Privacy at a glance
Simple WP Backup is designed to perform backup and restore work from your own WordPress installation. We do not sell Google user data, use it for advertising, or use backup contents for unrelated purposes. Google Drive access is limited to files the plugin creates or that a user explicitly makes available to it.
1. Scope and responsible party
This Privacy Policy applies to the Simple WP Backup website, WordPress plugin, support communications, and any Simple WP Backup service used to connect the plugin to Google Drive. “Simple WP Backup,” “we,” “us,” and “our” refer to the Simple WP Backup project and team.
Your WordPress website operator remains responsible for the personal data contained in that website and its backups. Simple WP Backup provides software tools used under the website operator’s direction.
2. Information we handle
Website and support information
- Information you voluntarily provide in a support request, such as your name, email address, message, and diagnostic files.
- Ordinary technical request information, such as IP address, browser type, requested page, time, and security logs, which may be processed by our website hosting provider.
Information handled by the plugin
- Backup settings, schedules, job state, backup metadata, integrity results, and redacted diagnostic logs.
- Website files and database content selected by the administrator for backup or restore.
- Local and remote backup identifiers, filenames, sizes, checksums, warnings, and retention settings.
- Google authorization credentials when an administrator chooses Google Drive storage.
3. Google Drive and Google user data
When you choose to connect Google Drive, Simple WP Backup requests the narrow https://www.googleapis.com/auth/drive.file permission. This allows the plugin to create and manage backup files it creates, or files you explicitly make available to it. It does not provide general access to all files in your Google Drive.
| Google data | Purpose | Normal storage |
|---|---|---|
| OAuth access and refresh tokens | Authenticate Drive requests and maintain the connection you authorized. | Encrypted in your own WordPress database. |
| Drive file and folder identifiers | Upload, verify, list, download, restore, or delete plugin-managed backups. | Your WordPress database and backup records. |
| Backup filename, size, checksum, and status | Show history, verify integrity, and manage retention. | Your WordPress site and Google Drive file metadata. |
| Connected account identifier, if displayed | Help administrators identify the connected Google account. | Your WordPress settings. |
| Backup archive contents | Store and retrieve the backup you requested. | Your Google Drive; temporary local copies may exist during processing. |
One-click connection service
Where the Simple WP Backup hosted connection service is used, it processes the Google authorization response only to establish the connection requested by the administrator. Connection requests are short-lived and single-use. Long-term authorization credentials are delivered to and stored by the originating WordPress installation; temporary connection records are deleted after successful retrieval or expiry.
Google API Limited Use disclosure
Simple WP Backup’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. How information is used
We and the plugin use information only as needed to:
- Create, schedule, store, verify, transfer, download, restore, and delete backups you direct the plugin to manage.
- Authenticate with Google Drive, refresh authorization, and report connection health.
- Maintain backup history, retention protection, recovery state, and post-restore verification.
- Respond to support requests, diagnose failures, secure the service, and prevent abuse.
- Comply with legal obligations and enforce applicable terms.
Google user data is not used for advertising, profiling, credit decisions, sale, or any purpose unrelated to backup storage and recovery functionality.
5. Storage, transmission, and security
By default, the plugin operates from your WordPress installation. Backup files may be stored on your server and, when selected, in your Google Drive. Google tokens are encrypted before being saved in the WordPress database using server-supported authenticated encryption and keys derived from the installation’s WordPress security salts.
Backup uploads and Google API requests use encrypted HTTPS connections. We use reasonable technical and organizational safeguards, but no internet transmission, hosting environment, or storage system can be guaranteed completely secure. Website administrators remain responsible for securing WordPress, hosting accounts, Google accounts, and backup access.
6. When information may be shared
We do not sell or rent personal information or Google user data. Information may be processed by:
- Google, when you authorize Google Drive and direct the plugin to use its services.
- Your WordPress hosting provider, server administrator, and other infrastructure providers you select.
- Our website hosting, email, security, and support providers, only as necessary to provide those services.
- Authorities or other parties when required by law, necessary to protect rights and safety, or involved in a legitimate organizational transition subject to appropriate safeguards.
We do not allow third parties to use Google user data for independent advertising or unrelated purposes.
7. Retention and deletion
- Local plugin data: retained on your WordPress installation until you delete backups, disconnect storage, clear logs, use plugin data-removal controls, or remove it through WordPress or your hosting provider.
- Google authorization: retained until you disconnect Google Drive, remove plugin data, revoke access through your Google Account, or the authorization expires or is revoked.
- Google Drive backups: retained according to your plugin retention settings or until you delete them. Disconnecting Google Drive does not automatically delete backup files already stored in Drive.
- Connection service records: temporary, single-use authorization records are removed after retrieval or automatic expiry.
- Support records: retained only as long as reasonably needed to resolve the request, maintain security, and meet legal obligations.
You can revoke Google access from your Google Account connections. You may also delete plugin-created backup files directly in Google Drive.
8. Your choices and rights
You can choose local-only storage and never connect Google Drive. WordPress administrators can inspect backup history, delete backups, disconnect Google Drive, remove stored authorization credentials, change retention, and configure whether plugin data is removed on uninstall.
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or portability for personal information controlled by us. Contact us to make a request. For data contained in a backup, contact the operator of the WordPress site that created it.
9. Children’s privacy
Simple WP Backup is a website administration tool and is not directed to children. We do not knowingly collect personal information from children through the website or hosted connection service.
10. Policy changes
We may update this policy when functionality, data practices, or legal requirements change. The updated policy will be posted here with a revised date. If a material change affects how authorized Google user data is used, we will provide appropriate notice and obtain consent when required before using that data for a new purpose.
11. Contact
For privacy questions, Google Drive data questions, or deletion requests, contact support@simplewpbackup.com.
