The short version
- The app has no server. Your files and your Google data travel only between your computer and Google. We never receive them, unless you choose to send us something yourself, such as a log when you ask for help.
- The app collects nothing about you: no analytics, no telemetry, no crash reports, and no account with us.
- This website has no tracking: no analytics, no advertising, no cookies of its own, and nothing loaded from other companies.
- The beta list keeps your email address (and your Linux distribution, if you choose one) only to email you about the beta and the public release. To limit abuse, the form also counts attempts per coded IP address for 48 hours. You can have your entry deleted at any time.
1. Who we are
Ambifold (“we”, “us”) is a product of iDevelop, a business registered in Israel (a sole proprietorship). We make the Ambifold desktop app and run this website, ambifold.com.
We are the controller of the personal data we receive: data from this website, the beta waiting list and the emails you send us. The desktop app processes your data only on your computer, under your control. We don't receive that data, so we are not its controller; section 2 explains what the app does with it.
Contact: support@ambifold.com. We read every message and answer privacy requests within one month.
2. The Ambifold desktop app
Ambifold is an app that you install and run on your own computer. It keeps folders that you choose in two-way sync with your Google Drive.
2.1 No server, no data collection
Ambifold has no server of its own. The app talks only to Google: your files, your Google sign-in and everything the app learns from Google go directly between your computer and Google's servers. The app sends nothing to us or to anyone else. It has no analytics, no telemetry, no advertising and no crash reporting, and you do not need an account with us to use it. If you ask us for help, you may choose to email us logs or screenshots yourself; section 6 explains how we handle them.
2.2 The Google user data the app accesses
When you connect a Google account, Ambifold asks Google for access to your Google Drive files. This is the https://www.googleapis.com/auth/drive permission, which Google's sign-in screen describes as “See, edit, create, and delete all of your Google Drive files”. Ambifold needs this full access because it syncs the folders you choose, including files that were created on the web, on your phone or by other apps. Google's narrower Drive permission only covers files that an app created itself or that you pick one by one, which is not enough to keep a whole folder in sync.
| What the app accesses | Why | Where it goes |
|---|---|---|
| Files and folders inside the Drive folders you choose to sync: their names, contents, sizes, modification times and folder structure | To compare both sides and copy, update or delete files so that each folder pair stays the same | Downloaded to, or uploaded from, the folder on your computer that you paired with it. The app also keeps a record of each file's name, size and modification time on both sides, in ~/.local/state/ambifold/, so that it can tell what changed |
| The names of the folders in your Drive, when you browse to pick one | To let you choose which Drive folder to sync | Shown on the settings page on your computer. Only the folder you pick is saved, as part of the folder pair, in the app's settings file |
| File and folder names in sync previews and logs | To show you what a sync will do or did, and to help you find problems | Kept on your computer, in ~/.local/state/ambifold/ |
| Your Google account's name and email address | To label the account in the app, and to notice when the same account is connected twice | Stored in the app's settings file on your computer |
| Google's sign-in tokens for your account | To keep syncing without asking you to sign in again | Stored in a file on your computer that only your user account can read |
2.3 How the app uses Google user data
Ambifold uses Google user data only to provide the features you see and use in the app: listing your Drive folders so you can pick one, previewing what a sync will do, and syncing files in both directions between the folders you paired. When a sync deletes a file in your Drive, the file is moved to Google Drive's trash, where you can restore it for 30 days. By default, Google Docs, Sheets and Slides are skipped and stay in Drive. If you change that setting, the app downloads converted copies of them (for example .docx files), and changes to such a copy can replace the original document in your Drive with a plain file.
Ambifold does not use Google user data for advertising, does not sell it, does not use it to assess creditworthiness, and does not use it to develop, improve or train artificial intelligence or machine learning models. Because the app sends Google user data only between your computer and Google, no person at Ambifold reads it, unless you choose to send some of it to us, for example in a log or screenshot when you ask for help (section 6).
2.4 How the app stores and protects it
- Everything stays on your computer. On Linux, the app's settings and sign-in tokens are in
~/.config/ambifold/, in files that only your user account can read. Logs, sync previews, the sync records and backups are in~/.local/state/ambifold/, in folders that only your user account can open. Synced files are in the folders you chose. - Encrypted in transit. All communication with Google uses HTTPS (TLS).
- A private settings page. The settings page is served by the app only on your own computer (
127.0.0.1). It opens with a single-use key handed over by the tray icon, and it refuses requests from websites and from other users of the same computer. - Your computer's own protection applies. Files on your disk are protected by your computer's security, such as your login and disk or home-folder encryption.
2.5 Sharing
The app does not share, transfer or disclose Google user data to anyone. It exchanges data only with Google, as needed to sync the folders you chose. We do not receive the data, so we cannot share it either.
2.6 Retention and deletion
- Synced files are your files. They stay in your folders until you delete them.
- Backups of files that a sync deleted or overwrote on your computer are kept for the period you set in the app (30 days by default) and then deleted automatically.
- Logs may contain file and folder names. They are kept to a fixed size, and the oldest entries are overwritten.
- Removing a folder pair in the app deletes its sync records and its log. Your files on both sides are not touched, and its backups are kept until their period ends.
- Removing an account in the app's settings deletes its sign-in tokens from your computer. You can also revoke the app's access at any time in your Google Account, under Third-party apps and services. In the free edition, it is listed there under the name you gave your own Google app.
- Uninstalling: delete the two folders named in section 2.4 and the autostart entry
~/.config/autostart/ambifold.desktopto remove everything the app stored, including tokens, logs and backups. In the free edition, you can also delete the Google Cloud project you created for it.
2.7 Free edition and the planned Connect plan
In the free edition, the app connects to Google through an OAuth client that you create in your own Google Cloud project, following the app's guide. That project belongs to you, and Google's terms apply between you and Google. We plan a paid “Connect” plan that would use Ambifold's own client, verified by Google, for a one-click sign-in. In both cases the data flows are the ones described above: directly between your computer and Google.
If we ever add a feature that sends any data from the app to us, such as a check for updates or for a Connect plan subscription, we will update this policy before that feature is released and say exactly what is sent.
3. Google API Services: Limited Use
Ambifold's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use of information received from Google Workspace APIs, including the Google Drive API, will adhere to the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.
In particular:
- Ambifold uses Google user data only to provide or improve the user-facing features described in section 2.
- Ambifold does not transfer Google user data to others, except as necessary to provide those features, to comply with applicable law, or as part of a merger, acquisition or sale of assets with your prior consent.
- Ambifold does not use or transfer Google user data for serving advertisements, including personalised or interest-based advertising, and does not sell it.
- No person at Ambifold reads Google user data unless you choose to send it to us, for example in a log or screenshot for support. We then use it only to help you, and delete it when your issue is resolved.
- Ambifold does not use Google Workspace API data, including Google Drive data, to develop, improve or train generalised or non-personalised artificial intelligence or machine learning models, and does not transfer or sell it for that purpose.
4. This website
This website sets no cookies of its own and uses no local storage. It has no analytics scripts, no tracking and no advertising, and it loads no resources from other companies (its fonts and images are served from ambifold.com itself).
The site is hosted by Cloudflare. As with any website, your browser sends technical information with each request, such as your IP address, the page requested, your browser's user agent and the time. Cloudflare processes this information on our behalf to deliver the pages and to protect the site against attacks and abuse, and keeps it only briefly, as described in its privacy policy. Cloudflare shows us only aggregate traffic statistics that don't identify anyone. We do not keep web server logs ourselves and do not use this information to identify visitors. If Cloudflare ever has to check whether a visitor is an automated bot, for example during an attack, it may set a strictly necessary security cookie (__cf_bm or cf_clearance); it is not used for tracking. Our legal basis is our legitimate interest in running a secure website (Article 6(1)(f) GDPR).
Because this website does no tracking, it treats every visitor the same whether or not the browser sends Do Not Track or Global Privacy Control signals. No third party collects information about your activity across websites through this site.
5. The beta waiting list
If you ask for an invite to the private beta, we store:
- your email address;
- your Linux distribution, if you choose one (or that you use Windows);
- the date and time of your request, and which version of the consent text you saw;
- whether and when you confirmed your request (see below).
You are not legally required to give us your email address. If you don't, we can't send you an invitation.
Confirmation: anyone can type an address into the form, so the first email we send you asks you to confirm that the request came from you. If you don't confirm within 14 days, we delete your address.
Abuse protection: to limit repeated submissions, the form counts attempts per hour for each coded IP address. The code is computed one way from your IP address with a secret key that is kept apart from the list, and it changes every day. We do not store your IP address itself, and these counters are not linked to your email address. Our clean-up deletes them after 48 hours. It runs whenever someone uses the form, and we also run it by hand at least once a week, so a counter can occasionally stay for up to a week.
Why: to email you an invitation to the beta, and to tell you when Ambifold is publicly released (or when the Windows version is ready, if you chose Windows). Your distribution helps us decide what to test. We send no newsletter and no other marketing, and we use no mailing-list services and no tracking pixels. We send these emails one at a time, or with every address hidden from the other recipients.
Legal basis: your consent (Article 6(1)(a) GDPR and UK GDPR), which you can withdraw at any time without affecting what happened before. For the attempt counters: our legitimate interest in keeping the form free of abuse (Article 6(1)(f)).
How long: until we have told you about the public release (or, if you chose Windows, that the Windows version is ready), and in any case no later than 31 December 2027; earlier if you unsubscribe, ask us to delete it, or don't confirm your request. Then we delete it.
Unsubscribe: reply “unsubscribe” to any email from us, or write to support@ambifold.com.
Where: the list is kept in a Cloudflare D1 database located in the European Union. Deleted entries can remain in Cloudflare's automatic database backups for up to 30 days before they are overwritten. To send the emails, we also keep working copies of the list on our own computer, and the messages we send you stay in our mailbox (section 7). When we delete your entry, we delete those copies too.
6. Emails, support and beta feedback
If you email us, for example with a question or to report a problem during the beta, we receive your email address, your message and anything you choose to attach. Logs, diagnostics and screenshots from the app can contain file and folder names from your computer and your Drive, the path of your home folder and your computer's user name. Please remove anything you don't want to share before you send it.
Why: to answer you and to fix problems in Ambifold.
Legal basis: taking the steps you ask us to take (Article 6(1)(b) GDPR), and otherwise our legitimate interest in supporting and improving Ambifold (Article 6(1)(f)).
How long: we delete logs, diagnostics and screenshots you sent once your issue is resolved, and conversations 12 months after the last message, or earlier if you ask.
7. Service providers
We use these companies to run the website, the waiting list and our email. We do not sell or rent personal data to anyone.
| Provider | What for | Data involved |
|---|---|---|
| Cloudflare, Inc. (United States) | Website hosting (Cloudflare Pages), the signup form's server code and database (Pages Functions, D1), DNS, and forwarding of email sent to ambifold.com addresses (Email Routing) | Technical data of website visitors; the waiting list; email you send us, while it is forwarded |
| Google LLC (United States) | The mailbox where email to support@ambifold.com arrives (Gmail). We also write our emails to you there, including the beta invitations and the release announcement, so copies of them are kept in it | Your email address, your messages to us and ours to you, and anything attached |
Cloudflare processes data on our behalf under its data processing addendum. Google provides our mailbox under its standard Gmail terms and its privacy policy, not under a data processing agreement with us. Before we send you any email, we will add the service that delivers our outgoing mail from support@ambifold.com to this table. The Ambifold app itself uses none of these services: it talks only to Google Drive, as described in section 2.
8. International transfers
We are based in Israel, which the European Commission and the United Kingdom recognise as providing an adequate level of data protection. The waiting list itself is stored in the European Union. Cloudflare and Google are based in the United States and operate worldwide. Cloudflare takes part in the EU–U.S. Data Privacy Framework and its UK extension, and its data processing addendum includes the European Commission's standard contractual clauses. Google LLC also takes part in the Data Privacy Framework. Email us for a copy of these safeguards.
9. Your rights
Depending on where you live, and in any case if the GDPR or UK GDPR applies to you, you have the right to:
- access the personal data we hold about you and get a copy of it;
- have it corrected, or deleted;
- restrict how we use it, or object to our use of it based on legitimate interests;
- receive it in a portable format;
- withdraw your consent at any time;
- complain to a data protection authority, such as the authority in your EU country, the Information Commissioner's Office in the UK, or the Privacy Protection Authority in Israel.
To use any of these rights, email support@ambifold.com, ideally from the address concerned. It is free, and we answer within one month. We may ask you to confirm that the address is yours.
To complain to us about how we handle your data, email support@ambifold.com with the subject “Privacy complaint”. We acknowledge it within 30 days, look into it without undue delay, and tell you the outcome. You can also complain to a data protection authority at any time.
We do not sell or share personal information as those terms are defined in California privacy law, we do not use it for targeted advertising, and we make no automated decisions about you.
10. How to delete your data
- Beta waiting list: reply “unsubscribe” to any email from us, or write to support@ambifold.com with the subject “Delete my data”. We delete your entry, our working copies of it and the emails we sent you, within 30 days and usually much sooner, and confirm by email.
- Emails you sent us: ask us, and we delete the conversation and anything you attached from our mailbox.
- The desktop app: we hold none of its data. Remove the account in the app, revoke access in your Google Account, and delete the app's folders (section 2.6).
11. Children
Ambifold and this website are not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has joined the waiting list, contact us and we will delete the entry.
12. Changes to this policy
When we change this policy, we update this page and the date at the top. If a change affects how we use your email address, we will tell you by email before it takes effect, and where the change needs your consent (for example, a new kind of email), we will ask for it and not assume it. If a change affects how the app handles Google user data, we will update this policy before the change is released.
13. Contact
iDevelop (trading as Ambifold), a business registered in Israel
Email: support@ambifold.com