
My main Google account hit the 15GB free limit while my alt accounts sat empty. So I built Spillover — an open-source tool that rebalances your Google storage across your own accounts, running entirely on your machine.
But here's the thing about building a tool that moves people's files: if it loses even one file, nobody will ever trust it again. Safety wasn't a feature — it was the whole design. Here's how I layered it.
1. Dry-run by default
spillover run only ever previews the plan. Nothing moves until you pass --execute — and even then it asks for confirmation. The default path is the safe path; destruction requires intent, twice.
2. Verify-before-trash
This is the core guarantee: a source file is trashed only after the destination copy's SHA-256 hash matches the downloaded bytes. The pipeline is download → hash → upload → verify → trash, in that order, always. Hash mismatch? The source stays untouched and the move is logged as failed. There is no code path where the original is touched before the copy is proven identical.
3. Trash, never delete
Even after verification, originals go to the source account's trash — not permanent deletion. That's a 30-day undo window, courtesy of Google. If something ever looks wrong, you can pull it straight back out.
4. Crash-safe resume
Every file is tracked as a transaction: pending → in_progress → done/failed, with the last completed stage recorded. If the run dies halfway — killed process, dead laptop, dropped network — spillover resume continues from the first unfinished stage. A destination copy that was already uploaded and verified is never re-uploaded.
5. A permanent local ledger
Every move (done, failed, or skipped) lands in a local SQLite ledger: filename, size, hash, source → destination. Months later you can run spillover find vacation.mp4 and know exactly where it went. No cloud, no account — just a file on your machine.
6. Guardrails around the edges
- 1GB safety buffer per account — a destination is never filled to the brim.
- Shared files skipped by default — moving a file you don't own breaks share links and strands collaborators, so they're flagged at plan time and skipped at run time unless you explicitly opt in.
- Narrow OAuth scopes — Drive plus the Photos picker scope only. The picker exposes solely the items you select, never your whole library. No Gmail, no contacts, nothing else.
The honest limitation: Google Photos
Since March 2025, Google blocks third-party apps from reading your full photo library and provides no delete endpoint — so no tool on earth can fully automate Photos moves in 2026. Spillover uses the picker (you select in Google's own UI) plus Takeout imports, copies your picks hash-verified into your other accounts' Drive, and writes you a manual-deletion checklist. I'd rather tell you what it can't do than pretend otherwise.
Spillover is MIT licensed — Python, with a local web UI and CLI. v0.1.0 is out now.
- Repo: https://github.com/aashish254/Spillover
- 7-minute tutorial: https://www.youtube.com/watch?v=EVb7bLrMGnY
If you've ever paid for Google storage while sitting on empty accounts, this one's for you. Issues, PRs, and feedback welcome.
Top comments (0)