Privacy Policy
Effective date: 2026-08-05
Version: 1.1
Product: Dioveo ("we", "us", "our"): Gmail attachment search, organization, download, and automation tools.
This Privacy Policy explains what we collect, how we use it, and the choices you have when you use our website, application, and related services (the "Service").
1. Who we are
- Controller: Opsaflow SAS, operating Dioveo
- Address: 60 RUE FRANCOIS IER 75008 PARIS
- Privacy contact: hello@dioveo.com
2. Scope
This Policy applies to data processed when you browse our site, create an account, connect an email provider (e.g., Gmail/Google Workspace), or interact with support and product communications.
3. Data we collect
a) Account & billing
- Name and email address (sign-in is via Google; we do not store passwords).
- Subscription status, invoices, and limited payment metadata from our payment processor (we do not store full card numbers).
b) Email integrations (Gmail / Google Workspace)
If you connect a Google account, we access data only to provide the features you enable. For example:
- Message metadata: sender, recipients, subject, date, labels, and size.
- Attachment metadata: type, size, and filename, processed securely when required for search or attachment management features.
- OAuth tokens: stored encrypted at rest; their values are never included in data exports.
You can disconnect your Google account at any time from within Dioveo or directly in your Google Account → Security → Third-party access.
b1) File integrations (Dropbox, Google Drive, OneDrive)
If you connect a file storage provider (Dropbox, Google Drive, or OneDrive) for workflow automation, Dioveo only uploads files that you explicitly select or that originate from your email attachments as part of enabled workflows.
Dioveo does not download, read, or browse existing files or folders in your connected storage accounts.
Access is limited to the minimum data strictly required to perform the upload action, including:
- The destination folder you choose
- File metadata necessary for upload (such as filename and file size)
- OAuth tokens required to authenticate and authorize the upload
No other data from your connected file storage accounts is accessed, processed, or stored.
OAuth tokens for all file storage integrations are stored securely and encrypted at rest, with the same protections across all providers.
You may disconnect any file storage integration at any time from Dioveo settings or directly from the provider's account settings (for example, under "Connected Apps").
c) Product usage
- App events (clicks, views), device/browser info, IP-based coarse location (city/region), crash logs.
- Cookie/LocalStorage identifiers for sessions and preferences (see Cookies).
d) Support & feedback
- Messages you send us and any files you attach.
Sensitive correspondence. Your mailbox may contain sensitive material, such as medical or legal mail, and indexed metadata (sender, subject, file name) can reflect that. Dioveo indexes it only on your instruction and acts as your processor for mailbox-derived data, as set out in the Terms (Section 22, Data Processing Addendum). You remain the controller of your mailbox, including other people's data in it.
4. Google API disclosure (Gmail/Workspace)
- We comply with the Google API Services User Data Policy, including Limited Use requirements.
- Gmail/Google Workspace data is accessed only to provide user-facing features (e.g., attachment search, manual folders, downloads, and workflows you configure).
- We do not use Google data for advertising and do not sell personal data.
- We do not transfer Google data to third parties except vetted sub-processors acting on our instructions under a DPA.
- Human access to Google data is rare, limited to security/abuse prevention or support you request, and is logged and restricted.
- We request least-privilege OAuth scopes and store OAuth tokens encrypted at rest; data is protected in transit with TLS.
- We store only minimal derived signals/metadata needed for features; attachments/content are processed only when you use features that require them and are deleted or de-identified when no longer needed.
- You can revoke access at any time in Dioveo settings or via Google Account → Security → Third-party access.
- We do not read emails for unrelated purposes and do not make automated decisions with legal or similarly significant effects.
- On disconnection or account closure, data is handled per our retention policy (see Section 10).
5. How we use data (purposes & legal bases)
Provide & operate the Service: display attachment lists, search emails, run workflows.
Legal basis: Performance of a contract.
Safety & integrity: authentication, abuse/fraud detection, troubleshooting, securing tokens, preventing misuse.
Legal basis: Legitimate interests and/or legal obligation.
Improve features: aggregated or de-identified metrics, performance analytics, A/B testing.
Legal basis: Legitimate interests.
Billing & support: payments, invoicing, tax compliance, responding to support requests.
Legal basis: Contract / legal obligation.
Optional updates: product tips, feature announcements, onboarding messages you opt into.
Legal basis: Consent and/or legitimate interests (you can opt out anytime).
Model improvement (optional): de-identified/aggregated data to improve quality, only if you opt in.
Legal basis: Consent.
- Your choice: You may withdraw consent at any time in settings or by emailing hello@dioveo.com.
6. Library organization
- Library folders are created and filled manually by you.
- Dioveo does not analyze attachments to classify them or automatically place them into folders.
- Moving an attachment into a Dioveo folder does not move or change anything in Gmail.
7. Sharing & sub-processors
We share personal data only with service providers acting on our instructions and bound by confidentiality:
- Hosting & databases: Hetzner (Germany)
- Network & DNS: Cloudflare, which proxies traffic to our site and so sees connection data such as your IP address
- Authentication, Gmail & Google Drive: Google
- Payments: Stripe
- Object storage for prepared downloads: DigitalOcean Spaces
- Transactional email (for example, telling you an export is ready): Resend
- Operational logging: Grafana Cloud (Loki)
- Cloud destinations you connect yourself: Google Drive, Dropbox, or Microsoft OneDrive. These receive your files only when you ask us to send them.
- Audience measurement, only if you accept: Google Analytics. Nothing is loaded or sent unless you accept the banner.
- Error monitoring, only if you accept: Sentry. It is currently not enabled in any environment; when it is, it starts only after you accept and never receives your attachments.
A current list of sub-processors is available on request at hello@dioveo.com.
We do not sell personal data.
8. International transfers
If data is transferred outside your region, we use appropriate safeguards (e.g., EU Standard Contractual Clauses) and perform transfer risk assessments.
Primary hosting region: Europe/Germany
9. Security
- In transit: every connection between you and Dioveo, and between Dioveo and the APIs it calls (Google, Stripe, your cloud drive), uses TLS. Traffic between our own services runs inside a private network that is not reachable from the internet.
- Prepared downloads are encrypted before they are stored, and the stored copy expires automatically after 7 days.
- Encrypted OAuth tokens; least-privilege scopes.
- Role-based access controls and centrally managed secrets.
- We are actively working toward SOC 2 Type II certification.
- Report security issues: hello@dioveo.com.
No method is 100% secure, but we work continuously to protect your data.
10. Retention
- Your account and your attachment index: kept while your account is active. When you delete your account we delete them straight away, not on a schedule, along with your connections, folders, workflows and export history.
- Database backups: we take a backup every night so we can recover from a failure, and we keep the last 30 of them, so a backup is deleted about 30 days after it is taken. A copy of your data can survive in those backups until the last one containing it is deleted. We do not restore backups to bring deleted accounts back.
- Prepared downloads: the zip we build for you is encrypted in storage and deletes itself after 7 days.
- Operational logs: kept for a limited period for security and troubleshooting, then deleted automatically. They record events such as a sync starting or failing, not the contents of your files.
You may request deletion at any time (see Your rights).
11. Your rights
Depending on your location, you may have the right to access, rectify, erase, restrict, port, and object to processing. You may also lodge a complaint with your local authority (e.g., CNIL in France, ICO in the UK).
California residents have rights under the CCPA/CPRA (including access and deletion). We do not sell or share personal data as defined by the CPRA.
Requests: hello@dioveo.com. We'll verify and respond within applicable timelines.
12. Cookies & similar technologies
- Strictly necessary: authentication/session, CSRF, preferences (always on).
- Optional analytics: only with your consent; you can change choices in settings.