Back to HomeLast Updated: July 16, 2026

Privacy Policy

Welcome to CloudVaults. Your privacy is paramount. This policy describes how we collect, use, and protect your information when you connect and manage your AWS S3, Google Cloud Storage, and Google Drive accounts through our application.

1. Google API User Data & OAuth Scopes

When you connect your Google Drive account, CloudVaults requests access to your files via Google OAuth 2.0. Specifically, we request permission to:

  • View your Google Drive file metadata (file names, sizes, creation times, mimeTypes, and parent directory mapping).
  • Read and download files you explicitly request to transfer, copy, or view in the CloudVaults interface.

Google Limited Use Compliance: CloudVaults' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer this information to third-party advertising partners, data brokers, or external servers.


2. How We Use and Process Information

We only access and use your connected storage provider metadata for dashboard functionality:

  • Consolidated Storage Dashboard: We aggregate metadata (such as folder structures, sizes, and last modified dates) so you can browse AWS S3, Google Cloud Storage, and Google Drive in a unified file manager.
  • Cross-Vault Transfers: When you initiate a "cross-transfer" copy or cut action, we temporarily read your file streams to securely write them to your designated destination bucket.
  • Storage Analysis & Duplicate Detection: We inspect filenames and hash values to calculate metrics and help you clean up duplicates.

3. Storage and Data Retention

We prioritize your credentials and sensitive keys:

  • Encrypted Credentials: Your AWS/GCS API keys, bucket names, and Google OAuth tokens are securely stored and encrypted in our database backend and used only to sign requests to the respective storage providers.
  • Cached Metadata: File metadata is cached in our Convex database to speed up folder browsing. No original files or their contents are ever permanently stored on our servers.

4. Revoking Access & Deleting Your Data

You retain complete control of your integration credentials:

  • Disconnecting Vaults: You can delete your connected S3 buckets, GCS projects, or Google Drive integrations from the Providers dashboard. Disconnecting a provider immediately deletes all associated credentials, API keys, and cached file metadata from our database.
  • Google Security Settings: You can permanently revoke CloudVaults' access to your Google account at any time via your Google Account Security Settings.

5. Contact Us

If you have any questions or suggestions regarding this Privacy Policy, please reach out to us at:
[email protected]

© 2026 CloudVaults. All rights reserved.