DriveBot

Privacy Policy

Last updated 29 September 2026

What we collect

  • Account data: your mobile number, the display name you choose, and organization membership.
  • Content: the files and folders you or your agents store, every version of them, and text we extract from them to power search.
  • Activity: an audit log of actions in each organization (who did what, when), API key usage times and the IP addresses requests come from.
  • Technical data: standard server logs needed to run and secure the Service.

How we use it

To provide the Service: authenticate you, deliver one-time codes by SMS, store and serve your content to authorised people and agents, index it for search, and keep the audit trail your organization relies on. We do not sell personal data and do not use your content to train models.

Search and AI processing

To enable semantic search, extracted text from files may be sent to a third-party embedding provider (currently OpenAI) to compute numerical vectors. Only the text needed for indexing is sent; it is not used by the provider to train its models under our agreement with them.

Service providers

We use DigitalOcean for hosting (servers located in India) and Twilio to deliver SMS verification codes. Each processes data only as needed to provide their service to us.

Sharing

Content is visible to the members and agent keys your organization authorises, and to anyone holding a public share link you create. We disclose data to third parties only with your instruction, to comply with law, or to protect the Service and its users.

Retention

Content and versions are kept until deleted by an authorised user (deleted items stay in the trash until purged). Audit logs are kept for the life of the organization. Server logs are kept for a limited period for security purposes.

Your rights

You can export your files at any time through the app or API, and you can ask us to delete your account and its data by contacting support@drivebot.in. We will respond within 30 days.

Security

Data is encrypted in transit. API keys and session tokens are stored only as one-way hashes. Access is controlled by the roles and grants described in the Help pages. Report security issues to support@drivebot.in.

Changes

We will post any changes to this policy here and update the date above.