Effective: July 1, 2026
1. Introduction
Drive. ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our encrypted cloud storage service (the "Service").
By using Drive., you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
2. Information We Collect
We collect only the minimum information necessary to provide and improve the Service:
- Account Information: Your email address is required to create an account. We use it solely for authentication and account recovery.
- Profile Information: Your display name and optional profile picture. These are visible to anyone you share files or folders with.
- Device Information: Device type, OS version, and a device identifier used to bind your account to your device and for push notifications.
- Usage Data: Aggregated, anonymized metrics about app performance and feature usage. This data cannot be traced back to you.
3. Information We Do NOT Collect
Drive. is designed with privacy first. We do not collect:
- File content (all files are end-to-end encrypted and we never have access to plaintext)
- Media content (photos, videos, documents — encrypted before upload, decrypted only on your devices)
- Contact list contents (sharing uses direct identifiers — we never access your address book)
- Location data (we do not track your location, even while you use the app)
- Browsing history or third-party app data
- Biometric data (fingerprints, face scans — these remain on your device)
4. How We Use Your Information
The limited information we collect is used exclusively for:
- Providing, maintaining, and improving the Service
- Authenticating your identity and securing your account
- Sending push notifications for account activity (e.g., sync requests, share invites)
- Detecting and preventing abuse, fraud, or unauthorized access
- Complying with legal obligations, if and when required by applicable law
We never use your data for advertising, profiling, or selling to third parties.
5. Data Storage and Security
Your files are encrypted on your device before upload and stored on our servers in encrypted form — we cannot read them. File metadata (filenames, folder structure) is also encrypted before transmission. Decrypted content exists only on your devices.
We implement industry-standard security measures including encryption at rest, TLS 1.3 in transit, hardware-backed key storage, and regular security audits. Despite these measures, no method of transmission or storage is 100% secure. We continuously work to improve our security posture.
6. Data Retention
We retain your account information for as long as your account is active. Your encrypted files are stored until you delete them or your account. Deleted files are permanently removed from our servers within 30 days.
If you delete your account, we delete all associated data within 30 days, except where retention is required by law.
7. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share information only in the following circumstances:
- Service Providers: With third-party vendors who help us operate the Service (e.g., cloud infrastructure, push notification delivery). These providers are bound by strict data processing agreements and may only use your data as instructed by us.
- Legal Compliance: When required by law, court order, or governmental regulation. We will challenge overly broad or unlawful requests.
- Protection of Rights: To protect the rights, property, or safety of Drive., our users, or others.
8. End-to-End Encryption
Drive. uses end-to-end encryption (E2EE) to protect all files, photos, videos, and folders you store. This means:
- Files are encrypted on your device before upload
- Only you (and those you explicitly share with) can decrypt them
- Drive. servers never have access to encryption keys or plaintext content
- Encryption keys are derived from your PIN and stored in your device's secure hardware (Secure Enclave / KeyStore)
We cannot recover your files for you if you lose access to your device or forget your PIN. This is a deliberate design choice to protect your privacy.
9. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your account and associated data.
- Portability: Request transfer of your data in a machine-readable format.
- Objection: Object to our processing of your data.
- Withdrawal of Consent: Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, contact us at privacy@drivedot.cloud. We will respond within 30 days.
10. Children's Privacy
Drive. is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal data, we will delete it immediately.
11. International Data Transfers
Your information may be transferred to and processed in countries where our servers and service providers are located. We ensure appropriate safeguards are in place through standard contractual clauses and data processing agreements.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes through the app or via email. Your continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:
Email: privacy@drivedot.cloud
Address: RootAcess Cyber Solutions Private Limited, Kota, Rajasthan, India 324010