PRODUCT HUNT
We're live on Product Hunt today. Support the launch and see how we catch risky shares before they become a problem.
View launch
top of page

Privacy Policy

Last updated: August 24, 2026

The Short Version

 

This is a plain-English summary. It is not a replacement for the full policy below, which is what actually governs.

  • What we look at. A normal NeatDrive scan reads information about your files — names, types, sizes, dates, folders, and who they are shared with. It does not open your files or read what is inside them.

  • Two optional features read file contents. Both are off unless you turn them on, need a separate Google permission you are free to decline, and work only on files you pick yourself. Neither runs during a normal scan.

    • AI naming reads roughly the first 2,000 characters of a file to suggest a better name.

    • Duplicate checking has two modes. Duplicate detection, which runs automatically during a scan, compares the MD5 checksum Google supplies with each file's metadata, and does not open your files. A content-based duplicate check, available only after you grant write access and only on files you select, downloads a file's bytes to compute a SHA-256 hash in memory — the bytes are discarded once the hash is computed and are never written, logged, or sent onward; only the hash is kept.

  • We can see who your files are shared with, including their email addresses. That is how we are able to tell you who has access to what, and warn you about sharing you did not intend. Those people are not our users, we never contact them, and we do not build profiles of them.

  • We do not sell your data and do not use it for advertising. We transfer it only to the processors named in the full policy. We do not use your data to train AI models, and our platform provider is contractually committed not to.

  • How much you can undo depends on the action. Revoking a share can be undone in NeatDrive for 30 days. Files we delete go to your Google Drive Trash, where NeatDrive can restore them for 30 days. Archived files move to a NeatDrive Archive folder in your own Drive, so you can move them back yourself, and a cleanup applied as a quarantine batch can be rolled back for 30 days. Renaming a file, removing your own access, and transferring ownership cannot be undone by NeatDrive. Two more things are permanent and ask you to confirm first: emptying your Trash from the Declutter page, and deleting your NeatDrive Archive folder.

  • You are in control. Nothing is changed in your Drive without your approval, you can disconnect Google Drive at any time, and you can delete your account and everything in it from inside the app.

 

Questions? help@neatdrive.net.

Overview

 

NeatDrive ("we", "our", or "us") is committed to protecting your privacy. This policy explains how we collect, use, store, and delete your information when you use our Google Drive cleanup service. NeatDrive is operated by NeatDrive LLC (Oregon, USA).


 

What We Collect

 

When you use NeatDrive, we collect:

  • Account information (your email address and basic account identifiers from Google Sign-In).

  • Google Drive file metadata — specifically: file names, MIME types, file sizes, created and modified dates, owner information, folder paths, Shared Drive names and identifiers, web view links, sharing settings, and permission details. Permission details include the email addresses and domains of the people your files are shared with, their access level, and whether a file is publicly discoverable. Those individuals may not be NeatDrive users themselves. We use this information solely to show you who has access to your files and to flag risky or unintended sharing. We do not contact these individuals, market to them, or build profiles about them.

  • A content checksum (MD5 hash) for each file. This checksum is supplied by Google as part of the file’s metadata — we do not open the file to calculate it. A content-based duplicate check, available only after you grant write access and only on files you select, downloads a file’s bytes and computes a SHA-256 hash in memory; the bytes are discarded once the hash is computed and are never written, logged, or sent onward. A checksum is a short fingerprint derived from a file’s contents. It lets us identify files whose contents match so we can detect duplicates, without storing the file itself. A checksum cannot be reversed to reconstruct your file or reveal its contents.

  • Usage and diagnostic data (pages visited, actions taken in the app, error logs). Page analytics are collected by Vercel in a cookieless form that cannot identify you individually, and crash diagnostics by Sentry. Neither receives the contents of your files.

  • File contents, only in the two limited cases described under "Optional Features That Read File Contents" below. During the standard read-only audit, NeatDrive reads metadata only.


 

What We Don't Collect

 

NeatDrive does NOT collect:

  • Your file contents during a standard scan. The default Drive audit reads metadata only and cannot access the contents of your files.

  • Your Google account password. Authentication is handled entirely via Google OAuth 2.0.

  • Sensitive personal information as defined under CPRA — see the California section below.


 

Google API Permissions We Request

 

NeatDrive uses a three-step permission model:

  1. Sign-in: Handled by our application platform, Base44, which authenticates you with Google and passes us only your name and email address. This step grants no access to your Google Drive, and NeatDrive requests no Google permissions of its own during it.

  2. Drive scan (drive.metadata.readonly): Allows NeatDrive to list and read metadata about your files. Displayed by Google as "See information about your Google Drive files." We use this to generate your Drive health score and identify sharing or organisation issues. The scan itself does not access file content.

  3. Cleanup actions (drive): Requested only if you choose to apply a suggested cleanup action — for example removing a public sharing link, renaming a file, or moving one to your archive folder. Displayed by Google as "See, edit, create, and delete all of your Google Drive files." NeatDrive requests this only at the moment you apply a change, never during sign-in or scanning, and every change is previewed before it runs and recorded in Recent Changes.

 

NeatDrive complies with the Google API Services User Data Policy, including the Limited Use requirements. NeatDrive does not use Google user data to train generalized or personalized AI or ML models, does not sell it, does not use it for advertising, and does not transfer it except as needed to provide the feature you requested, for security, or to comply with law.


 

Optional Features and File Contents

 

Two features read file contents. Both require the optional write permission, operate only on files you explicitly select, and do not run as part of a standard scan. AI naming suggestions read roughly the first 2,000 characters of a file to suggest a clearer name. A content-based duplicate check downloads a file’s bytes to compute a SHA-256 hash in memory, then discards the bytes — they are never written, logged, or sent onward — and keeps only the hash. Duplicate detection, which runs automatically during a scan, does not read file contents; it uses the MD5 checksum Google supplies with the file’s metadata.

  • AI naming suggestions. For files you select, we extract a short text excerpt — approximately the first 2,000 characters — in order to suggest a clearer, more descriptive filename.

  • Duplicate verification. There are two modes. Duplicate detection, during a normal scan, compares the MD5 checksum Google supplies with the file’s metadata — we do not open or download the file. A content-based duplicate check, available only after you grant write access and only on files you select, downloads a file’s bytes to compute a SHA-256 hash in memory so we can confirm two files are genuinely identical; the bytes are discarded once the hash is computed and are never written, logged, or sent onward. In both modes we store only the checksum, never the file’s contents.


 

AI-Powered File Renaming (Optional Feature)

 

NeatDrive offers an optional AI file renaming feature. This section explains how it works and how your data is handled when you use it.

 

What it does. When enabled, the AI renaming feature analyzes your file names, folder structure, and a short excerpt of the contents of the files you select — and generates suggested alternative names based on detected patterns, naming conventions, and folder context. Suggestions are presented to you in the NeatDrive dashboard for review. No file is renamed unless you explicitly approve the suggestion for that file.

 

What data is used. The AI renaming feature uses file names and folder paths from your Google Drive metadata, and — for files you select — approximately the first 2,000 characters of the file's text, used only to generate a suggested name. Content is read only for the specific files you opt in to; it is not read during the standard metadata scan, and it is never used to train AI/ML models.

 

Third-party AI processing. To generate renaming suggestions, NeatDrive transmits the relevant file names and folder paths, and a short excerpt of the contents of the files you select, to a third-party AI service provider: Base44 (base44.com/privacy-policy). This provider processes that data solely for the purpose of generating those suggestions on NeatDrive's behalf. Base44 routes AI requests to third-party providers — currently Anthropic and OpenAI — whose own terms govern how long request data is retained for abuse monitoring. We are seeking written confirmation of those retention terms and will update this policy when we have it.

Content-based duplicate check — platform processing only. Where you run a content-based duplicate check, the files you select are downloaded and hashed on Base44's infrastructure, because NeatDrive is built on the Base44 platform. The bytes are not sent to an AI model and are discarded once the hash is computed. Automatic duplicate detection does not send file contents to any third party — it compares the MD5 checksum Google supplies as file metadata.

Our agreement with Base44 restricts them to using personal data only to provide the service. NeatDrive does not use your data to train AI models and does not instruct Base44 to do so.

 

No automatic changes. The AI renaming feature never applies changes automatically. Every suggestion requires your explicit individual approval before NeatDrive takes any action on your Drive.

 

How to enable or disable. The AI renaming feature is off by default. You can enable or disable it at any time in your NeatDrive account settings. Disabling the feature stops all AI processing of your file name metadata.

 

EU users — automated processing disclosure. In accordance with GDPR Art. 13(2)(f), NeatDrive discloses that the AI renaming feature involves automated processing of your file name metadata to generate name suggestions. This processing does not produce legal effects or significantly affect you. The logic used is: pattern recognition applied to file name structure and folder hierarchy to suggest standardized naming formats. You are not subject to any decision based solely on automated processing — all suggestions require your review and approval.


 

How We Use Your Data

 

We use the data we collect to:

  • Provide and operate the NeatDrive service (scanning, reporting, and generating recommendations)

  • Improve product performance, reliability, and user experience

  • Maintain security, prevent abuse, and troubleshoot issues

  • Communicate with you about service updates or support requests

 

We do not sell your data. We do not use it for advertising. We transfer it only to the processors named below.

 

NeatDrive does not use your data to train AI models. Our agreement with Base44 restricts them to using personal data only to provide the service. AI assistant messages are processed by third-party providers (Anthropic, Google, OpenAI) under their own terms; we have asked our platform provider to confirm in writing which provider serves our integration and whether zero-retention is enabled, and have not yet received that confirmation.


 

Legal Basis for Processing — EU/EEA Users (GDPR Art. 6)

 

If you are located in the European Economic Area or United Kingdom, we process your personal data on the following legal bases:

  • Account information (email, Google account ID): Performance of contract — Art. 6(1)(b). Necessary to create and manage your NeatDrive account.

  • Google Drive file metadata (file names, sizes, sharing settings, folder structure): Performance of contract — Art. 6(1)(b). Necessary to provide the scan, Health Score, and Action Plan you requested.

  • Write action logs and audit trail: Performance of contract — Art. 6(1)(b). Necessary to provide the cleanup service and support the reversibility and rollback features described under "Deletion, Reversibility, and Retention" below.

  • Usage and diagnostic data (pages visited, error logs, feature usage): Legitimate interests — Art. 6(1)(f). We have a legitimate interest in understanding how NeatDrive is used to improve reliability and user experience. This interest does not override your rights.

  • AI renaming — file contents submitted for processing: Consent — Art. 6(1)(a). This feature is off by default and requires your explicit opt-in. You may withdraw consent at any time by disabling the feature in account settings. Withdrawal does not affect the lawfulness of prior processing.


 

Where Your Data Is Stored

 

NeatDrive is built on Base44 (base44.com), a US-based application platform. Your account information and Drive metadata are stored on Base44's infrastructure, hosted in the United States.


 

Other Services We Use

 

In addition to Base44, which stores your account information and Drive metadata, the following third-party services process data when you use NeatDrive:

  • Wix, which hosts our marketing website and the NeatDrive application. Wix also maintains a CRM that holds the name, email address, and form-submission history of everyone who applies for early access or requests a demo — that is contact data, not technical usage data. Wix also routes our triggered email through its own email infrastructure.

  • SendGrid, which is Wix's email delivery provider rather than a service NeatDrive contracts with directly. Every triggered email Wix sends on our behalf passes through SendGrid, which embeds an open-tracking pixel and click-tracking wrappers in each message. These carry the recipient's Wix contact identifier and record whether the message was opened and which links were clicked. SendGrid receives the recipient's email address and engagement data; it does not receive the contents of your Google Drive.

  • Vercel, which hosts and delivers the application, and provides privacy-friendly page analytics. These analytics are cookieless, use no advertising or device identifiers, do not record your screen or session, and are not able to identify you individually.

  • Sentry, which collects crash and performance diagnostics so we can identify and fix errors.

  • Cloudflare Turnstile, which distinguishes real visitors from automated traffic at sign-in.

  • Base44's own sub-processors. Base44 engages its own sub-processors to run the platform, currently including MongoDB and Supabase (data storage), Render (servers), Google Cloud (analytics), Datadog (logging), SendGrid (email), and OpenAI and Anthropic (AI processing). Base44 is operated by Wix.com Ltd, which is also listed among its sub-processors. The current list is published at base44.com/dpa/exhibitc.

 

None of these services receive the contents of your Google Drive files. Base44, which does store your Drive metadata, is contractually restricted to using it only to provide the NeatDrive service.
 

International Data Transfers

 

NeatDrive is operated by NeatDrive LLC in the United States. If you are located in the European Economic Area or United Kingdom, your personal data is transferred to and processed in the United States.

 

We rely on the European Commission's Standard Contractual Clauses (SCCs) (Commission Implementing Decision 2021/914) as the legal mechanism for this transfer. We have entered into a Data Processing Agreement incorporating the SCCs with Base44, our application platform and data storage provider, which governs how your data is handled and protected in the United States.

 

For questions about our data transfer arrangements, contact help@neatdrive.net.


 

Deletion, Reversibility, and Retention

 

How long an action stays reversible depends on the action. Revoking a share or public link can be undone in NeatDrive for 30 days. Files removed as duplicates or clutter are moved to your Google Drive Trash, where NeatDrive can restore them for 30 days. Files that are archived rather than deleted are moved to a NeatDrive Archive folder in your own Drive, where they remain until you move or delete them; a cleanup applied as a quarantine batch can be rolled back for 30 days. Four actions cannot be undone by NeatDrive at all: emptying Trash from the Declutter page, removing your own access to a file someone else owns, transferring ownership once Google has reassigned the file, and deleting your NeatDrive Archive folder. Renaming a file cannot be reversed by NeatDrive either.

 

Please note that files in Trash continue to count against your Google storage quota until Trash is emptied. Storage is not reclaimed at the moment a file is trashed.

 

Two further actions are permanent and cannot be undone by NeatDrive or by you. Both require an explicit confirmation step before they run:

  • Emptying Trash from the Declutter page, which permanently deletes files you have already trashed and selected.

  • Deleting your NeatDrive Archive folder, which permanently removes the folder and everything inside it. This deletion bypasses Trash, so those files cannot be recovered from Trash afterwards.

 

Transferring ownership of a file also cannot be reversed by NeatDrive once Google has reassigned the file to the new owner.

 

Google Workspace administrators can request restoration of permanently deleted files for up to 25 days through the Google Admin console. This option is not available for personal Google accounts.

 

We retain your scan data and account information for as long as your account is active. If you disconnect a Google Drive from NeatDrive, all scan results, findings, and action plan items associated with that drive are permanently deleted. If you delete your account, all associated data is permanently deleted within 30 days.


 

Data Security

 

All data is encrypted in transit (TLS) and at rest. Authentication is handled entirely via Google OAuth 2.0 — we never store your Google password.


 

Your Rights

 

For all users:

 

You can:

  • Request access to the information we have about you

  • Request deletion of your account and associated data by emailing help@neatdrive.net, or delete your account directly from within the NeatDrive app

  • Disconnect Google Drive access at any time from the NeatDrive app (My Drives page) or by revoking access in your Google Account settings at myaccount.google.com/permissions

 

For EU/EEA and UK users (GDPR/UK GDPR):

 

You have the following additional rights under GDPR Art. 15–22:

  • Right of access (Art. 15): Request confirmation of whether we process your personal data and, if so, a copy of that data.

  • Right to rectification (Art. 16): Request correction of inaccurate personal data we hold about you.

  • Right to erasure (Art. 17): Request deletion of your personal data where it is no longer necessary for the purpose it was collected, or where you withdraw consent.

  • Right to restriction of processing (Art. 18): Request that we temporarily stop processing your data in certain circumstances — for example, while a correction request is under review.

  • Right to data portability (Art. 20): Request a copy of the personal data you provided to us in a structured, commonly used, machine-readable format (applies where processing is based on contract or consent).

  • Right to object (Art. 21): Object to processing based on our legitimate interests (Art. 6(1)(f)). We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.

  • Right to withdraw consent (Art. 7(3)): Where processing is based on your consent (e.g., the AI renaming feature), withdraw consent at any time without affecting the lawfulness of prior processing.

 

To exercise any of these rights, email help@neatdrive.net. We will respond within 30 days. We may ask you to verify your identity before processing your request.

 

Right to lodge a complaint (Art. 77): If you believe we have processed your personal data in violation of GDPR, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EU supervisory authorities is available at edpb.europa.eu/about-edpb/about-edpb/members_en. UK users may contact the Information Commissioner's Office (ICO) at ico.org.uk.


 

California Privacy Rights (CCPA/CPRA)

 

This section applies to California residents under the California Consumer Privacy Act (Cal. Civ. Code §1798.100 et seq.) and the California Privacy Rights Act.

 

Categories of personal information we collect:

  • Identifiers: Email address, Google account ID

  • Internet or other network activity: Pages visited in the NeatDrive app, features used, error log data

  • Commercial information: Subscription plan and purchase history

  • Inferences drawn from other data: Drive Health Score derived from your Drive metadata

 

We do not collect: Social Security numbers, financial account numbers, precise geolocation, biometric data, health information, or sensitive personal information as defined under CPRA.

 

We do not sell or share your personal information. NeatDrive does not sell your personal information to third parties. NeatDrive does not share your personal information for cross-context behavioral advertising. This applies to all users, including California residents.

 

Your California rights:

  • Right to know: You may request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months, the categories of sources, and the purposes for collection.

  • Right to delete: You may request deletion of your personal information. Certain exceptions apply (e.g., data needed to complete a transaction, detect security incidents, or comply with law).

  • Right to correct: You may request correction of inaccurate personal information.

  • Right to opt out of sale or sharing: Not applicable — we do not sell or share personal information.

  • Right to limit use of sensitive personal information: Not applicable — we do not collect sensitive personal information as defined under CPRA.

  • Right to non-discrimination: Exercising your privacy rights will not result in discriminatory treatment.

 

How to submit a request: Email help@neatdrive.net with the subject line "California Privacy Request." We will verify your identity and respond within 45 days (extendable by an additional 45 days where necessary).


 

Contact

 

Questions or data requests? Email us at help@neatdrive.net.

NeatDrive logo

Read-only by default. Preview-first workflows. Most actions reversible for 30 days.

© 2026 NeatDrive LLC. All rights reserved.

Contact

help@neatdrive.net

Call us: +1 (231) 681-8790

You'll be greeted by Alfred, NeatDrive's AI phone assistant. Alfred can answer questions and take your details; for anything it can't handle, it'll connect you with our team by email. Please don't share passwords or payment information over the phone.

Also available from the Google Workspace Marketplace

Google Workspace Marketplace and the Google Workspace Marketplace logo are trademarks of Google LLC. Google Drive is a trademark of Google LLC.

bottom of page

NeatDrive is in early access — read-only by default, nothing changes until you approve it. 60 days of Pro free, limited to the first 20 people.

Get early access →
Launching soon on NxGn Tools