Privacy Policy
Effective Date: August 22, 2026 · Governing Law: People's Republic of Bangladesh
1. Introduction
DixDrive ("we," "us," or "our") provides a multi-cloud storage control plane that enables users to connect and manage their existing third-party cloud storage accounts (Google Drive, Microsoft OneDrive, Dropbox, and Box) from a single unified interface. We are dedicated to uncompromising data transparency, privacy, and security.
This Privacy Policy explains what information we collect, how it is processed, how security is enforced, and how you can exercise control or complete deletion of your data when using the DixDrive website, web application, mobile clients, and related services.
2. Information We Collect & Purpose
Identity & Account Information: DixDrive utilizes Google Sign-In exclusively for authentication. We collect your Google email address, verified account name, profile avatar, and unique Google account subject ID. We do not utilize, request, or store passwords or email OTP credentials. This data is used solely to authenticate your identity and maintain your personal control plane session.
Third-Party Provider OAuth Credentials: When you explicitly connect a cloud storage provider (Google Drive, OneDrive, Dropbox, or Box), we receive OAuth 2.0 access and refresh tokens. All tokens are encrypted at rest using industry-standard AES-256 cryptography. Raw provider credentials and access tokens are never transmitted to or exposed within client browsers or mobile clients.
Storage & File Metadata: DixDrive indexes file and folder metadata, which includes: file names, file sizes, MIME types, provider-assigned file IDs, virtual folder paths, creation/modification timestamps, checksum hashes, and sync state. This metadata is processed exclusively to provide unified file browsing, cross-cloud search, folder organization, storage health analytics, and upload routing.
System Diagnostics & Telemetry: Non-identifying operational metrics, including anonymized client device type, OS version, sync latency, and timestamped error reports, used to ensure reliable background change-feed synchronization and prevent platform abuse.
3. Architecture & Zero Persistent File Storage
Metadata-Only Management: DixDrive functions as a control plane. We store file metadata rather than persistent file content. Your actual files remain stored within your underlying cloud accounts.
Direct-to-Provider File Transfers: Where supported by the underlying cloud provider, file bytes travel directly between your device and your cloud storage provider via direct, resumable transfer sessions.
Transient In-Memory Streaming Fallback: For operations where a third-party provider does not support direct browser-to-cloud transfers, data may temporarily stream in-memory through the DixDrive API as a real-time transit pipeline. File content is never written to disk, persisted to object storage, or cached permanently on DixDrive servers.
No Human Inspection of File Content: No employee, contractor, or automated crawler at DixDrive inspects, analyzes, or reads the contents of your personal files. Access to metadata occurs strictly through automated routines explicitly initiated by your commands.
4. Google API Services User Data Policy Compliance
DixDrive's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google OAuth Scopes Requested:
openid, email, profile—Identity Scope: Used solely to sign you into your DixDrive account and verify your identity with passwordless security.https://www.googleapis.com/auth/drive— Storage Scope: Used solely upon your explicit instruction when connecting Google Drive as a storage destination. Allows DixDrive to index file metadata (names, sizes, types, timestamps, folder hierarchy), enable cross-cloud search, and facilitate user-directed file management (uploads, downloads, renaming, moving, and folder organization) directly to and from your Google Drive account.
Limited Use Commitments:
- No Transfer for Advertising: We never transfer, disclose, or sell Google user data or associated metadata to advertising platforms, data brokers, or information resellers.
- No AI / ML Model Training: Google user data and file metadata are never used to train, retrain, or fine-tune artificial intelligence or machine learning models.
- No Human Review: No human is permitted to read or view Google user data, unless: (a) you have given explicit affirmative agreement for specific technical troubleshooting; (b) it is required for security investigations regarding platform abuse; or (c) it is necessary to comply with applicable law.
- Strict Scope Separation: Signing in with Google does not grant access to your Google Drive files. Google Drive storage access requires a separate, explicit OAuth authorization step.
5. Cookies & Local Client Storage
DixDrive utilizes minimal client-side storage technologies:
Session Authentication Cookies: Secure, HTTP-only session cookies required to keep you securely signed in to the web dashboard.
Local Browser Storage & IndexedDB: Used on your local device to cache folder hierarchies and upload queue states, enabling instantaneous UI navigation and smooth resumable file transfers.
6. Data Sharing & Sub-processors
We do not sell, rent, monetize, or trade your personal data. Data is shared exclusively with necessary, vetted infrastructure service providers:
Infrastructure Sub-processors: Cloud database and serverless hosting for encrypted account metadata storage; official bKash Merchant Payment Gateway for yearly subscription processing; and aggregated telemetry monitoring for error diagnostics.
Legal Disclosures: We may disclose metadata if legally mandated by a valid subpoena, court order, or enforceable governmental request under applicable laws within Bangladesh.
7. Data Security Safeguards
AES-256 Encryption at Rest: All OAuth access tokens, refresh tokens, and sensitive account credentials stored in our database are encrypted with AES-256 encryption.
TLS 1.3 Encryption in Transit: All communications between your browser or mobile device, DixDrive servers, and third-party storage APIs are enforced with TLS 1.3 / HTTPS encryption.
8. Data Retention, Disconnection & Deletion Rights
Disconnecting a Cloud Account: You can disconnect any linked cloud provider at any time from the Cloud Manager. Disconnecting immediately purges the provider's OAuth credentials, refresh tokens, and indexed file metadata from DixDrive. Your actual files in Google Drive, OneDrive, Dropbox, or Box remain completely untouched.
Complete Account Deletion: You have the right to delete your DixDrive account at any time via Account Settings or by emailing [email protected]. Upon account deletion, all user profile records, encrypted tokens, and metadata catalogs are permanently and irreversibly deleted from active production databases within 30 days.
9. International Privacy & User Rights
User Rights (GDPR & CCPA/CPRA): Regardless of your location, you have the right to access the metadata associated with your account, request rectification of inaccurate data, export your metadata, object to or restrict processing, and request complete deletion. We do not sell or share personal information under California Consumer Privacy Act definitions.
10. Contact Us
For questions, privacy inquiries, or data deletion requests, contact our privacy team:
DixDrive Privacy & Legal Operations
Email: [email protected] / [email protected]
Website: https://dixdrive.com
Location: Dhaka, Bangladesh