Bukkumaku Ops Backups

Last updated: 3 October 2026

Privacy policy

This policy explains how Bukkumaku Studio’s private Bukkumaku Ops Backups tool handles the Google Drive connection and backup data.

Operator and purpose

Bukkumaku Studio, Kuala Lumpur, Malaysia, operates this tool for its authorized owners. Its purpose is database backup, integrity checking, interrupted-run recovery and owner-controlled restoration. Contact: [email protected].

Information accessed

With the owner’s authorization, the app uses Google Drive’s specific-files permission, https://www.googleapis.com/auth/drive.file. The configured runner accesses the app’s backup folder, encrypted snapshot files and encrypted retry journal. It reads their file identifiers, names, parent folders, sizes, checksums, app metadata, trash and sharing status, and the content needed to verify uploads or resume an interrupted backup.

The app creates and updates those files, lists its snapshots and moves eligible older daily snapshots to trash. It does not request full-Drive, Gmail, Contacts or Calendar permissions. It does not scan unrelated Drive files.

The source database export can contain order and customer information, payments, product configuration, staff accounts and audit records held in Bukkumaku Ops. Uploaded artwork/reference binaries are not included in these database snapshots.

Storage and protection

The runner temporarily processes the database export on a trusted private GitHub Actions runner. It compresses and encrypts each snapshot before uploading it to the owner’s private My Drive folder. The owner keeps the private recovery key; the scheduled runner receives only the public recovery key. Temporary runner files are removed when the execution environment is retired.

The Drive retry journal is separately encrypted and can contain upload-session information, backup state and the already-encrypted snapshot. A separate journal key protects that information. OAuth credentials and runner keys are retained in private repository secrets and in the owner’s protected recovery storage. Secrets, SQL exports and file contents are not intentionally included in job logs, artifacts or caches.

Snapshot metadata such as timestamps, identifiers, file sizes, digests and backup type is stored alongside the encrypted files. Bukkumaku Ops stores backup status information for authorized administrators. Encryption does not hide all file metadata from the storage provider.

Service providers and access

Google provides authorization and Drive storage, GitHub executes the private backup workflow and stores its configured secrets, and Cloudflare hosts the source database, application and this information website. These providers process the information needed to supply their respective services under their own policies. Authorized owners may download and decrypt backups for recovery or troubleshooting.

Google API data is not sold, used for advertising, supplied to an AI model or used for an unrelated purpose. The app does not grant public or shared-folder access to backup files. Use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

Retention and removal

For verified daily snapshots, the runner retains the union of the latest snapshot for each of the most recent seven Malaysia calendar dates, eight weeks and twelve months, plus the latest daily copy. Missing periods do not create additional copies. Eligible older daily snapshots are moved to Drive trash, not permanently deleted. Restore-drill and pre-change snapshots require owner review and are not automatically rotated.

The retry journal preserves the state and encrypted snapshot needed for resumption and is updated by subsequent runs. Drive trash, old file revisions and separately downloaded recovery copies can continue to occupy storage. The app does not automatically empty trash.

An owner can revoke the app’s Google access and disable its workflow to stop future operations. Revocation does not delete existing backups. After disabling the runner, the owner can remove its folder and journal, empty relevant trash, remove repository secrets and delete local recovery copies as appropriate. Deleting recovery keys or backups can prevent restoration. Contact support for help with access or deletion requests.

This public website

These information pages include no login, upload form or analytics scripts. The hosting provider may process ordinary request information, including IP address and browser information, to deliver and protect the site. No database records or backup credentials are published here.

Changes

Material changes to the backup’s data practices will be reflected on this page before use of the changed process. The date above identifies this version.