1. Operator and scope
Urban Luo operates TourBox Voice Upload for a personal news research workflow. This policy covers the local uploader and this information website. Contact: urban.luo0216@gmail.com.
2. Data accessed and processed
- Locally generated CSV content: news dates, public links, domains, platforms and research categories. Source links may identify public authors or accounts.
- Google Drive metadata for the configured file: file ID, name, type, size, modification time, checksum, trash status and editing capability.
- OAuth credentials, including a refresh token and temporary access tokens, used to authorize transfers. The application does not receive the Google account password.
- Local operational records: transfer times, row counts, latest data date, checksums and error status.
The requested Drive scope allows broader access than the current implementation uses. The uploader does not list the entire Drive or read unrelated files; it updates the configured CSV and checks its metadata.
3. Purposes and limits
Data is used to update the designated research file, verify delivery, retry interrupted transfers and diagnose operation. The uploader does not sell data, serve advertising, build advertising profiles or use Google user data to train generalized AI or machine-learning models.
TourBox Voice Upload's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
The operator may separately authorize an analysis service to read the research CSV. That is a separate integration governed by its own permissions and policies; this uploader sends the CSV to Google Drive and does not itself send it to an AI service.
4. Storage, security and retention
OAuth credentials and upload state are stored in the operator's local macOS user account with restrictive file permissions. Google API requests use HTTPS. The pending CSV is kept locally until upload is verified, then removed; a newer validated full report may replace it. The original research files remain in the operator's existing local/NAS workflow.
The refresh token remains until removed or replaced. Local logs and the latest upload status remain until the operator deletes them; this version has no automatic log expiry. The uploaded file and any Drive versions remain in Google Drive under the account owner's control. File permissions are a protection measure, not a claim of application-level encryption at rest.
5. Sharing and website hosting
Google processes the uploaded file and authorization requests to provide Drive and OAuth services. Existing Drive sharing permissions determine who can access the uploaded file; the uploader does not make it public or change those permissions.
This website is intended for hosting on Cloudflare Pages. The hosting provider may process connection information such as IP address, requested URL and browser information to deliver and secure the website, under Cloudflare's privacy policy. The supplied website includes no analytics scripts, advertising, forms or application-set cookies. Visiting it does not provide access to Drive data or credentials.
The uploader does not otherwise transfer Google user data to third parties, except as required by law or necessary to address security incidents consistent with applicable policies. Operator access is limited to operating and troubleshooting this personal workflow.
6. Revocation and deletion
You can revoke the application's access in Google Account connections. To stop the local workflow completely, disable its scheduled tasks and remove its saved credentials. Revocation stops future authorized API access but does not delete already uploaded files.
The account owner can delete the CSV and manage its trash and versions in Google Drive. Local source data, pending copies, tokens and logs must be deleted separately, including any backups or NAS copies the operator maintains. For questions or deletion assistance, contact the email above; do not send passwords or OAuth tokens.
7. Changes
Changes will be published here with an updated effective date. If Google user data will be used for a new purpose, the operator must provide an updated disclosure and obtain any required consent before that use.
中文摘要:本工具在本地运行,将指定 CSV 上传至自己的 Google Drive,并读取文件元数据进行校验。凭据保存在本机;待上传副本校验成功后移除。原文件、日志、Drive 文件与备份需分别管理或删除。网站不接收 CSV 或授权凭据。可在 Google 账号中撤销授权。本页英文正文提供完整说明。