Skip to content

AVENZERS CLOUD / POLICIES

Draft · not in effect

Privacy Policy

How AVENZERS Cloud handles account, storage, collaboration, and Google API data.

Draft prepared 11 October 2026No effective date assigned
Draft for review · not an effective policy

This complete draft is available so you can read how the service and its proposed commitments are described. It includes both current practices and plans that are not yet implemented. Any feature marked planned, proposed, or not operational is not available as a live commitment. This page is not an approved contract or final Privacy Policy for Google OAuth verification.

Questions or privacy requests: support@avenzers.tech

1. About this Policy

This Privacy Policy explains how AVENZERS Cloud ("AVENZERS Cloud", "we", "us", or "our") handles personal information when you visit our website, create an account, use managed storage, connect external storage accounts, exchange messages, collaborate in workspaces, or contact us. AVENZERS Cloud is a cloud-file and collaboration application offered under the AVENZERS GROUP brand. AVENZERS GROUP is operated as a Bangladesh-registered proprietorship based in Dhaka

Our product combines an AVENZERS account with optional storage connections. Signing in with Google is not the same as granting AVENZERS Cloud access to Google Drive. Connecting Drive is a separate, optional authorization step.

2. Information We Collect or Process

Account and profile data. We process account identifiers, email addresses, sign-in information supplied by the authentication provider, names, usernames, profile pictures, profile preferences, and authentication/session records. We do not need your Google account password.

Collaboration data. We process workspace and channel membership, roles, invitations, contact or friend requests, messages, reactions where available, message attachments and references, sharing settings, and notifications. The people you choose to collaborate with may see your display name, permitted profile details, messages, and items you share with them.

Files and metadata. We process filenames, types, sizes, folder locations, provider identifiers, file ownership, permitted sharing references, upload state, and access or activity records as needed to provide file-management services. For files in AVENZERS-managed storage, the service stores file bytes with its infrastructure provider. For files in your Google Drive or another connected provider, files ordinarily remain in that provider unless you explicitly initiate a supported copy, transfer, or migration. File contents may pass through AVENZERS-controlled servers when you upload, preview, download, or share a file through the service, even where the file remains stored externally.

Connected account data. When you authorize a storage connection, we may process the provider account identifier, email or account display information, authorized file/folder metadata, connection status, granted permissions, and authorization credentials required for the connection. Access and refresh credentials must be handled by secure server-side systems, not exposed to ordinary users or client-side application code.

Technical and support data. We may process request and error information, timestamps, browser/device characteristics, IP addresses, security events, and correspondence you send to support to operate and protect the service. Specific logging and retention periods are not established in this draft.

Payment and subscription data. The planned service model includes Free, monthly/yearly Paid and negotiated Enterprise plans, with opt-in automatic or manual renewal and location-dependent supported currencies. Checkout is not represented as active. If enabled, we may process plan type, billing country, currency, invoice/payment status, transaction identifiers and support disputes; a selected payment processor may separately process payment credentials. We must identify the actual payment processor and update disclosures before checkout goes live.

3. Why We Use Information

We process information, as relevant, to:

  • authenticate accounts and manage sessions;
  • create personal spaces, workspaces, channels, and authorized conversations;
  • display, organize, upload, preview, download, search, and share files according to your actions;
  • connect and maintain external storage access at your request;
  • enforce storage quotas, membership rules, file permissions, and abuse protections;
  • deliver service-related notifications, respond to requests, and troubleshoot errors;
  • prevent fraud, protect account security, and comply with valid legal obligations.

Where applicable privacy law requires a legal basis, our basis may be performing our agreement with you, our legitimate interest in securing and operating the service, compliance with law, or consent for optional activities. The operator must assess and confirm which bases apply in relevant jurisdictions before launch.

4. Google Sign-In and Google Drive — Separate Permissions

Google Sign-In. If you sign in through Google, AVENZERS Cloud uses information Google makes available for authentication, such as your Google account identifier, name, email, and profile picture, according to the sign-in permissions you grant. Google Sign-In does not automatically authorize access to Google Drive files.

Connect Google Drive. If you separately choose to connect Drive, the intended integration requests the limited Google Drive scope https://www.googleapis.com/auth/drive.file. That permission is designed for files created/opened with the app or files you expressly select or share with the app through a supported picker or workflow. It is not general permission to index or read every file in your Drive.

With this permission, the application may, at your direction and within Google's granted access:

  • create or reuse a visible "AVENZERS Cloud" folder in your Google Drive;
  • create, organize, rename, upload, move, trash, or retrieve authorized Drive items, as supported by the deployed implementation;
  • access metadata or file content necessary to show authorized previews, downloads, and in-app sharing;
  • maintain a connected-account record and refresh authorization when permitted.

File ownership, available space, storage charges, and Google Drive's own permissions remain subject to Google's service. AVENZERS Cloud must not silently turn a private Drive file into an "Anyone with the link" file. Sharing a file inside an AVENZERS workspace does not by itself mean its native Google sharing settings change.

Some connected-file access may be provided through an authenticated server route. That route must check current permissions; it can process file bytes transiently when serving a permitted request. Such access depends on continued authorization, service availability, provider policies, and technical limits. It is not a guarantee of unrestricted content-delivery service.

5. Google API Data — Limited Use Commitments

Our access to data obtained from Google APIs is restricted to providing or improving the user-facing features you request, maintaining or securing those features, meeting legal obligations, and other purposes allowed by Google's API Services User Data Policy.

We do not use Google API user data to serve personalized advertising, sell it to data brokers, or train generalized artificial-intelligence or machine-learning models. We do not transfer Google API user data to third parties except when necessary to provide features you authorize, for security purposes, to comply with applicable law, as part of a transaction allowed by Google's policies, or with your affirmative consent, as applicable. Human access to such data is limited to circumstances permitted by Google's policies, such as your explicit consent, security investigations, support when strictly necessary, or legal obligations, and must be subject to appropriate access controls.

Any product or operational practice that conflicts with these commitments must be changed before launch; policy wording alone does not establish compliance.

You may disconnect Google Drive within the app where the feature is available, or revoke third-party access through Google's account permissions page: https://myaccount.google.com/permissions. Disconnecting prevents future authorized access but generally does not remove original files from your Google Drive.

6. Storage Providers and File Location

AVENZERS Storage. Files intentionally uploaded to managed storage are held using our configured cloud-storage infrastructure, currently designed around Cloudflare R2. Account records, permissions, file metadata, and messaging are managed through our application/database infrastructure, currently using Supabase.

Google Drive. Files intentionally saved to Google Drive normally remain in the connected user's Google account. AVENZERS Cloud may store identifying metadata and process the file content for an authorized operation, but does not automatically create a permanent managed-storage copy merely because a Drive file is mentioned in a message.

Other providers. If optional third-party storage connectors become available, their access and data flows will be described at connection time and reflected in this Policy before launch. Do not assume an unimplemented connector is available.

7. Messaging, Workspaces, and Sharing

Content you send to a person, group, channel, or workspace becomes available to the recipients permitted by the applicable settings, rules, and current membership. Owners and authorized administrators may manage memberships, roles, and certain shared workspace resources. Recipients might retain copies they already downloaded even after access is revoked. Private workspaces are not publicly accessible by default; however, AVENZERS Cloud does not claim end-to-end encryption unless a verified end-to-end encryption system is actually implemented.

8. Cookies and Local Storage

We use or may use technologies required for login, security, session management, and user-selected preferences, including browser storage for appearance settings. See the Cookie Policy for details. Any optional analytics, tracking, advertising cookies, or consent-management technology must be disclosed and configured before activation; do not assume such tools are deployed from this draft.

9. Recipients and Service Providers

We share or make information accessible only as reasonably necessary for operation, user-selected collaboration, provider connections, security, legal obligations, or authorized support. Categories may include:

  • hosting and deployment services (currently planned/used: Vercel);
  • authentication, database, and realtime services (Supabase);
  • managed object storage (Cloudflare R2);
  • Google for Google Sign-In and optional Drive access;
  • the external storage provider you choose, if supported;
  • other participants or administrators of groups and workspaces to whom you choose to grant access;
  • professional advisers, authorities, or successor operators where legally permitted and necessary.

Provider identity and location, written agreements, subprocessor terms, and any international transfers must be confirmed against the live deployment. Third-party services have their own privacy practices.

10. Retention and Deletion

Owner-approved service policy, subject to implementation audit: Confirmed account closure ends access immediately once the deletion is accepted and authorized; there is no account recovery window. Applicable active personal data and user-owned AVENZERS-managed files are targeted for removal within 30 days, except records required by law, fraud/security investigations, dispute resolution, or other valid exemptions. Original files in a separately connected Google Drive account are not deleted by AVENZERS account closure; provider authorization should be revoked and stored access credentials removed.

Messages: Other conversation participants retain the conversation history, but the deleted sender's visible attribution is anonymized as Deleted User with name and profile image removed. Message bodies may still contain personal data disclosed in their text and may require case-by-case legal handling.

Organization-owned materials: Files and records that are genuinely owned by a continuing organization, rather than the departing user personally, are preserved subject to legitimate organizational access and retention. A sole organization owner cannot complete account deletion until ownership has transferred to a consenting eligible existing Admin.

Security/audit logs: Planned ordinary retention is 90 days, absent legal holds and justified exceptions; routine enforcement and underlying log vendors require verification.

Backups: The approved maximum residual retention after deletion is 30 days; actual snapshot/backup expiry and provider policies must be audited and configured to meet it before we make the commitment in production. Backups are not ordinarily used to restore a deleted account.

Inactive accounts: No automatic deletion solely for inactivity is planned. If an inactivity-based deletion program is introduced, notice and a revised policy will precede it.

11. Security

We design the service around authenticated access, per-user and workspace authorization, restricted provider permissions, server-side credential handling, and application/database access controls. No electronic system is perfectly secure; we cannot guarantee absolute security. Do not claim full end-to-end encryption, independent security certification, or verified incident-response service unless demonstrated by the released implementation.

12. Your Choices and Rights

Depending on applicable law, you may be entitled to access, correct, export, erase, restrict, or object to certain personal-data processing, or withdraw optional consent. The intended design includes self-service export of eligible user data (e.g., portable structured records and owned managed files) and support-assisted access/export where the self-service tool does not cover a request. Export excludes other users' private data, organization-restricted content without authority, and original files stored solely with external providers.

Contact support@avenzers.tech for access, correction, export, deletion, consent withdrawal, or privacy concerns. We may reasonably verify account ownership without requesting your password or OAuth tokens. We aim to respond to ordinary requests within 30 days where permitted, or earlier if applicable law imposes a shorter deadline; legally justified extensions, refusals and exceptions will be explained as required. The self-service export and deletion routes must be tested before being advertised as available. Necessary security/service messages may be sent; optional promotional marketing requires applicable consent or other lawful basis and an unsubscribe route.

We do not sell personal data. As an operator commitment, private user files and messages will not be used to train generalized AI models; actual vendor settings and subprocessors must be audited against this commitment.

13. International Processing

Application providers may process data in countries different from your residence. The operator must document actual provider regions, contractual safeguards, and legally required transfer mechanisms before publication; this draft does not represent that all processing happens in a single country.

14. Age Eligibility

AVENZERS Cloud is for adults aged 18 or older only. We do not knowingly permit individuals younger than 18 to open accounts. Contact support@avenzers.tech if you believe an underage account or related personal data needs review. Age verification and legally required remedial steps must be appropriate to the actual launch regions.

15. Changes to this Policy

We will publish an updated policy when our practices materially change. Our intended notice period for material changes is normally 30 days in advance, subject to legally required notice/consent and the need for urgent security or legal measures. Where a new use of Google API user data needs notice or permission, we will obtain it before that use. Each approved published version will show its effective date and be retained for consent history.

16. Contact

Service: AVENZERS Cloud
Operator: AVENZERS GROUP (Bangladesh-registered proprietorship), Dhaka, Bangladesh
Email (support and privacy): support@avenzers.tech
Planned service domain: https://cloud.avenzers.tech

A street address is not included in this draft. Contact AVENZERS GROUP at support@avenzers.tech with support or privacy requests.