Privacy policy
Orison Arc Files · Effective 4 October 2026
This policy explains how Orison Arc Files (“the app”), operated by Orison Arc, handles Google user data. The app is a private tool used only by Orison Arc, with Orison Arc's own Google Account. It is not offered to the public.
Google data the app accesses
- Google Drive files created by the app. With the
drive.filepermission the app can access only files it creates or that are explicitly opened with it. These are Orison Arc's own encrypted files, plus the information Drive returns about them: file identifier, name, size, checksum and times. - Authorization tokens. Google issues these so the app can keep working without asking to sign in each time.
The app does not access any other Google Drive files. It does not request or use your name, e-mail address, contacts, calendar, mail or any other Google data.
How the data is used
- To upload Orison Arc's encrypted files to Google Drive.
- To download those files when Orison Arc needs them, including to check that they were stored correctly.
Files are encrypted before upload. The decryption keys are never sent to Google, so neither Google nor anyone who obtains only the stored files can read their contents.
How the data is stored
- The encrypted files are stored in Orison Arc's Google Drive.
- Authorization tokens are stored only on equipment Orison Arc controls, readable only by the app's service. They are never kept in source code, documents or e-mail.
- Operational records hold file identifiers, sizes, checksums, times and results. They never contain file contents or tokens.
Sharing
Google user data is not sold, rented or shared with anyone, and is not used for advertising. It is not used to develop, improve or train artificial-intelligence or machine-learning models. No one other than Orison Arc's own administrators operates the app.
Retention and deletion
The app does not delete files from Google Drive. Orison Arc decides how long its files are kept, and removes them in Google Drive when they are no longer needed.
When an authorization is replaced, the previous token is kept only in a protected rollback copy until the new authorization has been verified, and is then deleted.
Access can be withdrawn at any time at myaccount.google.com/permissions. After that, the app can no longer reach Google Drive, and Orison Arc deletes the stored tokens.
Google API Services User Data Policy
Orison Arc Files' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Changes and contact
If this policy changes, the updated version will be published on this page with a new effective date. Questions: infra@orisonarc.com.