Privacy Policy
Last updated: June 26, 2026
1. Overview & Commitment to Privacy
StorageOptimizer ("we," "our," or "the Application") is committed to protecting your privacy. This policy outlines how we access, process, use, store, and handle your information, specifically regarding data accessed via third-party integrations, including Google and Dropbox API Services.
2. Third-Party API OAuth Scopes & Data Accessed
To provide storage optimization and duplicate identification features, our application requests access to specific cloud storage services via secure OAuth consent screens. The scopes we request are:
Google API Scopes:
- openid / email / profile: Standard scopes used to authenticate your session via NextAuth and display your basic profile details on the user dashboard.
- https://www.googleapis.com/auth/photospicker.mediaitems.readonly: Read-only access to media items. We access photo/video metadata (filenames, file sizes, creation times, pixel dimensions, and media formats) from your Google Photos library.
- https://www.googleapis.com/auth/drive: Access to view your files and perform file management operations (such as moving files to Trash) only when requested by you. We access file metadata (filenames, paths, creation/modification dates, file sizes, parent directory ids, and MD5 hashes) and require permission to execute file deletion or moving operations.
Dropbox API Scopes:
- account_info.read: Used to access basic profile details (like display name and email address) to set up your session.
- files.metadata.read & files.metadata.write: Used to view and scan metadata of files (such as file names, sizes, creation/modification times, paths, and hashes) to identify duplicate files.
- files.content.read & files.content.write: Access to read and write files in your Dropbox account. This is used strictly to download file contents locally for byte-level comparison if needed, and to perform file management operations (such as moving duplicate files to the Dropbox Trash folder or deleting them) only when requested by you.
3. Purpose & How We Use Your Data
We access and process your Google and Dropbox User Data strictly to deliver and improve core application functionality:
- Identifying Duplicate Items: The Application compares file names, creation dates, dimensions, hashes, and sizes to automatically detect duplicates across your photos, videos, and cloud drives.
- Executing User Actions: Deletion and trashing operations are executed directly against the Google or Dropbox APIs upon your explicit command. We move files you select into your provider-managed "Trash" or "Bin" folder, ensuring you maintain final control over actual deletion.
We do not permanently store, retain, or copy your file contents to our servers. File contents are accessed only as necessary to perform operations you explicitly request.
4. Data Processing, Storage, & Retention
- Local Processing: Where possible, duplicate detection is performed locally within your browser. Some metadata necessary to provide reports, maintain scan history, or execute requested operations may be processed by our servers.
- Transient Token Handling: Your integration credentials (access and refresh tokens) are encrypted and stored in transient, secure session cookies. They are not stored in our persistent application database and are securely deleted after your session expires or you sign out.
- Scan Result Metadata: Temporary scan results (metadata of identified duplicates) are saved in our database only to display reports on your console. You can permanently delete this scan history at any time by clicking "Clear Scan History" in your dashboard.
- Data Security Measures: We use industry-standard security measures, including encrypted HTTPS communications, encrypted token storage, and access controls designed to protect your information. While no system can guarantee absolute security, we take reasonable measures to safeguard your data.
5. Strict Data Sharing & Google Limited Use Disclosure
We maintain strict controls over data sharing:
- We do not sell, rent, lease, trade, or share your Google or Dropbox user data or metadata with third-party networks, data brokers, or advertisers.
- We do not use your user data to serve personalized ads, target ads, or compile marketing profiles.
- We do not use your user data to train machine learning models or general AI systems.
- We rely on third-party service providers, such as Google, Dropbox, authentication providers, hosting providers, and cloud infrastructure services, to operate the Application. These providers process data only as necessary to deliver their services.
StorageOptimizer's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. User Access Revocation & Deletion
You have full control over the permissions granted to StorageOptimizer. You can disconnect or completely revoke the Application's access permissions to your Google account at any time through the Google Account Security Settings Page, and to your Dropbox account through the Dropbox Account App Permissions Page.
7. Contact Info
If you have questions about this Privacy Policy or wish to request immediate manual data purging of any profile elements, please contact us at: hasimax.help@gmail.com.