byteport
Privacy Policy

Legal

Privacy Policy

Last updated July 31, 2026

Byteport lets you connect the cloud storage and object-storage accounts you already have — Google Drive, Dropbox, OneDrive, Box, Amazon S3, Cloudflare R2, Wasabi, Backblaze B2, Google Cloud Storage, and Azure Blob Storage — and browse and list your files from one place. This policy explains what we collect, how we access and use the file data in the storage you connect, how we store and protect it, who we share it with, and the choices you have. In short: we read only file metadata to show you your files, we never download or store the contents of your files, and we don’t sell your data.

Who this covers

“Byteport” (“we”, “us”) operates the Byteport dashboard at dashboard.byteport.com and the Byteport API at api.byteport.com. This policy applies to both. It does not cover the third-party cloud providers you connect — their handling of your data is governed by their own privacy policies.

Information we collect

  • Account information. Your name and email address, handled through our authentication provider (Supabase), to create and secure your account.
  • Storage-connection credentials. To connect a provider you either authorize us via OAuth (Google Drive, Dropbox, OneDrive, Box) or provide access keys (Amazon S3, Cloudflare R2, Wasabi, Backblaze B2, Google Cloud Storage, Azure Blob Storage). For OAuth we store the resulting access and refresh tokens; for key-based providers we store the access key and secret (and, where needed, a region or endpoint). All of this is encrypted at rest — see How we store and protect your data.
  • File metadata. When you browse a connection we retrieve metadata about your files and folders — names, sizes, types, and modification dates — to display and navigate your file list. We do not retrieve, open, or store the contents of your files.
  • Support information. If you contact support, the subject, message, and any attachments you send — along with your name and email — are processed to answer you.
  • Billing information. An account identifier, your email, and usage counts, used for metering and billing. Payment card details are handled by our payment processor and are never stored by Byteport.
  • Technical information. Standard request data needed to operate and secure the service. We do not run third-party advertising or analytics trackers by default.

How we access and use your file data

With the authorization you grant (OAuth) or the keys you provide, we connect to your storage provider on your behalf for a single purpose: to list your files and folders — their names, sizes, types, and modification dates — so you can browse and navigate them. That is the only thing we do with your storage access.

We do not:

  • download, open, read, or store the contents of your files — file bytes never pass through or reside on Byteport servers;
  • use your file data or metadata for advertising, profiling, or any purpose other than providing the features you use;
  • sell your data or share it with data brokers; or
  • use your data to train machine-learning or AI models.

We access this data solely to provide the file listing you use, and we retain the access only for as long as your connection exists (see Retention and deletion).

OAuth permissions we request

We request the minimum, read-only permissions needed to list your files and folders and read their metadata. None of these grant access to file contents or the ability to modify, create, or delete anything in your account.

ProviderAccess requestedWhat we do with it
Google DriveView file metadata, read-only (.../auth/drive.metadata.readonly)List your files and folders and read their metadata. No access to file contents; no write access.
DropboxRead file and folder metadata (files.metadata.read); read account infoList your files and folders and read their metadata. No access to file contents.
OneDriveRead your files, read-only (Files.Read); read your basic profileList your files and folders and read their metadata. No write access; no content stored.
BoxRead-only access to your Box filesList your files and folders and read their metadata. No write access.

You can review and revoke Byteport’s access at any time from your provider’s own security settings (for example, your Google Account permissions page or Dropbox’s connected-apps page).

Google API Services User Data Policy. Byteport’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the file browsing and sharing features you request, do not transfer it except as needed to provide those features or as required by law, do not use it for advertising, and do not allow humans to read it except with your consent, for security, or as required by law.

Our use of information from the Microsoft (OneDrive), Dropbox, and Box APIs is likewise limited to providing the features you request and is governed by those providers’ developer terms.

How we store and protect your data

  • Credentials and tokens are encrypted at rest using AES-256-GCM envelope encryption, with a per-account data key wrapped by AWS Key Management Service (KMS). They are decrypted only transiently, in memory, to communicate with your provider — they are never returned to your browser and never written to our logs.
  • File metadata is cached only in your browser for a short time (to keep the interface responsive) and clears automatically; it is not stored on our servers.
  • Infrastructure. Byteport runs on Amazon Web Services (Aurora PostgreSQL for account and credential storage, KMS for encryption keys) across multiple regions. Data in transit is protected with TLS.

Who we share data with

We do not sell your personal information. We share data only with (a) the cloud providers you connect — necessarily, to carry out your requests — and (b) the service providers we rely on to operate Byteport:

ServicePurposeData involved
SupabaseAuthentication and account databaseName, email, account records
Amazon Web ServicesHosting, database, encryption keysEncrypted credentials, account data
PlainCustomer supportName, email, and the ticket text/attachments you send
Autumn & StripeBilling and paymentsAccount id, email, usage counts, payment details
Email providerTransactional emailEmail address

We may also disclose information if required by law, to enforce our terms, or to protect the rights, safety, and security of Byteport and its users. If Byteport is involved in a merger or acquisition, we will notify you before your information becomes subject to a different privacy policy.

Retention and deletion

  • We keep your connection credentials and tokens until you remove the connection or delete your account.
  • Removing a connection permanently deletes the credentials and tokens we stored for it.
  • Deleting your account deletes your account and the connection credentials and tokens associated with it.
  • You can also revoke Byteport’s access at any time directly from your provider’s security settings, independently of Byteport.
  • File metadata cached in your browser clears automatically (within about 30 minutes) and when you sign out.

Your rights and choices

You can access and update your account information, remove any connection, revoke provider access, and delete your account at any time from the dashboard. Depending on where you live (for example under the GDPR or CCPA), you may also have the right to access, correct, delete, or export your personal information, or to object to certain processing. We do not sell personal information. To exercise any of these rights, contact us at help@byteport.com.

Security

We protect your data with encryption at rest (AES-256-GCM with AWS-KMS-managed keys) and in transit (TLS), least-privilege access, and the practice of never returning your stored credentials to the browser or writing them to logs. No method of transmission or storage is completely secure, but we work to protect your information and to promptly address any issues.

International transfers

Byteport is operated from the United States and processes data on AWS infrastructure that may be located in the United States and other regions. Where we transfer personal information across borders, we do so in reliance on appropriate safeguards. By using Byteport you understand your information may be processed in these locations.

Changes to this policy

We may update this policy from time to time. When we do, we’ll revise the “last updated” date above, and for material changes we’ll provide additional notice. Your continued use of Byteport after an update means you accept the revised policy.

Contact

Questions about this policy or your data? Email us at help@byteport.com.

© 2026 ByteportTermsHome