Privacy Policy

Last updated July 29, 2026

Overview

Orbit Drive pools multiple Google Drive accounts you own into a single, unified drive. This policy explains what data we collect when you use Orbit Drive, why we collect it, and how it’s protected — in particular, exactly what access we request from your Google account and what we do (and don’t) do with it.

What we access in your Google account

When you connect a Google account, Orbit Drive requests the drive.filescope only — Google’s narrowest Drive permission. This scope only grants access to files that Orbit Drive itself creates or that you explicitly open with Orbit Drive.

  • We cannotsee, list, or read the rest of your Google Drive — files you didn’t upload through Orbit Drive are invisible to us.
  • We use this access to upload files you send through Orbit Drive, list and download files you’ve already uploaded, and delete files when you explicitly delete them (including, if you choose, deleting them from Google Drive itself, not just from Orbit Drive’s records).
  • We also read your Google account email address and Drive storage quota, to identify your account and show how much space is used.

What we store

When you use Orbit Drive, we store:

  • Your email address, used to identify your Orbit Drive account.
  • OAuth tokens for each connected Google account, encrypted at rest — these let Orbit Drive act on your behalf without storing your Google password, and are never stored or transmitted in plain text.
  • File metadata — filename, size, file type, a content checksum used to avoid storing duplicate copies, and the folder it lives in within Orbit Drive’s virtual filesystem.

We do not keep a separate copy of your file contents — the files themselves stay in Google Drive. Orbit Drive stores metadata and routes each upload to the right connected account; Google Drive remains the source of truth for the actual file data.

What we never do

  • We never sell your data or share it with third parties for advertising or marketing.
  • We never access files you didn’t upload through Orbit Drive.
  • We never use your data to train AI or machine learning models.

Deleting your data

Disconnecting a Google account removes its stored OAuth tokens immediately. You can choose whether disconnecting also deletes the files that account was holding from Google Drive itself, or just from Orbit Drive’s records while leaving the files untouched in Drive. Deleting a file or folder in Orbit Drive removes its metadata from our database; if you choose to also delete it from Google Drive, that deletion happens immediately and cannot be undone.

To request deletion of your entire Orbit Drive account and all associated data, contact us at the email below.

Security

All traffic between your browser and Orbit Drive is encrypted (HTTPS). Google account sessions use OAuth 2.0 with PKCE, and OAuth tokens are encrypted at rest. Orbit Drive sessions use signed, expiring tokens rather than storing your password.

Children's privacy

Orbit Drive is not directed at children under 13, and we do not knowingly collect data from them.

Changes to this policy

If this policy changes, we’ll update the date at the top of this page. Continued use of Orbit Drive after a change means you accept the updated policy.

Contact

Questions about this policy, or requests to delete your data, can be sent to support@orbitdrive.space.