
Security & Privacy
How NeatDrive protects your data — and, just as importantly, what it can and cannot do to your Drive.
Independently security assessed
Verified by a Google-authorized third-party lab under the CASA framework.
NeatDrive has completed a Cloud Application Security Assessment (CASA) by a Google-authorized independent lab. Google requires this of every application that requests restricted Google Drive scopes, and it must be renewed annually. The assessment covers access control, application architecture, threat modelling, data protection and error handling — and confirms we can securely handle your data and delete it on request.
CASA is administered by the App Defense Alliance and built on the OWASP Application Security Verification Standard.
What NeatDrive can access
NeatDrive operates in read-only mode unless you explicitly authorize write access.
Phase 0 — Sign-in (required)
You sign in to NeatDrive through Base44, our platform provider, using your Google account. This authenticates you and grants NeatDrive no Google Drive access at all — no Drive scopes are requested until you explicitly connect your Drive in the next step.
Phase 1 — Read-only (default)
By default NeatDrive holds only the drive.metadata.readonly scope. With that scope alone we can read file metadata — names, types, sizes, dates, ownership, folder paths and sharing settings — and nothing else. We cannot read file contents, and we cannot create, edit, move or delete anything.
Phase 2 — Write access (optional, separate consent)
Cleanup actions need the full drive scope, because they act on files you already own that NeatDrive did not create — no narrower Google scope can reach those. Granting it lets NeatDrive rename files, move them into your NeatDrive Archive folder, send duplicates to your Google Drive Trash, revoke risky shares, and transfer ownership.
Worth being plain about: this grant gives NeatDrive the ability to read your files. What stops it is how NeatDrive is built, not what Google permits.
Turn write access off at any time in Settings and NeatDrive can no longer modify your files. To also remove the permission from your Google Account, revoke it at myaccount.google.com/permissions.
Nothing changes until you approve it
Actions are preview-first and applied only to items you approve.
Archived files are moved to a NeatDrive Archive folder in your own Drive rather than deleted, so you can move them back yourself at any time, and a whole cleanup batch can be rolled back from the Archived Files page for 30 days. Revoked shares are recorded so you can see exactly what was removed.
What cannot be undone
Some actions cannot be undone by NeatDrive:
-
Emptying Trash from the Declutter page — this permanently deletes files you have already trashed and selected.
-
Removing your own access to a file someone else owns — only that owner can share it back with you.
-
Transferring ownership — final once Google has reassigned the file.
Each of those tells you so on the confirmation screen before you approve it.
Deleting your NeatDrive Archive folder is irreversible too, but you do that in Google Drive rather than in NeatDrive.
What we do with your data
Metadata by default
A NeatDrive audit analyzes file metadata — names, sizes, types, dates, ownership, folder paths and sharing status. It does not open your files.
Finding duplicates
Exact-duplicate detection runs as part of every scan and does not open your files. It compares the MD5 checksum that Google already stores alongside each file as metadata; two files with the same checksum have the same contents. We store that checksum — a content fingerprint, not the content itself.
Comparing files that are similar but not identical is a separate, on-demand feature. It downloads file contents, and only for the specific files you select and run it on.
Content-aware naming
Our content-aware naming suggestions read file contents. This is opt-in, requires write access, and runs only on files you explicitly select.
Third-party processing
NeatDrive does not sell your Drive data, share it with data brokers or advertisers, or use it to train AI models. No NeatDrive code path sends your Drive data to any third party other than Base44 — our infrastructure and AI provider, described below — and any export you generate yourself.
To power specific features, limited data is processed by Base44:
-
File names and folder paths are stored in Base44's database as part of your scan results, and are sent to its language model to generate organization and naming suggestions.
-
A short excerpt of file content is sent to its language model only for AI renaming — an opt-in feature that requires write access and runs only on files you explicitly select. Excerpts are capped at 2,000 characters or 50 KB per file.
-
Content-based duplicate check — where you run a content-based duplicate check, the files you select are downloaded and hashed on Base44's infrastructure, because NeatDrive is built on the Base44 platform. The bytes are not sent to an AI model and are discarded once the hash is computed.
-
MD5 checksums are read from the metadata Google already stores and kept alongside your scan results. NeatDrive does not compute them from your file contents. Automatic duplicate detection does not send file contents to any third party.
Model calls are inference only. Nothing NeatDrive sends is used to train a model.
Base44's own handling of the data it processes is governed by its terms as our subprocessor.
Data retention
Scan results and their associated records are retained according to your plan: 30 days on Free, 90 days on Pro, one year on Team and Firmwide, and indefinitely on Enterprise. A daily job deletes scans past your retention window; for Enterprise workspaces no deletion job runs at all.
Two things extend retention in your favour. If a longer retention period is set on your workspace, the longer of the two applies. And your window follows the highest plan tier you have ever held — move from Pro down to Free and your scans are kept for 90 days, not 30.
Retention governs scan results and the records attached to them. It does not remove your workspace, your account, or data held outside a scan. Those are deleted only when you delete all workspace data from inside NeatDrive, or delete your account.
Deleting your data
You can permanently delete all of your NeatDrive workspace data — scans, findings, batches and audit logs — at any time from the Security & Privacy page inside NeatDrive. Your Google Drive files and your Google account are not affected.
Read the full Privacy Policy and Terms of Service.
