Sign in
AppearanceYour firmware. Your choice.
ROMFIX · PRIVACY POLICY

Privacy

Effective date: 8 October 2026.

Who operates RomFix

RomFix is operated by ROMFIX in Vietnam. For privacy, account, data deletion or support requests, contact info@romfix.net. This policy applies to romfix.net. RomFix is currently in a limited rollout; some features are not yet publicly available.

Information we use

We store your Google account identifier, email address and display name to identify your RomFix account. If you connect Google Drive, we store the connection identity, granted permissions and encrypted OAuth credentials. We also store selected file and folder identifiers, names, sizes, checksums, revision and ownership metadata, Save requests, destination status, contribution consent, withdrawal history and download transfer records needed to operate those features.

Operational records include session and security events, request IP addresses, requested paths, response status and timing. Essential session and OAuth cookies support sign-in and security. A browser preference stores your selected colour theme. RomFix does not use Google user data for advertising, sell it, or use it to train general-purpose AI models.

Google permissions and file access

Signing in requests basic identity permissions: openid, email and profile. A user Drive connection uses drive.file and Google Picker for files the user selects or creates through RomFix; it does not give RomFix access to every personal Drive file. The separate administrator source connection uses drive.readonly to read administrator-authorized firmware sources. Ordinary users are not asked for the administrator source permission.

RomFix uses these permissions to show firmware metadata, save a chosen firmware package into the user's selected Drive destination, verify that saved copy and, where the user has agreed to the Save and pool notice, serve that firmware copy for other users' Free Download. This can involve reading the firmware file's bytes. RomFix does not scan unrelated personal Drive files.

Consent and sharing

Google authorization grants file access; it does not replace the separate Save and pool notice. New Save requests that acknowledge that notice permit the same verified firmware copy to serve other users' downloads. Older private copies and withdrawn copies keep their original restrictions. Public pages do not display contributor identities, OAuth credentials or private source descriptors. See the Save policy.

Google provides account and Drive services. DNCloud hosts the RomFix application and its database; Cloudflare provides domain infrastructure. If a download edge service is enabled, it processes the authorized firmware transfer. Providers receive the information necessary for the service they perform. Recovery copies of current application data and configuration are held on the operator's access-restricted PC. Data may be processed in countries where these providers operate. Operator access is limited to running, supporting and securing the service, handling requests and meeting applicable legal obligations.

Limited Use of Google data

RomFix's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Google data is used for the user-facing functions described here, not advertising, sale, unrelated profiling or general-purpose AI training. Human access is limited to cases permitted by that policy, such as a user's affirmative agreement, security investigation or legal requirements.

Retention and security

Account and connection records are retained while needed for the account and connected features. Save, consent, withdrawal and security records can remain after a connection is disabled so RomFix can honour withdrawals, avoid duplicate operations, resolve incidents and handle requests. RomFix does not currently apply a fixed automatic deletion period to these database records or operator-held recovery snapshots. Retention and deletion requests are reviewed individually; we explain any records that must be retained and the reason.

OAuth credentials are encrypted in the application database. Access to private configuration, database and recovery files is restricted. HTTPS protects communication with this website. Session cookies expire after 12 hours; OAuth state expires after 10 minutes. Expiration prevents use and does not itself guarantee immediate removal of the corresponding database record. No system can guarantee absolute security.

Your choices and deletion requests

You can disconnect a Drive in My Drive, which blocks further RomFix use of that connection. You can also revoke RomFix access from your Google Account connections. Disconnecting does not delete your saved Drive files, account, consent history or recovery snapshots. You control files in your Drive.

To request access, correction, withdrawal, account closure or deletion of RomFix-held data, email the contact above from your connected email address and describe your request. We verify control of the account, review the affected records, disable ongoing access where needed, and confirm the outcome or explain a necessary retention exception. Please do not send passwords, access tokens or MFA codes. Deleting data from active systems does not instantly erase older offline recovery copies; those copies remain restricted, and requests must be honoured if a recovery copy is restored.

Changes and contact

We will update the effective date when this policy changes. A material change to how Google data is used requires appropriate notice and consent before that new use. Existing contribution or withdrawal decisions are not silently replaced by this policy.

About RomFix · Terms of use

Privacy | RomFix