Overview
This policy covers Duplicate Killer, a product published by Killer Apps. Killer Apps is a publisher brand operated by Contempo Curations (Pty) Ltd, South Africa. It explains how Duplicate Killer accesses your Google account and Google Drive data, what it stores, and what it explicitly does not store. It is written to reflect exactly how the application is built, not generic boilerplate.
Google account data
Duplicate Killer uses Google OAuth for sign-in and for Google Drive access. When you sign in, Google shares your basic account identifiers (such as your Google account subject identifier and email address) so we can recognize your account across sessions.
Exact-duplicate scanning reads Google Drive metadata, including:
- File and folder metadata needed to traverse a folder tree and display results (such as name, size, and type).
- The Google-provided
md5Checksum, where Google exposes one, used to group exact binary duplicates.
Duplicate Killer does not download your file contents to perform exact-duplicate matching - matching is based entirely on Google-provided metadata and checksums.
Google-native Docs, Sheets, and Slides do not have an md5Checksum, so they are excluded from exact-binary duplicate grouping today. Support for additional Workspace file types may be added in the future.
Cleanup access
Clean discovers exact duplicate files using Google Drive metadata and checksums - no separate Google Picker step is required. When you choose which duplicate files to send to Trash, you confirm that choice once in Duplicate Killer, and the server moves the selected files to Google Drive Trash using the same Google Drive access granted at sign-in.
Duplicate Killer never permanently deletes a file and never empties Trash on your behalf.
Organise access
Organise recommends existing Drive folders for loose files based on filenames and folder paths - not file contents. After you review the recommendations and choose which files to move, some selected files may require an additional Google confirmation: if Google has not yet authorized a specific file for Duplicate Killer, Google will ask you to confirm access to that one file before it can be moved. This uses Google's narrow drive.file scope, which only grants access to the exact file you confirm - not to your Drive as a whole.
Once confirmed, the actual move is performed only after the server re-verifies your selection, using the same Google Drive access granted at sign-in - not the browser-side confirmation credential described below.
Google tokens
Your primary Google OAuth access and refresh credentials are handled entirely server-side. They are never included in the browser-visible session data your device holds.
The Google file-access confirmation described above (used only by Organise, when a selected file has not yet been authorized) uses a separate, narrowly-scoped browser credential obtained only for that confirmation. It is used only to confirm access to the specific file you selected, is not persisted by Duplicate Killer, and plays no part in Clean's Trash operation. The actual Organise move is carried out server-side using your primary credential, not this browser credential.
Commercial / account data
Duplicate Killer may persist a small amount of account and billing state so the service can function, specifically:
- An internal application user identifier and your authenticated Google account subject.
- Billing/customer and subscription identifiers, subscription status, and relevant subscription dates.
- Webhook processing identifiers, used only to safely and idempotently process billing events.
Duplicate Killer does not persist any of the following:
- Google Drive file names
- Google Drive file IDs
- Google Drive folder IDs
- MD5 checksums
- Drive scan results
- Google file contents
- Google Picker OAuth tokens
We do not claim to store no data at all - the commercial/account state above is real and described accurately here.
Billing
Duplicate Killer currently offers free access. Paid plans are being prepared but are not yet activated; none are being sold today, and Duplicate Killer does not directly handle or store your payment card details. This section will name our payment processor before any paid plan is activated.
Sharing
We do not sell Google user data. We share data only with service providers who help us operate Duplicate Killer (such as hosting and, where applicable, payment processing), and only to the extent required for them to provide that service to us.
Limited Use disclosure
Duplicate Killer's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Retention & deletion
Account and commercial state described above may persist for as long as needed to operate the service for you. You may request deletion of your Duplicate Killer account/commercial data at any time - see Data Deletion & Account Removal for how. Where applicable law requires limited retention of certain billing or security records, we retain only what is legally required, for no longer than necessary.
Security
We apply reasonable technical and organizational safeguards to protect your data, including encrypted transport, credentials handled server-side rather than in the browser, and narrowly-scoped access requests. No service can guarantee absolute security, and we make no absolute or unqualified claim about the strength of these safeguards beyond what is stated here.
Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected by updating the date at the top of this page.
Contact
Questions about this policy or your data can be sent to stephenjoehley@gmail.com.