Privacy Policy
Contents
1. Overview
CloudBox is an iOS application that lets you connect the cloud storage accounts you already own — such as Google Drive, Microsoft OneDrive, Dropbox and network drives — and browse them as a single library. CloudBox is a client application, not a storage service.
The short version: CloudBox does not store the contents of your files on our servers. When you move, upload or download a file, it transfers directly between your device and your own cloud account. We do not sell your data, and we do not use your file content for advertising or to train AI models.
2. Who we are
CloudBox is developed and operated by MONI TECHNOLOGY CO., LTD. ("MONI", "we", "us"). For any privacy question, contact us at support@moniai.app.
This policy applies to the CloudBox iOS application and the website at cloudbox.moniai.app.
3. What data CloudBox accesses
CloudBox only requests the access it needs to show you your files and manage your storage.
| Data | Why CloudBox needs it | Where it lives |
|---|---|---|
| File and folder metadata (name, size, type, dates, folder path) | To display your unified library, calculate storage totals, and detect duplicates | Processed on your device; cached locally on your device only |
| File content | Only when you explicitly open, preview, upload, download or move a file | Streamed between your device and your cloud account — never stored by us |
| Storage quota (used / total) | To show how full each account is and choose the best account for Smart Upload | Processed on your device |
| Account identifier (email or account name) | To label each connected account in the interface | Stored on your device |
| OAuth access & refresh tokens | To stay connected to your accounts without asking you to sign in repeatedly | iOS Keychain on your device, encrypted by the operating system |
| Anonymous crash & diagnostic reports | To find and fix bugs. Contains no file names and no file content. | Apple / our crash reporting provider; can be disabled in iOS settings |
| Email address (waitlist only) | To notify you once, when CloudBox launches | Our waitlist provider; deleted on request |
What CloudBox does not collect
- We do not collect your cloud account passwords. Sign-in happens on the provider's own page.
- We do not store copies of your photos, videos or documents on our infrastructure.
- We do not build advertising profiles, and we do not sell personal data to anyone.
- We do not use your file content to develop, improve or train any AI or machine-learning model.
4. Google API Services disclosure
When you connect a Google Drive account, CloudBox accesses your Google user data through Google's official APIs, with your explicit consent given on Google's own OAuth consent screen.
CloudBox's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Scopes CloudBox requests
| Scope | What it allows | Why CloudBox needs it |
|---|---|---|
drive.readonly |
Read file metadata and content in your Drive | To list your files in the unified library, calculate storage use, detect duplicates, and preview or download files you select |
drive.file |
Create files, and access files the app itself created or you opened with it | To upload new files through Smart Upload and manage files you explicitly hand to CloudBox |
userinfo.email |
Read the email address of the signed-in account | To label the connected account so you can tell multiple Google accounts apart |
How Google user data is used
- Google Drive data is used only to provide the user-facing features described in this policy — browsing, storage analytics, duplicate detection, upload, download and organisation.
- Google user data is processed on your device. We do not transfer your Google Drive file contents to MONI servers.
- We do not transfer Google user data to third parties, except as required by law.
- We do not use Google user data for advertising, and we do not use it to train generalised AI or machine-learning models.
- We do not allow humans to read your Google user data, unless (a) you give explicit consent for a specific support issue, (b) it is necessary for security purposes such as investigating abuse, or (c) it is required by law.
Revoking Google access
You can disconnect a Google account at any time inside CloudBox (Settings → Cloud Accounts → Disconnect), or revoke CloudBox's access directly from your Google Account at myaccount.google.com/permissions. Revoking access immediately invalidates the stored tokens.
5. Other cloud providers
The same principles apply to every provider CloudBox supports:
- Microsoft OneDrive — accessed via Microsoft Graph API using OAuth 2.0. Subject to the Microsoft Privacy Statement.
- Dropbox — accessed via the official Dropbox API using OAuth 2.0. Subject to the Dropbox Privacy Policy.
- NAS / network drives — accessed over standard protocols using credentials you enter. These credentials are stored in the iOS Keychain on your device and are never transmitted to us.
When you connect a third-party account, that provider's own privacy policy governs how they handle your data on their side. CloudBox only acts on the instructions you give it.
6. Where your data is stored
- On your device: OAuth tokens (iOS Keychain), your list of connected accounts, app preferences, and a local cache of file metadata and thumbnails used to make browsing fast.
- On your cloud accounts: your actual files, exactly where they already are. CloudBox does not relocate anything unless you tell it to.
- On our servers: only your waitlist email address, if you submitted one, and anonymised crash reports. Nothing else.
Deleting the CloudBox app from your device removes the local cache and all stored tokens.
7. How we use data
We use the data described above solely to:
- Display your files and folders across connected accounts
- Calculate and show storage usage and analytics
- Detect duplicate and oversized files so you can free up space
- Perform uploads, downloads, moves and deletions that you initiate
- Choose the best destination account for Smart Upload
- Diagnose crashes and improve app stability
- Notify you once when CloudBox launches, if you joined the waitlist
8. Data sharing
We do not sell, rent, or trade your personal data. We share data only in these limited cases:
- Cloud providers you connect — requests you initiate are sent to the relevant provider's API.
- Service providers — crash reporting and waitlist email delivery, bound by contract to process data only on our instructions.
- Legal obligation — if required by applicable law, regulation, or valid legal process.
9. Revoking access & deleting your data
You are in control at all times.
Disconnect a cloud account
In CloudBox: Settings → Cloud Accounts → select account → Disconnect. This deletes the stored tokens and local metadata for that account.
Revoke from the provider
- Google: myaccount.google.com/permissions
- Microsoft: account.live.com/consent/Manage
- Dropbox: dropbox.com/account/connected_apps
Delete everything
Deleting the CloudBox app removes all locally stored data, including tokens and cached metadata. To have your waitlist email address removed from our records, email support@moniai.app with the subject "Delete my data". We will action the request within 30 days and confirm by email.
10. Security
- All communication with cloud providers uses encrypted HTTPS/TLS connections.
- OAuth tokens are stored in the iOS Keychain, protected by the device's hardware-backed encryption.
- CloudBox requests the narrowest set of permissions that still allows the features to work.
- We never ask for, receive, or store your cloud account passwords.
No system can be guaranteed perfectly secure, but we design CloudBox so that the most sensitive material — your files — never passes through our infrastructure in the first place.
11. Children's privacy
CloudBox is not directed at children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact support@moniai.app and we will delete it.
12. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you, to object to or restrict processing, and to lodge a complaint with your local data protection authority. Because CloudBox stores almost everything on your own device and in your own cloud accounts, most of these rights you can exercise directly in the app. For anything else, contact support@moniai.app.
13. Changes to this policy
We may update this policy as CloudBox evolves. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you in the app. Continued use of CloudBox after a change means you accept the revised policy.
14. Contact us
MONI TECHNOLOGY CO., LTD.
Email: support@moniai.app
Website: cloudbox.moniai.app
CloudBox is an independent application. It is not affiliated with, endorsed by, or sponsored by Google LLC, Microsoft Corporation, or Dropbox, Inc. All trademarks are the property of their respective owners.