This Privacy Policy applies to StratoFusion, a cloud storage aggregation platform that helps you connect third-party storage providers, browse files, run transfers, and manage backup or sync jobs. It is effective as of April 4, 2026 (2026-04-04).
1. What StratoFusion does
StratoFusion provides a control plane for your connected cloud storage accounts. StratoFusion does not operate as a general-purpose file hosting service for your content. Your files remain with the underlying provider unless you instruct StratoFusion to move, copy, upload, or download them through the connected provider or StratoFusion's transfer systems.
2. Information we collect
Depending on the features you use, we process the following categories of data:
- Account and identity data such as your Clerk account identifier, email address, subscription tier, and connected-provider account labels.
- OAuth connection data such as access tokens, refresh tokens, scopes, expiry timestamps, and account-type metadata returned by Google, Microsoft, Dropbox, or other providers you connect.
- File and folder metadata such as names, paths, parent folders, sizes, mime types, timestamps, container identifiers, namespace identifiers, and provider/account context. For Google Drive, this may include Google Drive file and folder metadata made available through the Drive API for the account you connect.
- File content when you explicitly ask StratoFusion to upload, download, transfer, back up, or sync content through a connected provider.
- Operational data such as backup and sync job settings, transfer status, activity logs, audit logs, quota usage, and error messages.
- Billing data such as Stripe customer identifiers, subscription status, invoices, and plan entitlements. We do not store full payment card numbers.
- Technical and security data such as IP address, user agent, request identifiers, and token-refresh events used for debugging, fraud prevention, and service reliability.
3. Files, content, and metadata
StratoFusion does not claim ownership of your files. We process file and folder metadata to render the UI, search across providers, resolve paths, track quotas, and record activity. For Google Drive, OneDrive, and Dropbox, most search and full-text behavior relies on the provider's own APIs and indexing systems.
Where StratoFusion performs temporary extraction, caching, or transfer preparation to satisfy a request, that processing is used to deliver the feature you asked for and is not intended to create a permanent customer file repository inside StratoFusion.
4. OAuth credentials and authentication data
StratoFusion uses OAuth so that you authorize access directly with the provider. We do not receive your Google, Microsoft, or Dropbox password.
- OAuth tokens stored by StratoFusion are written to our application database so we can maintain the connection, refresh expired access, and run jobs you authorize.
- Stored OAuth token values are encrypted before they are persisted by the application.
- We also store scope, expiry, and account metadata so the product can distinguish personal vs. business connections and display the right account context.
5. Google user data and provider permissions
When you connect a provider, you authorize StratoFusion to access that provider according to the scopes shown during the connection flow. We aim to request the least-privilege provider access consistent with the features you enable.
- Google Drive connections currently request the Drive
drivescope. For Google Drive connections, the Google user data we collect or process may include OAuth tokens, granted scopes, expiry timestamps, connected-account labels exposed by Google Drive, file and folder metadata, and file content only when you ask StratoFusion to upload, download, transfer, back up, or sync that content. We do not currently request separate Google profile scopes in this flow. - OneDrive connections request file access, profile basics, and offline access. Work or school connections may additionally request read-only SharePoint site access so SharePoint sites and document libraries can be listed and transferred.
- Dropbox connections request account-info access plus the file metadata and file content read/write scopes used by browsing, search, upload, download, copy, move, backup, and sync flows.
Your use of those providers remains subject to their separate terms and privacy notices, including Google, Microsoft, Dropbox, Clerk, Stripe, and other infrastructure providers where applicable.
6. How we use Google user data and other service data
StratoFusion uses Google user data and other connected-provider data only to operate and improve the user-facing features you ask us to run.
- We use Google Drive and other provider data to link accounts, label the connected account in the UI, browse files and folders, run search, prepare transfers, execute uploads and downloads, and run scheduled backup or sync jobs that you configure.
- We use metadata, logs, and security events to keep the service reliable, investigate failures, prevent abuse, refresh expired connections, and provide customer support.
- We do not sell Google user data.
- We do not use Google user data for targeted advertising, credit or lending decisions, data brokerage, or other independent commercial purposes unrelated to StratoFusion's user-facing features.
- We do not use Google user data to train generalized or non-user-facing AI or machine-learning models.
7. When we share or disclose data
StratoFusion shares or discloses data only when it is necessary to provide the service, comply with law, or protect the service and its users.
- We share data with the provider you connected so that your requested browsing, transfer, backup, sync, and download actions can be carried out.
- We may disclose data to subprocessors and infrastructure providers that help us operate StratoFusion, such as identity, hosting, job execution, logging, analytics, and billing providers, but only to the extent needed to deliver the feature or operate the service.
- We may disclose data if required by law, legal process, or a valid governmental request, or when reasonably necessary to enforce our terms, investigate fraud, or protect users and the service.
- We do not transfer or disclose Google user data to third parties for targeted advertising, resale, or any independent use that is not required to provide or improve StratoFusion's user-facing functionality.
8. How we protect your information
StratoFusion uses practical safeguards designed to keep control with the customer who connected the account and requested the job.
- Provider connection details are stored in encrypted form.
- Provider API traffic and web traffic are expected to use TLS.
- Connected accounts, transfer history, and job controls are limited to the signed-in StratoFusion user who created them.
- Background transfer systems are protected so jobs cannot be triggered through open public access.
- Internal troubleshooting and debug tools are limited to authorized team use.
9. How transfers and downloads work
To execute transfers, StratoFusion may stream data through its transfer and download systems. This includes uploads, downloads, copy, move, backup, and sync operations that you initiate or schedule.
- Provider API traffic and web traffic are expected to use TLS in transit.
- We use background processing systems to move data between providers or between a provider and your browser when the feature requires it.
- Those background systems are used only when you start a job or set a schedule that authorizes one.
- We do not intentionally inspect file contents for advertising or data brokerage purposes.
- Temporary transfer-state snapshots in those systems are operational records and are retained for short, adaptive windows measured in minutes to up to approximately one day, not as a permanent content archive.
10. Search, indexing, and AI features
Search features use a combination of provider APIs, metadata matching, and limited application-side processing.
- Basic search uses file and folder metadata such as names and paths.
- Full-text behavior primarily depends on the provider's own indexing support and limitations.
- In the current product implementation, AI semantic search is disabled by default. We are not currently generating production embeddings, training generalized AI or machine-learning models on Google user data, or maintaining a general vector store for customer files.
- If StratoFusion later launches AI semantic search, we expect to update this Policy and provide feature controls before using embeddings or similar vectorized representations of your content or metadata.
11. Billing and payment information
Billing and subscription management are provided through Stripe. StratoFusion stores billing identifiers, plan entitlements, invoice and subscription state, and other Stripe-generated account metadata needed to provide the billing experience. Payment card details are handled by Stripe, not stored by StratoFusion.
12. Retention
Retention varies by data category and may be adjusted for security, legal, or operational reasons.
- Connected account records, preferences, and OAuth tokens remain until you disconnect the provider, clear your connected services, or otherwise remove the account from StratoFusion.
- User activity logs are configured with a default retention period of 90 days.
- System audit logs are configured with a default retention period of 365 days.
- Token-refresh logs, quota history, and billing records may be retained as needed for fraud prevention, support, disputes, finance, and compliance.
- Temporary worker-side transfer state is retained for short operational windows only and may be cleaned earlier or later depending on workload and failure-recovery needs.
- Google Drive file content is not retained as a permanent StratoFusion content repository solely because you connected your account. Content that moves through our systems for a transfer or download is retained only for the short-lived operational windows needed to complete that request, recover from failure, or troubleshoot the job.
13. Disconnecting providers and deleting data
You can disconnect a linked provider from the StratoFusion interface. When you do so, StratoFusion removes the stored tokens for that linked account and deletes the active connection record from the application database.
Once that connection is removed, StratoFusion should no longer be able to start new jobs for that provider account unless you connect it again.
Disconnecting a provider from StratoFusion does not automatically delete any data already held by the provider or any data the provider may have already shared under its own rules. You may also need to revoke StratoFusion directly from the provider's connected-app settings.
If you request broader account cleanup or disconnect all services, StratoFusion may delete connected account metadata, tokens, and preferences while retaining logs, invoices, and security records as reasonably necessary for compliance, dispute resolution, abuse prevention, or legitimate business operations.
If you want us to handle a deletion or privacy request that is not available in the product interface, contact support@stratofusion.io. We may need to retain limited records where required for security, finance, tax, fraud prevention, or legal compliance.
14. Cross-border processing
StratoFusion and its subprocessors may process data in different regions, including regions where our hosting, identity, billing, or connected storage-provider partners operate infrastructure. By using the service, you acknowledge that metadata and transfer traffic may be processed outside your local jurisdiction.
15. Your privacy rights
Depending on where you live, you may have rights to access, correct, export, or delete certain personal data and to understand how it is processed.
- EU/UK users may have rights under GDPR, including access, rectification, deletion, restriction, objection, and portability.
- California residents may have rights under CCPA/CPRA, including the right to know, delete, and correct covered personal information.
- StratoFusion does not describe its current product as selling personal information for cross-context behavioral advertising.
Some rights requests may require us to preserve limited records for security, fraud prevention, tax, finance, or legal obligations.
16. Children
StratoFusion is intended for users who are old enough to lawfully enter into a binding contract in their jurisdiction and is not directed to young children.
17. Changes to this Policy
We may update this Privacy Policy from time to time. When we make material changes, we may update the effective date, post a revised version at this page, and, where appropriate, provide in-product notice.
18. Contact us
Privacy questions, deletion requests, and account-data requests can be sent to support@stratofusion.io.
19. Related policies
Review our Terms of Service and Fair Use Policy for the service rules, quotas, and billing limits that apply alongside this Privacy Policy.