Brive Privacy Policy

Effective: 18 October 2025 Last updated: 22 August 2026 (UTC)

Welcome to Brive (https://brive.bloggersminds.com/). Brive is a cloud media storage bridge and management service operated by Blogger Mind (https://bloggersminds.com/). Brive enables users, developers, and applications to connect user-authorized Google Drive storage, upload and manage media assets, and access media programmatically via our API. This Privacy Policy details how Brive collects, processes, stores, protects, and handles personal data, Google Drive data, media metadata, and API activity when you use the Brive service ("Services").

1. Definitions

To ensure clarity throughout this Privacy Policy, the following terms hold defined meanings:

  • "Brive", "Service", "We", "Us", or "Our": The Brive storage bridge, media management platform, website, and API hosted at https://brive.bloggersminds.com/, operated by Blogger Mind.
  • "User", "You", or "Your": Any individual, developer, or authorized organization accessing or using Brive or its APIs.
  • "Account": A registered user profile used to manage Brive storage connections, view media, or generate API keys.
  • "Google Drive Integration": The user-authorized connection between Brive and your Google Drive account, established via Google OAuth 2.0.
  • "Media": Image, video, or asset files uploaded, stored, indexed, managed, or retrieved through Brive.
  • "API": The Brive Application Programming Interface (https://brive.bloggersminds.com/api/v1/media) and developer tools (https://brive.bloggersminds.com/developers/).
  • "API Key": A secret credential issued to authenticate programmatic requests to the Brive API.
  • "Personal Data": Any information relating to an identified or identifiable natural person.
  • "Processing": Any operation performed on Personal Data, including collection, recording, storage, retrieval, disclosure, or deletion.
2. Information We Collect: Account Data

When you register and use an account on Brive, we collect the following basic profile and authentication details:

  • Identity & Contact: Display name, email address, and username.
  • Authentication Credentials: Passwords stored strictly using salted cryptographic hashing algorithms (e.g., bcrypt/Argon2). We never store plaintext passwords.
  • Account Metadata: Account creation date, login timestamps, and operational status flags.
  • Support Communications: Messages, inquiries, or bug reports submitted directly to our support team.
3. Google Drive Integration & OAuth Scope

Brive allows users to optionally connect their own Google Drive account to serve as the storage backend for uploaded media.

Google OAuth Authorization & Scope

The connection is initiated by the user and authorized via Google OAuth 2.0. Brive currently requests and utilizes strictly the following Google OAuth scope:

https://www.googleapis.com/auth/drive.file

Scope Explanation

The drive.file scope grants Brive access only to files and folders that were specifically created, uploaded, or opened by Brive. Brive does not request or receive unrestricted access to your entire Google Drive.

Brive cannot view, read, index, modify, or delete your existing private documents, spreadsheets, photos, emails, contacts, or other files located in your Google Drive outside the files managed directly through Brive.

Brive does not request access to, nor process data from, other Google services such as Gmail, Google Calendar, Google Contacts, Google Photos, YouTube, Google Docs, or Google Sheets.

4. Categories of Google Drive Data Processed

When you authorize Brive to connect your Google Drive account, we process only the categories of data strictly necessary to operate the storage bridge:

  • Google Account Identity: Google account identifier, account display name, and email address returned during OAuth authorization to identify the connected storage backend.
  • Storage Quota Metrics: Storage usage and total quota availability returned by the Drive API to determine upload eligibility and prevent storage overflow.
  • Drive File Identifiers: Unique Google Drive file IDs generated when media is stored in your Drive.
  • File Metadata: File names, MIME types, file sizes, creation timestamps, and modification timestamps for Brive-managed media assets.
  • Public Media Permissions: Drive file view permissions required to serve media items configured for public sharing.
  • OAuth Tokens: Encrypted access tokens and refresh tokens required to communicate securely with Google APIs on your behalf.
5. Purposes of Google Drive Data Processing

Brive uses Google Drive information exclusively for legitimate storage management functionality:

  • To connect your authorized Google Drive account to your Brive profile.
  • To upload, store, retrieve, and delete media files as requested by you or through your authenticated API keys.
  • To track and display media metadata (file names, sizes, formats) in your Brive dashboard.
  • To check available storage capacity before processing media uploads.
  • To generate and deliver canonical public media delivery URLs (e.g., https://brive.bloggersminds.com/m/{media-id}) for media configured for public access.
  • To maintain system stability, troubleshoot authorized storage operations, and protect against service abuse.
6. Google User Data - Limited Use Commitment

Brive adheres strictly to the Google API Services User Data Policy, including the Limited Use requirements:

  • No Sale of Data: Brive does not sell, rent, lease, or trade Google user data, Drive files, or Drive metadata to third parties, data brokers, or advertisers.
  • No Advertising: Google Drive user data is never used to display, serve, or personalize advertisements.
  • No Unrelated AI Training: Google Drive user data and uploaded media are never used to train, fine-tune, or develop artificial intelligence or machine learning models.
  • Restricted Human Access: Human access to Google user data is strictly prohibited, except with your express consent for customer support, where required by law, or where necessary for security and abuse investigations.
7. OAuth Security, Disconnection, and Revocation

Google OAuth access tokens and refresh tokens are stored securely on our backend servers and protected by server-side security controls. OAuth credentials are never exposed in client-side HTML, JavaScript, or public logs.

Disconnecting Google Drive from Brive

You can disconnect your Google Drive account at any time through the Brive dashboard. Disconnecting unlinks the Drive connection in Brive and removes active OAuth credentials from our active database, preventing future automated uploads.

Revoking Authorization Directly with Google

You can revoke Brive’s authorization at any time directly through your Google Account Security settings at: https://myaccount.google.com/permissions.

Effect on Files Stored in Google Drive

Disconnecting Google Drive or revoking OAuth authorization terminates Brive’s connection. Files already uploaded to your Google Drive remain in your Google Drive until you delete them directly. Brive database metadata records may be retained or removed in accordance with our standard retention and backup cycles (up to 30 days).

8. Media Files & Metadata Handling

When media is uploaded through Brive, we record operational metadata required to index and serve the asset:

  • Stored Properties: Media ID, stored filename, original filename, validated MIME type, file size in bytes, upload timestamp, and associated account ID.
  • EXIF & Metadata: Uploaded images may contain embedded EXIF metadata (such as camera models or GPS tags). We recommend stripping sensitive EXIF data before upload.
  • Malware & Safety Scanning: Uploaded files are subject to automated verification to maintain system security and prevent the distribution of malicious payloads.
9. Public Media URLs & Content Visibility

Brive provides canonical public media URLs for media files that have been configured or created for public access:

https://brive.bloggersminds.com/m/{media-id}

  • Public Access: Public media URLs are accessible over HTTPS without requiring a Brive login, allowing media to be embedded in websites, applications, and documents.
  • User Responsibility: Not every Brive file is automatically public. Users are solely responsible for media they configure for public access and must ensure they hold all necessary intellectual property rights.
  • Confidentiality Warning: Users must never upload confidential, private personal information, medical records, financial data, or secret credentials as public media.
10. Brive Developer API & Usage Logging

Brive provides a REST API for authorized external applications and services. Complete technical documentation is published at https://brive.bloggersminds.com/developers/.

API Authentication & Security

  • API requests authenticate using secret Bearer keys: Authorization: Bearer brv_xxxxxxxxx
  • Upload endpoint: POST https://brive.bloggersminds.com/api/v1/media
  • API keys are secret credentials. Developers must store keys exclusively in secure backend server environments and must never expose them in client-side JavaScript, public HTML, or public source code repositories.

API Activity Logging

To enforce rate limits, prevent abuse, maintain system security, and diagnose technical errors, Brive logs operational API request metrics:

  • API key identifier and associated user ID.
  • Endpoint called, HTTP method, and response status code.
  • Request processing time, uploaded payload size, and MIME type.
  • Originating IP address and request timestamp.

Configurable Usage Limits

Brive may impose configurable request-rate, upload-size, concurrency, storage, or other usage limits to maintain service stability, security, and fair use. Applicable limits may be communicated through the Brive developer documentation, API responses, response headers, or other service notices and may change as the service evolves.

11. Technical, Device & Network Information

When you access the Brive website or API, our infrastructure automatically records technical access logs to maintain uptime and system defenses:

  • Device & Browser: Browser type, version, operating system, language settings, and screen resolution.
  • Network & Routing: IP address, Internet Service Provider (ISP), and country of origin.
  • Request Logs: Request URLs, referring URLs, HTTP protocol headers, and timestamp logs.
12. Cookies & Local Storage

Brive uses minimal, essential cookies and local storage tokens strictly necessary for system operation:

  • Essential Session Cookies: Maintain user authentication state, secure session management, and verify CSRF protection tokens.
  • Security Cookies: Help identify rapid automated attacks, brute-force attempts, and unauthorized session modifications.
  • Preference Storage: Remember interface preferences such as layout or theme toggles.
14. Data Sharing & Third-Party Service Providers

We do not share your personal information or Google Drive data with outside parties except in the limited, defined scenarios outlined below:

  • Google APIs / Google Drive: When you connect Google Drive, files and API instructions are transmitted directly to Google Drive via official Google APIs to execute requested storage operations.
  • Hosting Infrastructure: Secure cloud server and database providers that host Brive applications, metadata indexes, and API endpoints.
  • Email Services: Transactional email providers used to send password resets and security alerts.
  • Security & DDoS Mitigation: Security networks that protect Brive API endpoints against malicious traffic and Denial-of-Service attacks.
  • Legal Duty: When required by lawful court orders, subpoenas, or legal processes to protect rights, safety, and property.
15. Statement on Sale of Personal Data

Brive does not sell, rent, trade, or lease personal information, Google Drive user data, media files, or email addresses to data brokers, direct marketers, or third parties for monetary or commercial gain.

16. Data Retention Policy

Brive retains personal data, metadata, and operational records only for as long as necessary to provide the service, maintain security, comply with legal obligations, and resolve disputes:

  • Account Profile Data: Retained for the active lifetime of your account until deletion is requested.
  • Media Metadata & Index Records: Retained while your account and media assets remain active in Brive.
  • API Activity Logs: Retained for 30 to 90 days for rate limiting, abuse detection, and debugging before automated rotation.
  • System & Security Logs: Retained for 30 to 90 days for firewall and security analysis.
  • Disaster Recovery Backups: Database snapshots are held on rolling operational deletion cycles (up to 30 days) for disaster recovery.
17. Data Security Safeguards

We implement technical and organizational measures to safeguard user data, API keys, and connected storage credentials:

  • Transport Layer Encryption: All data transmitted to Brive and its API endpoints is encrypted using HTTPS over TLS.
  • Credential & Token Security: Passwords are cryptographically hashed. OAuth tokens and API secrets are stored securely using backend access controls.
  • API Defenses: Automated rate limiting, request validation, and IP monitoring defend against abuse and brute-force attempts.
  • Least-Privilege Access: Administrative server access is strictly limited to authorized engineering personnel via cryptographic key authentication.

While we enforce robust defensive measures, no transmission over the internet or electronic storage solution can be guaranteed to be 100% secure. Users and developers are responsible for safeguarding their account passwords and API keys.

18. Security Incident Notification

In the event of a confirmed security incident affecting the security of your unencrypted personal data, Brive will promptly take remediation measures. Where legally required, we will notify affected users via email or platform announcements in accordance with applicable legal timing standards.

19. Your Privacy Rights

Depending on your geographic location and local data protection regulations, you may have the following rights regarding your personal data:

  • Right to Access: Request confirmation of whether we process your data and receive a copy of your stored records.
  • Right to Rectification: Request correction of inaccurate or incomplete personal details.
  • Right to Erasure: Request permanent deletion of your account and personal data.
  • Right to Restrict Processing: Request temporary limitation of data processing under specific legal conditions.
  • Right to Data Portability: Request a machine-readable export of data you provided to Brive.
  • Right to Withdraw Consent: Withdraw consent for Google Drive OAuth connections at any time.
20. Account Deletion & Data Removal

You may request account deletion at any time through your Brive dashboard or by contacting support at tech@bloggersminds.com.

Upon account deletion:

  • Your profile details, email, and authentication credentials are removed from our active database.
  • All active Brive API keys are permanently revoked.
  • Google Drive OAuth tokens are deleted from active tables, immediately terminating Brive's access to your Google Drive.
  • Brive media index records are marked as deleted.
  • Residual database snapshot records are permanently purged following standard backup rotation cycles (up to 30 days).
21. Third-Party Services (Google Drive)

Google Drive is operated independently by Google LLC and is governed by Google’s own Terms of Service and Privacy Policy. Blogger Mind and Brive do not own or manage Google’s independent infrastructure.

Connecting your Google Drive account to Brive subjects your storage usage to Google’s policies. We encourage you to review Google’s privacy practices directly.

22. Children’s Privacy

Brive is a technical media storage service not directed toward children under 13 (or under 16 in relevant jurisdictions). We do not knowingly collect personal information from children. If you believe a child has created an account, please contact us at tech@bloggersminds.com to have the data removed.

23. Policy Revisions & Updates

We review and update this Privacy Policy periodically to reflect service updates and legal requirements. When updates occur, we will update the "Effective Date" and "Last Updated" timestamps at the top of this page.

For material changes affecting personal data or Google Drive integration, we will provide advance notice via email or a dashboard notification. Continued use of Brive after revisions take effect constitutes acceptance of the revised Privacy Policy.

24. Contact Information & Privacy Inquiries

If you have questions, concerns, or legal inquiries regarding this Privacy Policy or Brive’s data handling practices, please contact us at: