Draivu Draivu
Features Pricing Story Privacy Terms Contact Get Extension

Privacy Policy

Last updated: July 24, 2026  ·  Applies to the Draivu Chrome Extension and this website

On this page

Zero-Data Promise What We Access Data Sharing Data Protection Payments Data Retention Your Privacy Rights No Tracking Contact

Draivu is architected for maximum privacy. It is completely serverless.
No user data, file metadata, or Google Drive content is ever transmitted to or stored on servers controlled by the developer. Everything stays between your browser and Google's own servers.

What We Access & Why Sensitive Scopes

Draivu requests the minimum permissions required to do its job. Below is an exact breakdown of every Google OAuth scope the extension uses, and precisely how it is used.

Scope Why it's needed What we never do with it
drive.file Allows Draivu to read and preview only the files you explicitly select via Google Picker. Without this, file previews and full-text search cannot work. We never access files you haven't selected. We never download, copy, or transmit your file contents to any server.
drive.appdata Stores your pinned-file registry (a list of file IDs and names) in a hidden Application Data folder in your own Drive. This enables sync across your devices. We never read, modify, or share any other folder in your Drive. The appdata folder is invisible in the standard Drive UI.
contacts.other.readonly Powers the contacts autocomplete when you use the Share feature to share a file with someone, using Google's "Other contacts" (people you've emailed or interacted with, not your saved Contacts list). Your contacts are never stored, logged, or sent anywhere. They are used only to render autocomplete suggestions in the moment you type.

The use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Who We Share Your Data With Zero Third Parties

We do not share, transfer, sell, or disclose your Google user data (Drive files, file metadata, contacts, or any content accessed via the scopes above) to any third party, for any purpose, ever.

You
Your browser
HTTPS/TLS Secure Direct browser-to-Google connection No Draivu server in between
Google
Drive files, metadata, contacts

Because Draivu has no backend server, there is no infrastructure of ours in the middle to leak from. Your data moves directly between your browser and Google's own servers. The only two parties that ever see any of your data are you and Google.

The one exception, entirely separate from Google user data: if you purchase Draivu Pro, your billing details are handled directly by Dodo Payments (see Payment Processing below). Dodo never receives any Google user data, only what's needed to process a payment.

How We Protect Your Data Sensitive Data

Transport: All communication with Google's APIs happens over HTTPS/TLS, directly from your browser to Google's servers. There is no developer-controlled server in between to intercept, log, or store anything in transit.

Storage: Data Draivu keeps locally (your FAB position, pinned-file list, sticky note states, UI preferences) is stored in chrome.storage.local, which is sandboxed to the Draivu extension by Chrome itself. No other extension, website, or script can read it. Your pinned-file registry additionally syncs through a hidden Application Data folder inside your own Google Drive, which only Draivu's own OAuth token can access and which is invisible in the standard Drive UI.

Sensitive scopes specifically: the contacts.other.readonly scope is used only to render autocomplete suggestions in the moment you type in the Share dialog. Results are never written to storage, logged, or transmitted anywhere; they exist only in memory for that interaction.

No server-side attack surface: because Draivu is fully serverless, there is no database, no server logs, and no developer-side infrastructure holding your data that could be breached, subpoenaed, or misused. The only copies of your data live in your own browser and your own Google account.

Payment Processing Third Party: Dodo Payments

Draivu Pro is an optional paid upgrade. All payment processing is handled by Dodo Payments (dodopayments.com), a Merchant of Record. Dodo collects your billing details, issues a receipt, and emails you a license key.

We never see your credit card, billing address, or payment details. The only thing Draivu receives from Dodo is whether your license key is valid or not. A single boolean.

For Dodo's own privacy practices, see the Dodo Payments Privacy Policy.

Data Retention & Deletion

Since Draivu has no backend servers, there is no user data stored on our end. Nothing to retain, nothing to request deletion of.

The only data Draivu stores is saved locally in your browser using chrome.storage.local: your FAB position, pinned file list, sticky note states, and UI preferences.

Uninstalling the extension wipes all of this instantly. Your pinned-file registry in Drive's appdata folder can be deleted by revoking Draivu's access at myaccount.google.com/permissions.

Your Privacy Rights GDPR / CCPA

European Union / EEA (GDPR): if you're located in the EU or EEA, Google user data accessed through Draivu is processed under the General Data Protection Regulation. Our legal basis is your explicit consent, given through Google's own permission screen each time you authorize a scope, and the contractual necessity of providing the specific feature you've asked to use.

You have the right to access, correct, restrict, or object to how your data is processed, and the right to data portability. In practice, most of this is already satisfied by Draivu's architecture: since we don't store your Google data ourselves, there's nothing on our end to access, correct, or export beyond what you can already see and manage directly in your own Google Account. Revoking Draivu's access through Google Account Permissions immediately and completely ends our access.

You also have the right to lodge a complaint with your local data protection supervisory authority if you believe your data has been mishandled. We'd genuinely appreciate you reaching out to us directly first at hello@draivu.com so we can address it.

California (CCPA): Draivu does not sell or share your personal information with any third party, and hasn't met the revenue or data-volume thresholds that trigger CCPA's formal requirements. Even so, if you're a California resident, you have the right to know what personal information we have about you and to request its deletion. The same answer applies here too: we don't retain any of it ourselves, so there's nothing to disclose or delete beyond what's already in your own Google Account. You can revoke Draivu's access anytime through Google Account Permissions.

No Tracking. No Ads. No Telemetry.

We built Draivu because we wanted a better Drive experience. Not to harvest data.

🚫

No analytics
No Google Analytics, Mixpanel, Segment, or any tracking SDK. Not in the extension, not on this page.

🍪

No cookies
This website sets no cookies. The extension does not use cookies.

📣

No ads
We will never show ads or sell your data to advertisers or data brokers. Ever.

📡

No phone-home
The extension makes no background network requests except to Google APIs and Dodo's license validation endpoint.

Contact

Questions about this policy or anything else? We're a small indie project. Real humans respond.

📬   Reach us at hello@draivu.com. We usually reply within 48 hours.

Send email
Draivu Draivu
Pricing Story Privacy Policy Terms of Service Contact Chrome Web Store
© 2026 Draivu
Draivu is an independent product and is not affiliated with, endorsed by, or sponsored by Google LLC. Google Drive, Google Docs, and related marks are trademarks of Google LLC. Use of Google APIs is subject to Google's Terms of Service.