn to request access to, correction of, or deletion of information handled by isap. Include enough information to identify your request without sending credentials. Identity verification may be required. We will explain any legal retention requirements or limitations that affect the request.
See data and account access for disconnection and removal instructions.
8. Website information
This website does not include advertising trackers, an analytics SDK, or a Google sign-in form. Workflow selections are held in browser memory and reset when the page reloads. Email links open your email application.
The environment hosting the website may process technical request information, such as IP addresses and user-agent details, for delivery, diagnostics and security. These records are subject to the retention and access requirements in this policy.
9. Google API Services
isap’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
10. Changes and contact
We will update the effective date when this policy changes and communicate material changes to affected internal users. For questions about data handling or your rights, contact hello@isap.vn.