Personal & Internal Tool

Direct Google Drive Sync with FSM Rclone

FSM Rclone is a dedicated, client-side data transfer and backup utility created and operated by FSM Systems. It enables authorized system engineers to securely mount, synchronize, and back up personal and operational data directly between local workstations and Google Drive.

fsm-admin@workstation:~

$ rclone --config=fsm-rclone.conf sync /data/backups gdrive:SecureVault/

2026/10/02 14:00:01 INFO : Google Drive root 'SecureVault/': Connecting via OAuth 2.0 Client...

2026/10/02 14:00:02 INFO : Validating TLS connection to googleapis.com...

2026/10/02 14:00:03 INFO : Comparing remote hashes (MD5) with local files...

2026/10/02 14:00:05 INFO : Transferred: 4 / 4 files, 100%, 48.2 MB/s

2026/10/02 14:00:05 INFO : Sync completed successfully (0 errors).

$ _

Application Transparency

Why FSM Rclone Exists & How It Works

In strict compliance with Google Cloud Platform developer guidelines, this page explains what the application does, why access is requested, and how your data is handled.

Personal Administration & Backup

FSM Rclone is designed for internal administrative workflows at FSM Systems. It allows individual engineers to replicate critical database snapshots, configuration files, and work directories safely to Google Drive storage folders.

Point-to-Point Direct Connection

All file transfers occur strictly between the client's local computer and Google Drive API endpoints (https://www.googleapis.com). FSM Systems does not operate intermediate proxies, relays, or hosted middleman servers.

Local Credential Storage

OAuth 2.0 refresh tokens and configuration profiles are stored exclusively on the user's local disk within an encrypted or permission-restricted configuration file (e.g. ~/.config/rclone/rclone.conf). Tokens are never shared or transmitted elsewhere.

Scope Justification

Requested Google Drive OAuth Scopes

FSM Rclone adheres to the principle of least privilege, requesting only the specific Google Drive permissions necessary to execute bi-directional file synchronization and integrity checks.

OAuth Scope Access Type Exact Technical Purpose
https://www.googleapis.com/auth/drive.file
Recommended / Per-File Access
Restricted / Sensitive Allows FSM Rclone to create, read, update, and manage only the specific files, folders, and backup archives that were created by or opened directly with the application in Google Drive.
https://www.googleapis.com/auth/drive
Full Drive Access (Optional Configuration)
Restricted Scope Requested only when the user explicitly configures synchronization across pre-existing cloud directories, shared drives, or entire drive hierarchies. Required to query remote file hashes (MD5), timestamps, and folder trees to identify changed or missing files.
https://www.googleapis.com/auth/drive.readonly
Read-only Mode (Optional)
Sensitive Used during read-only restore drills, directory audits, or one-way download tasks (e.g. rclone copy gdrive: /local/path) without write permissions.
Google API Services User Data Policy Compliance (Limited Use Disclosure)

FSM Rclone's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google user data obtained through OAuth authentication is never transferred to external servers, never shared with third parties, never used for advertising, and never utilized to train generalized artificial intelligence or machine learning models.

Zero-Intermediary Guarantee

How Data Moves Through FSM Rclone

Understanding the end-to-end data pipeline: why user data remains strictly private to the user.

1

Local User Consent

The user initiates authorization via Google's official OAuth consent screen. Upon grant, Google issues temporary access tokens directly back to the local client.

2

Direct Encrypted Sync

FSM Rclone opens an HTTPS/TLS connection directly between the local computer and Google Drive endpoints. Payloads stream point-to-point without intermediary servers.

3

Instant Revocability

Because tokens exist only on the user's machine, revoking access is instantaneous via Google Account Permissions or deleting the local config file.