PRIVACY & YOUR CONTROL

Privacy policy

Effective September 18, 2026

My Drive Storage Review is a personally operated desktop tool for inventorying Google Drive accounts and helping their users plan storage organization. This policy covers the local application and this public information website.

1. Information the application accesses

When you authorize a Google account, the application requests https://www.googleapis.com/auth/drive.metadata.readonly. It accesses the account email address and available profile display name returned by the Drive API, reported storage usage and limits, and available file metadata.

Metadata can include file and folder names and IDs, file types and sizes, storage quota consumption, creation, modification and last-viewed dates, folder relationships, ownership and owner email addresses, sharing indicators, starred and trash status, available checksums, and shortcut targets. The inventory may include items shared with you that Google returns to your account.

The current version does not retrieve file contents, Gmail messages, or Google Photos libraries, and does not change files, sharing permissions, or account settings.

2. How this information is used

The application uses metadata to produce storage reports, display and filter the file inventory, identify possible duplicate binary files, compare usage between scans, and record your review decisions. It uses OAuth access and refresh tokens to make authorized Google API requests and renew access when permitted.

A duplicate candidate or a review mark is not an instruction to delete data. Future download, deletion, transfer, or archiving features would require a separately disclosed workflow and any additional Google permissions they need.

3. Local storage and retention

OAuth client configuration, account tokens, metadata snapshots, and reports are stored on the computer running the application. Sensitive directories and files use owner-only operating-system permissions. The application does not itself encrypt these files at rest; protection also depends on that computer's security and any disk encryption you enable.

Reports and saved tokens remain locally until the operator removes them. Successful scans replace the latest account snapshot and create a new report. Review decisions in the interface remain in the current browser tab until exported to a local JSON file. Exported decisions remain until deleted.

Local backup or synchronization software may copy these files if the operator includes their storage location in a backup or sync configuration.

4. Sharing and service providers

Google receives authenticated requests needed to operate the Drive API and OAuth connection. The application does not automatically upload account tokens, metadata inventories, or reports to this public website or to an AI service.

If you expressly choose to review your inventory with an AI assistant or another person, selected metadata or reports may be shared to carry out that requested review. An assistant with access to your local workspace may read reports you ask it to analyze. Any such service also operates under its own privacy terms and your account settings. OAuth credentials are not needed in shared reports.

The application does not sell Google user data, use it for advertising, or use it to build or train generalized AI or machine-learning models.

5. Public website

This website is hosted on Cloudflare Pages and serves only application information and this policy. No Google account tokens or private Drive reports are included in its deployment. It has no application account registration, advertising, or application-added analytics or tracking scripts.

Cloudflare may process ordinary request information, such as IP addresses, browser details, and requested URLs, to deliver and protect the website under its privacy policy.

6. Revoking access and deleting local data

You can stop future authorized access by opening your Google third-party connections and removing this application's connection. Repeat this for each connected account.

Revoking Google access does not erase previously saved local reports or copies shared elsewhere. To remove the application's local data, delete the relevant account tokens, metadata snapshots, and reports from its private/ and reports/ directories, along with exported review files and any backups you created. The application operator can assist with identifying those files.

7. Google API Services User Data Policy

My Drive Storage Review's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

8. Contact and changes

For privacy questions or assistance removing local application data, contact the application operator at the support email displayed on the application's Google OAuth consent screen.

This policy will be updated if the application's data practices change. The effective date at the top identifies this version. Material changes to account access will be explained before requesting additional permissions.