Inkfold Privacy Policy

Effective date: 24/09/26

This Privacy Policy describes how Inkfold (“the app”) handles data, including data accessed through your Google Account. Inkfold is described at the Inkfold homepage.

Data Inkfold stores on your device

Your notes (handwriting and text pages) are stored locally in the app’s private storage on your device. This data never leaves your device unless you choose to enable Google Drive sync.

Google user data

Inkfold integrates with one Google API: the Google Drive API, using exactly one OAuth scope:

Scope What it grants
.../auth/drive.file Access only to files and folders that Inkfold itself creates in your Drive. Inkfold cannot see, read, or modify any other file in your Google Drive.

This scope is only requested if you explicitly choose “Sign in to Google Drive” from within the app. The app remains fully functional if you never sign in.

What is accessed: the contents of a single Drive folder named “Inkfold”, which Inkfold creates and manages. Inside it, one sub-folder per document, each containing the document’s page files (SVG/Markdown) and a small JSON manifest.

Why it’s accessed: to upload your documents so they’re backed up, and to download them again on another device signed in to the same account. This is a two-way sync of your own notes — nothing more.

What is not accessed: your Google account profile beyond the account email needed to identify which account is signed in; any other file, photo, or document in your Drive; any other Google service (Gmail, Calendar, Contacts, etc — Inkfold does not request access to any of these).

How Google user data is stored and retained

  • A copy of your synced documents is cached locally on each device you use Inkfold on, for offline access.
  • Inkfold’s own servers: there are none. Inkfold has no backend — sync is a direct, on-device connection to the Google Drive API. No Google user data is transmitted to, or stored on, any server operated by the app’s developer or any other party.
  • Data in your Drive is retained there until you delete it yourself (from Inkfold, or directly in Google Drive) or revoke Inkfold’s access.

Sharing and disclosure

Inkfold does not sell, rent, or share Google user data with any third party, for any purpose, including advertising. Inkfold contains no advertising or analytics SDKs and performs no tracking.

Limited Use disclosure

Inkfold’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Your controls

  • Sign out from within Inkfold’s menu at any time; this stops future sync but does not delete files already in your Drive.
  • Revoke access entirely at any time from your Google Account permissions, independent of the app.
  • Delete synced data by deleting the “Inkfold” folder in your Google Drive, or deleting individual documents from within the app (which removes them from Drive on the next sync).

Security

Communication with the Google Drive API uses OAuth 2.0 and HTTPS throughout. Inkfold requests the narrowest available Drive scope (drive.file) specifically so it is never granted broader access than it needs.

Children’s privacy

Inkfold is not directed at children and does not knowingly collect data from children.

Changes to this policy

If this policy changes, the effective date above will be updated and the new version published at this same URL.

Contact

Questions about this policy or Inkfold’s data practices: https://github.com/Pingue/inkfold/issues