Privacy policy

Pavlo's NAS Management System (PaNasMs)

Last updated: 22 September 2026.

Scope and responsibility

PaNasMs is self-hosted NAS management software. The operator of each NAS controls that installation, its users, files, backups and enabled modules. This notice describes the project's website, optional OAuth relay and the Google integration supplied with PaNasMs. An operator's custom modules or modifications can have different data practices and must be assessed separately.

Google sign-in and linked accounts

If you choose Google sign-in or account linking, the NAS requests your Google account identifier, email address and basic profile. It stores the identifier, email and display name with the existing Linux account you selected. This allows that identity to sign in to the NAS; it does not by itself authorize access to Google Drive.

Google Drive and Cloud Sync

Drive access requires separate consent for a selected Google account and module. Full Drive permission permits reading, creating, editing and deleting files; read-only permission permits reading files. Cloud Sync uses file names, metadata, change cursors and file contents to synchronize the folders you configure. Two-way tasks can propagate deletions. The broad Drive scope can technically access files beyond an individual configured folder; it is not a Google-enforced folder-only permission.

The NAS stores account references, task settings, cursors and history locally in SQLite. Core stores OAuth client secrets and grant tokens encrypted at rest and renews access tokens. An authorized module receives temporary access tokens through a private local channel. The Cloud Sync module writes those tokens to its private runtime directory, and rclone transfers files directly between the NAS and Google. Synchronized copies and task history remain on the NAS until you or its operator remove them. Encryption at rest does not prevent a privileged NAS administrator from accessing data.

OAuth relay and hosting

The optional project relay runs on Cloudflare Workers. During authorization it receives the browser's callback, including an authorization code or error and a random state value. It stores that response in Cloudflare KV with a ten-minute expiration and requests deletion after retrieval by the NAS. KV propagation and hosting retention are controlled by Cloudflare. The relay does not exchange the code for tokens and does not receive the NAS client secret, access or refresh tokens, or synchronized file contents.

The presentation website is hosted by GitHub Pages and includes no project-added analytics or advertising scripts. GitHub, Cloudflare and Google may process connection information such as IP addresses and request metadata under their own policies. OAuth callbacks necessarily reach the relay hosting platform; this notice does not promise that infrastructure logs contain no request metadata.

Use and disclosure

The supplied Google integration uses Google data only for account linking, authentication and the synchronization or other explicitly authorized functionality. It does not sell Google user data or use it for advertising or training general-purpose AI models. PaNasMs' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

Data is processed by your NAS, your selected cloud provider and the hosting infrastructure described above. If you publish files through NAS shares, install other modules or provide logs to someone, those choices can disclose additional information. Do not submit passwords, tokens or private file contents in public project issues.

Control, revocation and deletion

You can view and revoke module permissions or unlink a Google identity in My profile → Connections. Local revocation prevents further token delivery and refresh; already-issued tokens may remain valid at Google until expiry. Cloud Sync checks permissions during use and stops affected work when access is refused. You can also revoke the application's access in your Google Account; this can affect multiple permissions for the same Google application.

Removing a Cloud Sync task or connection preserves synchronized files. Removing the module preserves its local settings and data. Ask the NAS operator to remove retained local state and backups when you require deletion; copies already synchronized to Google must be managed there as well. Changes to this notice are published on this page.

Contact and third-party policies

For data held by a private NAS, contact its operator. For the project-provided integration or relay, contact shturman.p@gmail.com. For implementation questions, use the project issue tracker without posting sensitive information.