Privacy Policy

Last Updated: August 25, 2026

This Privacy Policy describes how Google Drive S3 Pool ("we", "our", or "the Application") collects, accesses, uses, and safeguards information when you connect and use our S3-compatible cloud storage gateway with your Google account.

1. Information We Access and Process

When you authorize access to your Google Account via OAuth 2.0, our application requests access to the Google Drive API (`https://www.googleapis.com/auth/drive`). We access the following information:

  • OAuth Credentials & Tokens: Temporary OAuth access tokens and refresh tokens necessary to authenticate requests to Google Drive on your behalf.
  • Google Drive Files & Folders: File metadata (names, sizes, MIME types, and folder hierarchy) and file binary streams explicitly uploaded or retrieved through your authenticated S3 gateway requests.

2. How We Use the Information

The information accessed from your Google account is used strictly and solely for providing the core functionality of the S3-compatible gateway:

  • Uploading, storing, and organizing objects in designated Google Drive storage pools.
  • Retrieving and streaming file contents when requested via standard S3 API calls.
  • Deleting or copying objects as instructed by authenticated S3 requests.
  • Maintaining accurate bucket indices and metadata in your private Cloudflare D1 database.

3. Google API Services User Data Policy (Limited Use)

Specifically:

  • We do not sell your Google Drive data to any third parties.
  • We do not use your data for advertising, marketing, or profiling purposes.
  • We do not use your data to train generalized artificial intelligence (AI) or machine learning (ML) models.
  • Human review of your data is strictly prohibited unless required by applicable law or explicitly authorized by you for troubleshooting.

4. Data Storage, Security, and Protection

We employ industry-standard security practices to protect your data:

  • All communications between S3 clients, Cloudflare Workers, and Google APIs are encrypted in transit using TLS 1.3 / HTTPS.
  • OAuth refresh tokens and credentials are encrypted and stored securely within Cloudflare Secrets and Cloudflare KV.
  • File metadata is stored in an isolated Cloudflare D1 database belonging to your deployment.

5. Data Retention and Account Revocation

You retain full ownership and control of your data at all times:

  • Revoking Access: You can revoke the application's access to your Google account at any time via your Google Account Security Permissions page.
  • Data Deletion: Deleting an object via the S3 API or deleting your deployment immediately removes associated files and cached metadata.

6. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or data handling practices, please contact us:

Email: hirestilestari@gmail.com
Developer: Google Drive S3 Pool Team