Privacy in Vulcan Drive
Technical data map available in this local revision
Reviewed on September 5, 2026
1. Scope of this page
This page describes what the current code can process. It does not state that every capability is enabled in every environment. Region, retention period, legal basis, and subprocessors require operational and legal validation before this revision is published.
2. Separate data and purposes
Account: identity and session data needed to authenticate access. Private Drive: file bytes, name, type, size, versions, folders, and operational states needed to store, list, search, and recover files. Private indexing: extracted content and technical artifacts for the current version, used for search and organization when the corresponding feature is enabled. ONIXBRAIN: eligible private files feed local knowledge automatically. Individual exclusions are immediate and reversible. This local purpose does not authorize transfer to an AI provider or export.
3. Technical boundaries verified in code
The application has an object storage adapter for Backblaze B2 and uses Supabase for identity and structured data. This describes the implementation and does not confirm the region, contract, or configuration of a specific environment. Assisted organization has a conditional Google Gemini transport. Its mode can be off. The AI gateway is a separate capability and does not prove that a request occurred. The worker has a conditional integration with a self-managed OCR service for eligible documents. Disabled OCR is not automatically replaced by another provider.
4. Controls and limits
Drive reads are scoped to the authenticated user. Transfer URLs are temporary, and the server revalidates identity, current version, and purpose for sensitive operations. Diagnostics accept enumerated technical fields and bounded pseudonyms. Pseudonymization is not anonymization. Revoking a source prevents new application use after confirmation. It cannot retrieve bytes already sent, downloaded exports, or data already viewed on another device.
5. Retention, region, and requests
This revision does not publish a retention period, processing region, legal basis, or contractual subprocessor list without responsible confirmation. For data questions or requests, use the contact channel shown in the product. The applicable response depends on verified identity and current obligations.