Privacy.
Last updated October 7, 2026
AlbumFlow copies photos from your iCloud account to your Google Drive. Doing that means holding credentials for both accounts, so this page is specific about what we keep, where it lives, and when it is deleted.
01The short version
- We mirror the iCloud Photos albums you choose into your own Google Drive. Your photos pass through our servers only while a file is being copied and are deleted the moment its upload completes.
- We store your email address, your Apple ID and iCloud password, and a Google Drive token, so that syncs can run without you. Credentials and tokens are encrypted at rest.
- We never sell data, never use your photos for anything other than copying them to your Drive, and never use Google user data to train machine-learning or AI models.
- You can disconnect iCloud or Google, or delete your account, at any time from the dashboard.
02Who we are
AlbumFlow is operated by Abood Tech (“we”, “us”). This policy explains what information we collect when you use getalbumflow.com and the AlbumFlow service, why we collect it, and the choices you have.
AlbumFlow is not affiliated with, endorsed by, or sponsored by Apple Inc. or Google LLC. iCloud is a trademark of Apple Inc. Google Drive is a trademark of Google LLC.
03What we collect
Account information. Your email address and a hashed password when you create an account. We use the email to sign you in, to send the alerts you opt into, and for service notices such as a trial ending or an iCloud session that needs reconnecting.
iCloud credentials. To read your albums we sign in to iCloud on your behalf, the same way the Apple website does. For that we store your Apple ID and iCloud password, encrypted at rest with a server-side key, together with the session cookies Apple issues after you approve the two-factor code on your device. We read album names and the list of files in each album. We never modify, delete, or reorganise anything in your iCloud library.
Google Drive access. When you connect Google Drive we receive an OAuth token, stored encrypted, and the email address of the Google account you connected. We use the token to create folders and upload files in the Drive location you choose for each workflow, to list the files already there so unchanged files are skipped, and, when you turn on mirrored deletions, to remove files from that folder that are no longer in the album. See “Google user data” below.
Workflow settings and activity. The album names or patterns, Drive folders and schedules you configure, and a log of each sync run: when it ran, how long it took, how many files were uploaded or removed, the names of those files, and any error messages. These appear in your dashboard and are what our alerts are based on.
Photos and videos in transit. During a sync, each new file is downloaded from iCloud to a temporary directory on our server, uploaded to your Google Drive, and then deleted from our server. Files are kept only for the seconds or minutes it takes to copy them. We keep no library, thumbnails, or archive of your photos.
Billing. Payments are handled by Stripe. We store a Stripe customer and subscription identifier and your plan status. We never see or store your card number.
Technical data. Standard server logs (IP address, browser user agent, requested pages, timestamps) kept briefly for security and debugging. We set only the cookies needed to keep you signed in and to protect forms against cross-site request forgery. We do not use advertising or analytics trackers.
04How we use it
We use the information above only to:
- run the syncs you configure, on the schedule your plan allows;
- show you the status of your workflows and connections in the dashboard;
- send the email alerts you have chosen (for example, when an iCloud session expires);
- bill you for a paid plan and respond to support requests;
- keep the service secure and diagnose problems.
We do not sell or rent personal data. We do not use your photos, file names, or album names for advertising, profiling, or any purpose other than operating your sync.
05Google user data
AlbumFlow’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, Google Drive data obtained through the Drive API is:
- used only to provide and improve the sync feature you see in the dashboard: creating folders, uploading your photos, listing what is already in the destination folder, and removing mirrored files when you enable that option;
- never transferred to anyone else, except as needed to provide the feature, to comply with the law, or as part of a merger or acquisition with notice to you;
- never used for serving advertisements;
- never used to develop, improve, or train generalised or non-personalised machine-learning or AI models;
- never read by a human, except with your explicit permission for support, where required for security or legal reasons, or in aggregated, anonymised form for internal operations.
You can revoke AlbumFlow’s access at any time from the Connections page in the dashboard, or from your Google Account’s permissions page. Revoking access stops all workflows that use that Google account; files already in your Drive are untouched.
07Security
Passwords for your AlbumFlow account are stored as salted hashes. iCloud passwords and Google tokens are encrypted with a key held only on the server. All traffic to the service uses HTTPS. Access to production systems is limited to the people who operate the service.
No method of storage or transmission is perfectly secure. If we learn of a breach affecting your data we will notify you by email without undue delay.
08Retention and deletion
- Photos and videos: deleted from our server as soon as each file has been uploaded to your Drive, and in any case at the end of the sync run.
- iCloud credentials and Google tokens: deleted when you disconnect the account in the dashboard or delete your account.
- Workflow settings and run history: kept while your account exists so the dashboard can show them; deleted with your account.
- Server logs: rotated automatically and kept for a short period.
- Billing records: kept as long as required for tax and accounting purposes.
To delete your account, use the Settings page in the dashboard or email us. Deleting the account removes your credentials, tokens, workflows and history. Everything already copied to your Google Drive remains yours and is not affected.
09Your choices and rights
Depending on where you live you may have the right to access, correct, export or delete your personal data, to object to or restrict certain processing, and to complain to a data-protection authority. You can exercise most of these directly in the dashboard; for anything else, email us and we will respond within 30 days.
The service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
10Changes to this policy
We will post any changes on this page and update the date at the top. For material changes we will also email account holders before the change takes effect.