Privacy Policy

Effective date: June 24, 2026

This Privacy Policy describes how Overdrive Tools ("Overdrive", "we", "our", or "us") collects, uses, stores, and shares information when you use the Overdrive Workspace service — a read-only Google Workspace™ Drive™ exposure audit tool for Workspace administrators.

1. Google API Limited Use Disclosure

Overdrive's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In accordance with Limited Use, Overdrive:

  • Uses Google user data only to provide and improve the Overdrive Workspace service.
  • Does not transfer Google user data to third parties except as necessary to provide and improve the service, as required by law, or with your consent.
  • Does not use Google user data for advertising or to train AI or ML models.
  • Does not allow humans to read Google user data except as needed to provide the service, investigate security issues, or comply with applicable law — and only after obtaining your consent when feasible.
  • Does not sell Google user data.

2. Google Data We Access

Overdrive connects to Google APIs using OAuth 2.0. The following scopes are requested from the authorizing Workspace administrator. We request the minimum scopes needed for the audit service.

Identity (always requested)
openid / email / profile

Authenticates the administrator's Google Account and identifies them within Overdrive.

Read-only audit scopes (requested on Workspace connection)
admin.reports.audit.readonly

Reads Google Workspace™ audit log events — specifically Drive™ sharing events and OAuth application authorization events — to detect external exposure and third-party app grants. We never access audit events for Gmail™, Calendar, or other Google services beyond Drive and token events.

admin.directory.user.readonly

Reads Workspace user directory: names, email addresses, organizational units, 2-step verification status, and account suspension status. Used to classify internal vs. external principals and to identify exposure by suspended or departed users.

admin.directory.domain.readonly

Reads the verified domains registered to the Workspace organization. Used to classify sharing recipients as internal or external.

Remediation scopes (not yet released — requested only if you enable optional remediation)
drive (full Drive access)

NOT CURRENTLY REQUESTED. This scope would be added only if you explicitly enable the optional remediation feature, which allows removing specific external permissions on files you select. It will be requested separately with a clear explanation. The current audit product never requests this scope.

The following is explicitly never accessed: file contents, email messages, calendar events, contacts, or any data not described above.

3. How We Use Google Data

We use Google user data exclusively to:

  • Authenticate Workspace administrator accounts.
  • Process audit log events to derive exposure findings (external shares, public links, OAuth app grants).
  • Classify sharing principals as internal or external using your verified domains.
  • Aggregate risk signals per internal user, file, domain, and shared drive.
  • Present findings in the Overdrive Workspace dashboard and reports.
  • Investigate support issues and security incidents where you request our assistance.

We do not use Google user data to train machine-learning models, serve advertising, or for any purpose beyond operating and improving the Overdrive Workspace service.

4. Data We Store

What we persist

Overdrive applies a "scan broadly, store narrowly" principle. We store only derived findings and aggregates — never raw audit logs.

  • Workspace record — organization name, verified domains, OAuth connection status.
  • Scan summaries — metadata about each audit scan (time, scope, totals).
  • Risky file findings — file ID, title, sharing type, external principals, and risk score for files that have external or public exposure.
  • External principals — email addresses or domains of external sharing recipients.
  • User risk aggregates — per-internal-user exposure counts and risk scores.
  • OAuth refresh token — encrypted at rest, stored server-side only, never exposed to the browser. Used to call Google APIs on your behalf.

What we do not persist

  • Raw Google audit log events — processed transiently and discarded. Google's audit log remains the system of record.
  • Any file contents.
  • Private, internal-only files with no external exposure.
  • Full directory snapshots — only the data necessary to classify sharing recipients.

Storage and security

All derived data is stored encrypted at rest and in transit. Data is tenant-isolated by workspace: no workspace can access another workspace's data. Infrastructure is hosted on Supabase (EU Central — Frankfurt, Germany) and Vercel. See Section 7 (Sub-processors) for details.

5. Data Sharing

We do not sell, rent, or trade your data. We share data only:

  • With sub-processors listed in Section 7, who process data on our behalf under appropriate agreements.
  • As required by law — in response to lawful requests from courts or governmental authorities.
  • To protect rights — where reasonably necessary to enforce our Terms, prevent fraud, or protect the safety of users.
  • With your consent — for any other purpose with your explicit consent.

Google user data is never shared with third parties for advertising or any purpose unrelated to providing the Overdrive Workspace service.

6. Retention and Deletion

Scan findings and derived data are retained for as long as your workspace remains connected to Overdrive, or until you request deletion.

When you disconnect your workspace or delete your account:

  • Your OAuth refresh token is immediately revoked and deleted from our systems.
  • All derived findings, aggregates, and workspace records are deleted within 30 days.
  • Anonymized aggregate statistics that cannot be tied back to your organization may be retained for product improvement.

You may also request deletion of your data at any time by contacting us at info@overdrive.tools.

7. Sub-processors

We use the following sub-processors to operate the service. All sub-processors are bound by data processing agreements. We will update this list when sub-processors change and will provide notice consistent with our Terms of Service.

Sub-processorPurposeLocation
Supabase, Inc.Database (PostgreSQL), auth, storageEU Central — Frankfurt, Germany
Vercel, Inc.Application hosting, serverless functionsUnited States (edge globally)
Google LLCGoogle APIs (data source); Google Cloud Platform™ for OAuthUnited States
Lemon Squeezy (LemonSqueezy, LLC)Payment processing and subscription billing (Merchant of Record)United States

8. GDPR and International Data Transfers

Controller / Processor roles

Overdrive Tools acts as the data controller for Workspace administrator account data (name, email) and as a data processor on behalf of your organization for Google Workspace user data accessed via the integration. Your organization is the data controller for that user data.

Lawful basis

Processing of administrator account data is based on contract performance (providing the service you signed up for). Processing of Workspace data via the Google API integration is based on your organization's consent given during the OAuth authorization flow.

Data subject rights

If you are in the European Economic Area, United Kingdom, or another jurisdiction with applicable data-protection law, you may have rights including: access, rectification, erasure, restriction of processing, data portability, and the right to object. To exercise these rights, contact us at info@overdrive.tools.

International transfers

Derived data is stored in Supabase's EU Central region (Frankfurt, Germany). Overdrive Tools is headquartered in Israel, which the European Commission has recognised as providing an adequate level of data protection (EU adequacy decision). Accordingly, transfers from the EEA to Israel are permitted without additional safeguards. Transfers to Vercel and other sub-processors in the United States are governed by standard contractual clauses or equivalent approved mechanisms.

Data Processing Agreement

If your organization requires a Data Processing Agreement (DPA) for GDPR compliance, contact us at info@overdrive.tools.

Supervisory authority

You have the right to lodge a complaint with your local supervisory authority if you believe we have processed your personal data unlawfully.

9. Security

We implement technical and organizational measures to protect your data, including encryption at rest and in transit, tenant isolation, access controls, and secrets management. OAuth refresh tokens are stored server-side only, encrypted at rest, and never transmitted to the browser.

No transmission over the internet is completely secure, and we cannot guarantee the absolute security of your data. If you believe a security incident has occurred, contact us immediately at info@overdrive.tools.

10. Children's Privacy

Overdrive Workspace is a business-to-business service intended for use by Workspace administrators. It is not directed to children under 13. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Effective date" at the top and, for material changes, notify connected workspace administrators via email or an in-app notice. Continued use of the service after notice constitutes acceptance of the updated policy.

12. Contact

For privacy inquiries, data subject requests, or to obtain a Data Processing Agreement:

Overdrive Tools
45 Rothschild Blvd., Tel Aviv, Israel