Last updated: 11 September 2026
DriveMesh is a private, personal-use application that lets its operator manage files across their own Google Drive accounts from a single interface. It is not offered as a commercial service and is not available to the general public.
This policy explains exactly what Google user data DriveMesh accesses, how that data is used, where it is stored, and how it can be removed.
When you connect a Google account, DriveMesh requests the following permissions:
auth/drive) — to list, search, move, rename, trash and delete files and folders in that account.openid, userinfo.email) — used only to label which connected account is which in the interface.In practice, DriveMesh reads file metadata: names, IDs, MIME types, sizes, creation and modification dates, folder relationships and trash status. It does not open, download, read or analyse the contents of your documents, images or other files.
File metadata is used solely to display your files in the interface and to carry out actions you explicitly request — running a search, moving an item to a folder, sending something to Trash, or deleting it permanently.
DriveMesh performs no background scanning, no indexing for other purposes, no advertising, no profiling, and no automated processing of your data. Nothing happens that you did not initiate.
Access tokens are cached temporarily and expire within an hour. File contents are never stored. File metadata is fetched live from Google's API when you use the app and is not retained on the server afterwards.
Google user data obtained through DriveMesh is not sold, rented, shared, transferred or disclosed to any third party. There are no analytics providers, advertising networks, or external processors involved. Data moves between your browser, the DriveMesh backend, and Google's APIs — nowhere else.
DriveMesh's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
You can disconnect any account from within DriveMesh, which immediately deletes its stored refresh token and email address from the database.
You can also revoke DriveMesh's access at any time from your Google Account permissions page. Revoking access invalidates the stored token instantly, and DriveMesh loses all ability to reach that account.
To request deletion of all stored data, contact the address below.
Refresh tokens are encrypted before being written to the database. The application itself sits behind password authentication, secrets are held in Cloudflare's encrypted secret storage, and all traffic is served over HTTPS. No credentials or tokens are ever exposed to the browser.
If this policy changes, the revised version will be published on this page with an updated date.
Questions about this policy or about data handling: xpravan2@gmail.com