Privacy Policy
last updated 2026-01-01
What we store
ODrive is a control plane for storage you already own. We store your account email, workspace settings, drive configuration, file metadata (names, paths, sizes, timestamps) and operational logs. Provider credentials are encrypted with AES-GCM envelope encryption before they are persisted, and are only decrypted inside a server-side operation.
What we never store
- File contents — transfers stream through and are not retained.
- Plaintext credentials, tokens, or share passwords (hashed with PBKDF2).
- Raw IP addresses in share access logs — they are salted and hashed.
Third-party providers
When you connect a drive, ODrive acts on your behalf against that provider using the scopes you granted. Their handling of your files is governed by their own policy. You can revoke a connection at any time from Drives, which deletes the stored credential immediately.
Retention
Operational logs are retained for 30 days, share access logs for 90 days, and trashed metadata for the retention window configured in your workspace settings. Deleting your workspace deletes all associated records.
Contact
Privacy requests: privacy@odrive.app.