Privacy Policy

Last updated: October 4, 2026

TG2CloudDrive is a self-hosted Telegram-to-cloud-storage tool maintained by NichoSpace. This policy explains how the software handles Telegram and Google Drive data on the server where you deploy it, and what this public website processes.

1. Deployment and responsibility

Each user deploys their own bot and configures their own storage connection through rclone. We do not operate a shared bot service or receive your Google authorization. Your files, Google access and refresh tokens, and transfer records are processed on your deployment, under your control. This website does not accept files, Google OAuth tokens or Google Drive account connections.

If you use a bot operated by someone else, that deployment operator controls its configuration and server data. Ask that operator about their retention settings and access practices before sending files or granting authorization.

2. Telegram data and files

  • Messages and account identifiers: the bot processes the user ID, username when supplied, chat ID and message ID accompanying submitted media, to check access rules, organize destinations and send transfer status messages.
  • Submitted files: documents, photos, videos, audio and voice messages are downloaded into a local cache before being uploaded to your configured cloud destination. File contents are processed for transfer and, when enabled, checksum verification and duplicate detection.
  • File and task metadata: filenames, media types, destination and local paths, timestamps, transfer status, attempts, errors, chat and message identifiers, and optional deduplication hashes are recorded in the deployment's SQLite database for retries, progress reporting and cleanup.
  • Optional Telegram user client: deployments that enable this feature retain a Telegram authorization session on their own server to download supported media through that account. The project maintainers do not receive this session.

3. Google user data: access and use

When you authorize Google Drive through rclone, Google issues access and refresh tokens for the configured OAuth application. rclone stores these credentials in its configuration on your server and uses them to authenticate Drive API requests and refresh access. TG2CloudDrive does not ask for your Google password.

For requested transfers, rclone creates or locates destination folders, uploads file contents, reads relevant file and folder metadata such as names, IDs, paths, sizes and checksums, checks for existing destination files, and verifies uploads. Existing files at the configured destination may be overwritten according to your conflict settings. These operations support the transfer features you configure; Google data is not used for advertising, profiling or training AI models.

This OAuth project's declared permissions include https://www.googleapis.com/auth/drive, https://www.googleapis.com/auth/docs (Drive file access), and https://www.googleapis.com/auth/drive.metadata.readonly (Drive file metadata access). Listing a scope in the project does not mean every connection requests it; review the permissions shown by Google for your connection.

The rclone Drive connection configured for this project uses the https://www.googleapis.com/auth/drive scope. Google grants this scope the ability to view and manage all files in the authorized Drive; it is not limited to files created by the bot. TG2CloudDrive uses the connection for the configured transfers, destination checks and verification. Review the Google consent screen before granting access. Your own deployment may use a different scope, which determines the data and actions its token permits.

TG2CloudDrive does not call the Google Docs API to read or edit document text. Files received from Telegram are treated as transfer payloads. Drive file metadata is read through rclone for storage operations, rather than collected by this public website.

4. Storage and protection

Cached files, task records, operational logs and rclone credentials stay on the server where you run the bot. Uploaded files are stored in the cloud account you configure. The website and project maintainers do not receive copies of those files or tokens. rclone communicates with Google Drive over HTTPS. Protect your server, restrict access to the rclone configuration and database, and secure any backups; this software does not provide automatic encryption of those local records at rest.

5. Sharing and third-party services

Transfers exchange the submitted media with Telegram and the storage provider you select, such as Google Drive. Your hosting provider may process connection data or have access according to your hosting arrangement. TG2CloudDrive does not sell user data, provide it to advertising networks or send Google credentials to the project maintainers. Third-party providers handle data under their own policies.

Google user data is not made available for human reading through the website. Access on your own deployment is controlled by you and anyone to whom you grant server access. Share only the minimum diagnostic information needed for support, and remove tokens and personal file information before submitting a public issue.

6. Retention and cleanup

  • Successful transfers remove the local cached file after upload and verification. Failed, cancelled or abandoned cached files are eligible for cleanup after the configured retention period, which defaults to 24 hours.
  • Completed, failed and cancelled task records are eligible for deletion after a separate retention period, also 24 hours by default. Pending tasks remain until processed or cancelled. Automatic cleanup runs periodically while the bot is running (hourly by default), or when you run the cleanup command; a stopped bot does not perform scheduled deletion.
  • Credentials remain in the rclone configuration until you remove them. Operational logs may contain timestamps, task IDs, paths and error details; their retention is controlled by your server or container logging configuration. Local Telegram Bot API data, optional Telegram sessions and backups are managed separately on your server.
  • Uploaded files stay in your Google Drive until you delete them. Removing local records or revoking authorization does not delete files already uploaded to Drive.

7. Revoking access and deleting data

You can revoke Google access at Google Account third-party connections. Revocation prevents future authorized access but does not erase the local rclone configuration. To remove local data, stop the bot, remove its rclone credentials and any cached files, task database, logs, Telegram sessions and backups you no longer need. Delete uploaded files separately in your cloud drive. For a deployment operated by someone else, request deletion from that operator.

8. Google API Services User Data Policy

TG2CloudDrive's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google data is used only to provide the user-facing storage transfer features described here.

9. Public website

This website is hosted on Cloudflare and can be viewed without an account. Cloudflare may process IP addresses, request URLs, browser information and connection or security logs to deliver and protect the site. We do not add advertising trackers or analytics trackers. If you contact us, we receive the contact details and message you choose to provide and use them to respond to your request.

10. Updates and contact

Changes to this policy will be published on this page with an updated date. For privacy questions about the project or website, contact NichoSpace at tg2clouddrive@nichospace.me. For files or credentials on a self-hosted deployment, contact its operator; we do not hold those records or have access to delete them.