Privacy Policy — Bitácora
Last updated: 2026-08-08
Bitácora uses Google sign-in, Supabase and your own Google Drive to manage academic tasks, meetings and study files. Your files stay in your Drive — they are never copied to our servers. This policy explains what data it collects, why it asks for Google Drive access, and how you can control it.
What data does Bitácora collect?
Account information from Google Sign-In (name, email and profile photo); your academic data (tasks with their due dates, subjects, professors, meetings and majors); and the metadata of your study files — name, size, type, major, subject, Drive identifier and link.
The contents of your files are never read, uploaded to our servers or analyzed. Only the metadata listed above is stored, so the app can show you an organized list.
Why does Bitácora ask for full Google Drive access?
Bitácora stores your study files in your own Google Drive, inside a folder named Bitácora, organized by major and subject. To do this it requests the https://www.googleapis.com/auth/drive scope.
Google does not offer a scope limited to a single folder. The narrowest available scope, drive.file, only grants access to files the app itself created — with it, Bitácora cannot detect the files you add to the folder directly from your computer, nor reliably notice when you delete one. That automatic detection is a core feature of the app, which is why the broader scope is requested.
What Bitácora does — and does not do — with that access
Bitácora limits its own access by code to the Bitácora folder and its subfolders. Before reading, modifying or deleting any file, the app checks that it belongs to that folder tree; if it cannot confirm this, it does not act. Within that boundary it creates the folders, uploads the files you choose to upload, queries the Google Drive Changes API to detect files added, renamed, moved or deleted, and deletes a file from Drive only when you delete it from the app.
Bitácora does not read the contents of your files, does not access files outside the Bitácora folder even though the granted permission would technically allow it, does not copy your files to our servers or anyone else's, and does not use your Drive data for advertising, profiling, AI model training, or sell it to anyone.
Bitácora's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Where is your data stored?
Your tasks, subjects, meetings and file metadata are stored in Supabase (PostgreSQL). The contents of your files are stored only in your own Google Drive.
Everything travels over HTTPS/TLS. Row-level security policies enforce on the server that each user can only read and write their own records. The local device cache is stored encrypted, and the Google Drive access token is kept in the system's secure store (Keystore on Android, Keychain on iOS) — on the web version it lives in memory only and is discarded when the tab closes.
Sharing
Your personal information is never sold. It is shared only with Supabase as the database and authentication provider, and with Google for sign-in and for storing your files in your own Drive. Tasks and meetings you explicitly publish as shared become visible to other members of your major; your personal files are never shared this way.
Your rights and how to revoke access
You can access, correct and export your data, and delete your account at any time. You can revoke Bitácora's access to your Drive whenever you want from your Google account settings (myaccount.google.com/permissions) — the app then stops accessing your Drive and your files stay there, untouched.
If you delete your account, your data is permanently removed from our servers within 30 days. File metadata is kept only while the file exists in your Drive folder: delete the file from Drive and its metadata is removed on the next sync. The files themselves live in your Google Drive and are not affected by deleting your Bitácora account or revoking the permission.
Changes to this policy
If this policy changes, the "last updated" date above will change too, and significant changes are announced inside the app.
Contact
For questions about this policy or to exercise data deletion rights, contact cristian.bravo.droguett@gmail.com.