Privacy Policy
Last updated: July 29, 2026
Teserro ("Teserro," "we," "us") provides a service that adds password protection, expiration, and access tracking to files shared from Google Drive ("the Service"). This policy describes what data we collect, why, and how it's handled.
1. Information we collect
From people who sign in to Teserro
- Google account information. Teserro uses Google Sign-In for authentication. We receive your name, email address, and Google account profile photo (if set) from Google. Teserro never sees or stores your Google password.
- Google Drive access. With your Google Workspace administrator's approval, Teserro requests read-only access to specific Shared Drives in order to list files and folders you choose to share. Teserro cannot create, modify, move, or delete anything in your Google Drive.
- Share configuration. Titles, expiration dates, and — for Direct Links — the password you set for that link, so it can be enforced when someone opens it.
From people who open a shared link
- Email address, if the link is a Tracked Link that requires one before viewing.
- Access activity — timestamps of when a link or file was viewed or downloaded, used to power the sender's activity log for that share.
Automatically, when you visit teserro.com
- Standard web analytics (pages visited, referring site, approximate location, device/browser type) via Google Analytics, but only after you accept our cookie banner. If you decline, no analytics cookies are set.
2. How we use this information, and our legal basis for doing so
- To operate the Service: authenticate you, enforce link passwords and expiration dates, and generate the view/download activity a share owner sees. Legal basis: performance of the contract with your organization (you're using the Service your Workspace admin set up).
- To send transactional email — invitations to join a tenant and expiration reminders — via our email provider, Resend. Legal basis: performance of the contract and our legitimate interest in keeping your account and shares functioning as expected.
- To understand how teserro.com is used, so we can improve it. Legal basis: your consent, given via the cookie banner — analytics cookies are never set before you accept, and you can decline with no loss of functionality.
- To maintain security and prevent abuse of the Service. Legal basis: our legitimate interest in keeping the Service and its users' data secure.
We do not sell personal information, and we do not use your data for advertising, ad targeting, or any cross-context behavioral advertising.
3. How information is stored and shared
- Application data (share metadata, access logs, account records) is stored in Google Cloud Firestore, hosted on Google Cloud infrastructure.
- Transactional emails are sent through Resend, which processes recipient email addresses solely to deliver those emails.
- Direct Link passwords are stored so the Service can enforce them and so the link owner can view and share the password they set; they are transmitted over encrypted (HTTPS) connections. They are separate from — and never replace — your Google account password, which Teserro never has access to.
- We do not share your data with third parties except the service providers above, or if required by law.
4. International data transfers
Teserro's infrastructure — Google Cloud Firestore, Firebase Authentication, and Resend — is hosted and processed in the United States. If you're accessing the Service from outside the US, your information will be transferred to and processed in the US. Our service providers maintain their own compliance certifications and contractual safeguards (such as Standard Contractual Clauses) for handling data transferred from the EEA, UK, and Switzerland.
5. Data retention
Share metadata and access logs are retained for as long as your organization's Teserro account is active, or as needed to provide the Service. You or your administrator can delete a share at any time, which removes its record from Teserro (the underlying file in Google Drive is never affected).
6. Your privacy rights
Regardless of where you're located, you can contact us at info@teserro.com to exercise any of the rights below. We'll respond within the timeframe required by applicable law. Your Google Workspace administrator can also revoke Teserro's access to your Shared Drives at any time from Google Workspace admin settings.
If you're in the EEA, UK, or Switzerland (GDPR/UK GDPR)
You have the right to: access the personal data we hold about you; request correction or erasure of it; restrict or object to our processing of it; receive a copy of it in a portable format; and withdraw consent at any time where processing is based on consent (e.g., analytics cookies), without affecting the lawfulness of processing before that withdrawal. You also have the right to lodge a complaint with your local data protection supervisory authority.
If you're a California resident (CCPA/CPRA)
Teserro does not sell or share personal information for cross-context behavioral advertising. You have the right to know the categories and specific pieces of personal information we've collected about you, request deletion or correction of it, and not be discriminated against for exercising these rights. We collect two broad categories of personal information as described in Section 1 above: identifiers (name, email address) and internet/network activity (access and usage logs). Note that Teserro is a young company and may not yet meet the revenue or data-volume thresholds that make the CCPA legally applicable — we're extending these rights as a matter of good practice either way.
Cookie choices
You can decline analytics cookies at any time via the cookie banner shown on your first visit to teserro.com, or by clearing your cookie preference and revisiting the site.
7. Security
We use industry-standard measures to protect data in transit (HTTPS/TLS) and rely on Google Cloud and Firebase's infrastructure security. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. Children's privacy
The Service is intended for business use and is not directed at children under 16. We do not knowingly collect personal information from children.
9. Changes to this policy
We may update this policy as the Service changes. Material changes will be reflected by updating the "Last updated" date above.
10. Contact
Questions about this policy, or want to exercise any of the rights above? Email info@teserro.com.