MoveMyPosts · Legal
Privacy Policy
Effective date: September 30, 2026
1. About this policy
MoveMyPosts is operated by Emre Durukan. This policy explains how movemyposts.com handles information when you move saved Google Maps places into Google Sheets. For privacy questions or data requests, contact [email protected].
2. Information we access
- Manual import: you select a Google Takeout ZIP or Saved collection CSV. The browser reads place titles, list names, Google Maps links, notes, and comments. You may add notes or a visited status.
- Direct Google transfer: with your permission, Google supplies your Saved collections archive to our server. The archive may also contain non-Maps saved items and images. We process the archive in memory to extract Maps places; other archive content is not used for the export.
- Authorization and transfer records: direct transfers use Google access and refresh tokens, a random session identifier, authorization state, archive job identifier, timestamps, job status, errors, exported place count, and the created spreadsheet identifier or URL.
- Support and technical information: if you email us, we receive your address and message. Our hosting and network providers may process IP addresses, request details, browser information, and security or diagnostic logs to deliver and protect the service.
3. Google permissions and how we use them
Google account authorization is optional until you choose a Google transfer or export. Browsing this website, reading this policy, trying sample data, and importing a Takeout file do not require signing in. We do not request access to Gmail, contacts, calendars, your location history, or your entire Google Drive. The application does not request profile or email scopes or fetch your Google account profile.
We request drive.file to create and write the spreadsheet you request. MoveMyPosts does not scan your Drive or read unrelated existing files. Direct transfer also requests dataportability.saved.collections to obtain your Saved collections archive. These permissions are requested in separate Google consent steps. We never receive your Google password.
Manual export sends your selected rows directly from your browser to Google Sheets. Direct transfer writes the Maps places found in the archive into a new Sheet in the Google account you authorize for Sheets. Choose the same Google account for both direct-transfer consent steps. The exported columns are Place, List, Google Maps URL, Note, Comment, and Status. We do not change your original Google Maps lists or continuously synchronize them.
4. Storage and retention
Manual imports are not uploaded to our server. Selected place titles, list names, Maps URLs, notes, comments, and visited status are sent directly from your browser to Google Sheets only when you request an export. Direct transfers pass through our server: it receives Google's archive download, parses the Maps rows, and sends them to the Google Sheets API. The archive and rows are held in memory during processing, rather than retained as downloadable files.
- In your browser: manually imported places, your edits, import summaries, and export history links are stored in local storage until you clear them or your browser removes site data. Manual-export access tokens are held in page memory, not local storage.
- On our server: direct-transfer session payloads, including pending OAuth tokens, are encrypted in the Cloudflare D1 database. Some operational fields, such as phase and expiry time, are stored separately to manage jobs. Downloaded archives and parsed place rows are processed in memory and are not intentionally persisted as archive files or a places database.
- Transfer expiry: sessions expire eight days after they start. Expired sessions cannot be resumed and their database records are removed when a subsequent transfer starts; expiry is not a guarantee of immediate physical deletion. Tokens are removed after successful completion and processing failures. An interrupted or denied authorization can retain an earlier encrypted grant until the session is deleted or cleaned up.
- In Google: created Sheets remain in your Google Drive until you delete them there. Google's retention rules apply to data held by Google.
- Support and service logs: correspondence is retained as needed to resolve requests and meet applicable obligations. Infrastructure logs and backups may follow the relevant provider's retention schedule.
5. Sharing and limited use
The recipients of Google user data needed for these workflows are Google (authorization, archive delivery, and the resulting spreadsheet) and Cloudflare (our hosting, server processing, and encrypted transfer database). Opening links to Maps or your new Sheet takes you to Google's services. Sharing an exported Sheet with other people is controlled by you in Google Drive; MoveMyPosts does not publish your Sheet or grant other people access.
Google receives the spreadsheet data you choose to export. Cloudflare provides site hosting and the database and server processing used for direct transfers. Google Identity Services provides authorization, and the main application loads fonts from Google; those requests disclose normal network information to the providers. See Google's Privacy Policy and Cloudflare's Privacy Policy.
We do not sell Google user data, use it for advertising or credit decisions, or use it to train generalized AI or machine learning models. Google data is used only to provide the transfer and export features you request. Any other disclosure is limited to what is necessary for security, legal obligations, or a business transfer with your prior consent where required. We do not routinely allow people to read your Google user data. Human access is limited to your affirmative agreement to view specific data for support, investigating abuse or security issues, complying with applicable law, or using aggregated and anonymized data for internal operations as permitted by Google’s Limited Use requirements.
MoveMyPosts follows the Google API Services User Data Policy, including its Limited Use requirements. Our use of information received through the Data Portability API also complies with Google's Data Portability API user data and developer policy, including its Limited Use requirements.
6. Cookies and local storage
The direct-transfer flow sets an essential, HTTP-only session cookie named mmp_transfer, with an eight-day lifetime. On HTTPS it is marked Secure. The cookie links your browser to your transfer. Local storage keeps your manual workspace and export history. The application code does not include advertising trackers or third-party analytics.
7. Your choices and deletion
You can choose the manual workflow without granting Saved collections access, decline either Google permission, or stop using the service. To remove all copies, browser data, server transfer records, Google authorization, and exported Sheets need to be addressed separately:
- Use Clear local data to remove browser-stored places, edits, and export history. You can also clear this site's storage in your browser settings.
- While a direct transfer is waiting, use Cancel transfer and delete pending access. This removes its server session and attempts to reset Google's Data Portability authorization. Cancellation may be temporarily unavailable while processing is already running.
- Revoke MoveMyPosts access in your Google Account connections. The manual export's Disconnect control also requests revocation of its current grant. Revocation does not delete an existing Sheet or your browser workspace.
- Delete exported spreadsheets in Google Drive separately.
- For access, correction, deletion, or another privacy request, email [email protected]. Describe the transfer and approximate time; do not send passwords, OAuth tokens, or your full archive. We may need proportionate information to verify a request. Rights and exceptions depend on your location.
8. Security and international processing
We use HTTPS and encrypt stored direct-transfer session payloads. No service can guarantee absolute security. Google and Cloudflare operate globally, so processing may take place outside your country. Where applicable, processing is based on your authorization, providing the requested service, protecting its operation, and legal obligations. If applicable law gives you the right, you may object to processing or complain to your local data protection authority.
9. Children and policy changes
MoveMyPosts is intended for people who can lawfully authorize their Google account and agree to the service terms; it is not directed to children under 13. Contact us if you believe a child has supplied personal data. We will publish policy updates here with a revised date. If we materially change how we use Google user data, we will provide notice and request any required additional consent before that new use.