Your files. Your choices.
Privacy Policy
Last updated: 25 September 2026
Uploadock helps people collect files in Google Drive. File contents travel directly from the sender’s browser to Google; Uploadock processes the information needed to arrange that transfer.
1. Who operates Uploadock
Uploadock is operated by [Operator legal name], at [Business/contact address and country]. For privacy, support, or abuse reports, contact [Public support and privacy email].
This policy covers folder owners and guests using Uploadock. The receiving folder owner separately decides why they collect your files, who may access them, and how long to keep them. Ask that owner about their handling of your uploaded content.
2. Information we handle
- Owner accounts: a Google account identifier, internal account identifier, timestamps, and login sessions. Google sign-in requests basic identity information; our account database does not retain your Google profile photo, name, or email.
- Drive connection: encrypted Google refresh credentials, granted permissions, and connection timestamps. Short-lived access credentials are used to contact Google and operate the owner’s folder picker.
- Upload requests: the destination folder identifier, title, instructions, availability, expiry, protected link credentials, and a password hash if a password is set. Request titles and instructions are visible to people with the link.
- Transfer setup: filenames, declared file sizes, file types, and Google upload session addresses are processed temporarily to initiate transfers. Folder names and available location information may be retrieved to help owners choose a destination. We do not keep a permanent file inventory or upload-completion history in our database.
- Service protection: network requests include an IP address and ordinary connection information. Abuse controls use temporary pseudonymous counters derived from IP addresses and request/account identifiers. These are not anonymous data.
- Support: if you contact us, we receive the information you choose to provide. Do not send passwords, Google credentials, or sensitive files in a support report.
3. Files and recipients
Uploadock’s application server does not receive or store uploaded file contents. Google receives the contents, filenames, and transfer information, and stores files in the connected owner’s Drive. Access after upload depends on that owner’s Google Drive sharing settings. Guests cannot browse the destination or other guests’ files through Uploadock.
Only upload files you intend to give to the recipient. Uploadock does not provide end-to-end encryption, inspect file contents, or scan uploads for malware.
4. Why we use this information
We use information to sign owners in, connect their Drive, manage upload requests, initiate guest transfers, prevent abuse, troubleshoot the service, and respond to support or legal requests. Where applicable data-protection law requires a legal basis, these activities rely on providing the requested service, legitimate interests in security and reliability, legal obligations, or consent where required. Google authorization can be withdrawn at any time.
5. Google permissions and data use
We request limited per-file Google Drive access using drive.file, rather than access to your entire Drive. This permission can allow more than uploads on files authorized for the app; Uploadock limits guests to initiating new uploads into the owner’s configured destination.
We use Google data only to operate and support the features described here. We do not sell Google user data, use it for advertising, or use it to train generalized AI models. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements where applicable.
Google handles data under its own Privacy Policy. Service providers running our hosting, database, and backups may process the application data needed to operate Uploadock. We may disclose necessary information to comply with law or address security and abuse.
6. Cookies and browser storage
We use an essential session cookie for owner login and temporary state for authorization flows. The guest browser may keep filenames, sizes, progress, and sensitive upload-session addresses in tab-scoped session storage to support recovery after a reload. Recovery records have a 24-hour application validity window and are removed when processed as completed, cancelled, or expired; browser cleanup timing may vary. Closing the tab or clearing site data can remove recovery information.
When enabled, we use Google Analytics 4 to measure visits to public pages and clicks on the create-link action after you accept analytics. Google may receive cookie identifiers, page and event information, browser/device information, and network connection information. Your choice is stored in your browser. Declining optional analytics does not prevent use of Uploadock. Google sign-in and Picker separately use Google services that may have their own storage behavior.
Error diagnostics and analytics controls
When enabled, Sentry receives technical error reports to help us diagnose software failures. Reports can include error descriptions, application stack traces, release and environment information, and browser/runtime details. A browser connecting directly to a provider also exposes network connection information to that provider. Error diagnostics are separate from optional marketing analytics.
Our intended collection excludes file contents, filenames, folder paths, upload-link credentials, and Google authorization tokens. We do not use session replay. See Google privacy information and Sentry privacy information for their processing practices.
Draft launch requirements: verify telemetry filtering and public/private page isolation, provide a persistent preferences control for withdrawing analytics consent, and confirm provider regions and retention before enabling collection. These controls are not yet verified complete. Clearing site data removes the locally stored choice but does not erase reports already sent to providers.
7. Retention and deletion
Owner and request records remain until deleted. Disconnecting Drive removes the stored connection credential and closes requests. Deleting an account removes its live account, connection, session, and request records. Owner login sessions expire after seven days. Temporary abuse counters expire and are cleaned up by the application.
Launch retention schedule to confirm: abuse counters up to 24 hours; sanitized operational logs and encrypted database backups up to seven days. Hosting locations, provider details, support-message retention, and any international-transfer safeguards must be finalized before this draft becomes the published policy. GA4 and Sentry retention must be documented separately from application logs and backups. Sentry Developer advertises a 30-day lookback; this is not a verified seven-day deletion schedule. Confirm GA4 event-data retention and aggregate-report behavior in the actual property settings.
Account deletion does not delete files already in Google Drive. Contact the recipient to request file deletion. An already-issued upload session may remain usable after a link is closed or a connection is removed. Deleted application records may remain in backups until those backups expire.
8. Your choices and rights
You can close or delete requests, disconnect Drive, or delete your account from the dashboard. You can also remove Uploadock’s Google access through your Google account settings. If Google revocation cannot be confirmed, the app will tell you.
Depending on your location, you may have rights to access, correct, delete, restrict, object to processing, or receive a copy of your personal data, withdraw consent, and complain to a data-protection authority. Contact [Public support and privacy email] to make a request; we may need to verify your identity. For uploaded files, contact the receiving owner as well.
9. Updates
We will update this page when our practices change and provide notice of material changes where required. We will obtain additional consent before a new use of Google data when required by Google’s policies or applicable law.