The Dropbox integration is a scoped native OAuth client. Authorization uses PKCE and returns directly to ElseKept through the registered macOS callback.
Permission boundary
The Dropbox application is configured for App Folder content access, not Full Dropbox. ElseKept requests only the file permissions needed inside that folder to create, list, download and delete its encrypted objects. Dropbox automatically includes read-only access to basic Dropbox account information, specifically the account name, email address and country. ElseKept does not use that information or call Dropbox account-profile APIs. It does not request sharing, contacts, team administration or access to files elsewhere in the account.
What is stored
The App Folder contains encrypted backup objects, encrypted recovery metadata and commit markers used to distinguish complete recovery points from partial uploads. Dropbox receives encrypted bytes and normal service metadata such as object sizes and request timing. The application cannot inspect unrelated Dropbox files.
How authorization works
ElseKept opens Dropbox’s authorization page, creates a fresh PKCE challenge and returns through its registered com.elsekept.app.oauth callback. The callback is accepted only for the matching authorization request. Offline token access lets scheduled backups refresh an expired access token without asking the user to reconnect each time.
Access tokens, refresh tokens and expiry information are stored as device-only macOS Keychain items. They are not stored in the backup catalog, command-line arguments, environment variables or app logs.
Removing access and data
Removing the related backup plan from ElseKept removes its local provider credentials but leaves remote encrypted backup data intact for safety. Users can revoke ElseKept from Dropbox’s connected-app settings. Revocation prevents future uploads, health checks and recovery until the user reconnects.
To erase the encrypted Dropbox copy, delete the ElseKept folder inside the Dropbox Apps folder. Revoking the app alone does not erase objects already stored there.
ElseKept does not send application telemetry, share Dropbox data with advertisers or use Dropbox data for profiling.
Policy and support
Read the privacy policy and terms of use. For authorization, recovery or deletion questions, visit support or email [email protected].