Privacy Policy
Effective date: June 24, 2026
This Privacy Policy describes how Overdrive Tools ("Overdrive", "we", "our", or "us") collects, uses, stores, and shares information when you use the Overdrive Workspace service — a read-only Google Workspace™ Drive™ exposure audit tool for Workspace administrators.
1. Google API Limited Use Disclosure
Overdrive's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In accordance with Limited Use, Overdrive:
- Uses Google user data only to provide and improve the Overdrive Workspace service.
- Does not transfer Google user data to third parties except as necessary to provide and improve the service, as required by law, or with your consent.
- Does not use Google user data for advertising or to train AI or ML models.
- Does not allow humans to read Google user data except as needed to provide the service, investigate security issues, or comply with applicable law — and only after obtaining your consent when feasible.
- Does not sell Google user data.
2. Google Data We Access
Overdrive connects to Google APIs using OAuth 2.0. The following scopes are requested from the authorizing Workspace administrator. We request the minimum scopes needed for the audit service.
openid / email / profileAuthenticates the administrator's Google Account and identifies them within Overdrive.
admin.reports.audit.readonlyReads Google Workspace™ audit log events — specifically Drive™ sharing events and OAuth application authorization events — to detect external exposure and third-party app grants. We never access audit events for Gmail™, Calendar, or other Google services beyond Drive and token events.
admin.directory.user.readonlyReads Workspace user directory: names, email addresses, organizational units, 2-step verification status, and account suspension status. Used to classify internal vs. external principals and to identify exposure by suspended or departed users.
admin.directory.domain.readonlyReads the verified domains registered to the Workspace organization. Used to classify sharing recipients as internal or external.
drive (full Drive access)NOT CURRENTLY REQUESTED. This scope would be added only if you explicitly enable the optional remediation feature, which allows removing specific external permissions on files you select. It will be requested separately with a clear explanation. The current audit product never requests this scope.
The following is explicitly never accessed: file contents, email messages, calendar events, contacts, or any data not described above.
3. How We Use Google Data
We use Google user data exclusively to:
- Authenticate Workspace administrator accounts.
- Process audit log events to derive exposure findings (external shares, public links, OAuth app grants).
- Classify sharing principals as internal or external using your verified domains.
- Aggregate risk signals per internal user, file, domain, and shared drive.
- Present findings in the Overdrive Workspace dashboard and reports.
- Investigate support issues and security incidents where you request our assistance.
We do not use Google user data to train machine-learning models, serve advertising, or for any purpose beyond operating and improving the Overdrive Workspace service.
4. Data We Store
What we persist
Overdrive applies a "scan broadly, store narrowly" principle. We store only derived findings and aggregates — never raw audit logs.
- Workspace record — organization name, verified domains, OAuth connection status.
- Scan summaries — metadata about each audit scan (time, scope, totals).
- Risky file findings — file ID, title, sharing type, external principals, and risk score for files that have external or public exposure.
- External principals — email addresses or domains of external sharing recipients.
- User risk aggregates — per-internal-user exposure counts and risk scores.
- OAuth refresh token — encrypted at rest, stored server-side only, never exposed to the browser. Used to call Google APIs on your behalf.
What we do not persist
- Raw Google audit log events — processed transiently and discarded. Google's audit log remains the system of record.
- Any file contents.
- Private, internal-only files with no external exposure.
- Full directory snapshots — only the data necessary to classify sharing recipients.
Storage and security
All derived data is stored encrypted at rest and in transit. Data is tenant-isolated by workspace: no workspace can access another workspace's data. Infrastructure is hosted on Supabase (EU Central — Frankfurt, Germany) and Vercel. See Section 7 (Sub-processors) for details.
6. Retention and Deletion
Scan findings and derived data are retained for as long as your workspace remains connected to Overdrive, or until you request deletion.
When you disconnect your workspace or delete your account:
- Your OAuth refresh token is immediately revoked and deleted from our systems.
- All derived findings, aggregates, and workspace records are deleted within 30 days.
- Anonymized aggregate statistics that cannot be tied back to your organization may be retained for product improvement.
You may also request deletion of your data at any time by contacting us at info@overdrive.tools.
7. Sub-processors
We use the following sub-processors to operate the service. All sub-processors are bound by data processing agreements. We will update this list when sub-processors change and will provide notice consistent with our Terms of Service.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database (PostgreSQL), auth, storage | EU Central — Frankfurt, Germany |
| Vercel, Inc. | Application hosting, serverless functions | United States (edge globally) |
| Google LLC | Google APIs (data source); Google Cloud Platform™ for OAuth | United States |
| Lemon Squeezy (LemonSqueezy, LLC) | Payment processing and subscription billing (Merchant of Record) | United States |
8. GDPR and International Data Transfers
Controller / Processor roles
Overdrive Tools acts as the data controller for Workspace administrator account data (name, email) and as a data processor on behalf of your organization for Google Workspace user data accessed via the integration. Your organization is the data controller for that user data.
Lawful basis
Processing of administrator account data is based on contract performance (providing the service you signed up for). Processing of Workspace data via the Google API integration is based on your organization's consent given during the OAuth authorization flow.
Data subject rights
If you are in the European Economic Area, United Kingdom, or another jurisdiction with applicable data-protection law, you may have rights including: access, rectification, erasure, restriction of processing, data portability, and the right to object. To exercise these rights, contact us at info@overdrive.tools.
International transfers
Derived data is stored in Supabase's EU Central region (Frankfurt, Germany). Overdrive Tools is headquartered in Israel, which the European Commission has recognised as providing an adequate level of data protection (EU adequacy decision). Accordingly, transfers from the EEA to Israel are permitted without additional safeguards. Transfers to Vercel and other sub-processors in the United States are governed by standard contractual clauses or equivalent approved mechanisms.
Data Processing Agreement
If your organization requires a Data Processing Agreement (DPA) for GDPR compliance, contact us at info@overdrive.tools.
Supervisory authority
You have the right to lodge a complaint with your local supervisory authority if you believe we have processed your personal data unlawfully.
9. Security
We implement technical and organizational measures to protect your data, including encryption at rest and in transit, tenant isolation, access controls, and secrets management. OAuth refresh tokens are stored server-side only, encrypted at rest, and never transmitted to the browser.
No transmission over the internet is completely secure, and we cannot guarantee the absolute security of your data. If you believe a security incident has occurred, contact us immediately at info@overdrive.tools.
10. Children's Privacy
Overdrive Workspace is a business-to-business service intended for use by Workspace administrators. It is not directed to children under 13. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Effective date" at the top and, for material changes, notify connected workspace administrators via email or an in-app notice. Continued use of the service after notice constitutes acceptance of the updated policy.
12. Contact
For privacy inquiries, data subject requests, or to obtain a Data Processing Agreement: