Last updated · August 1, 2026

Privacy Policy

This policy explains what Purgify collects, why it collects it, and how you stay in control. The short version: we collect the minimum each feature needs, and we never sell your data.

01Who we are

Purgify is a multi-cloud storage cleanup service operated by Auris, a company based in Santiago, Chile. Purgify helps you find duplicates, stale files and reclaimable space across the cloud storage providers you choose to connect.

02Information we collect

We collect the minimum needed to run the service:

  • Account information: the email address you sign up with, used for authentication.
  • Provider credentials: OAuth access and refresh tokens issued by the providers you connect (Microsoft OneDrive, Dropbox, Box, Google Cloud Storage), or the bucket credentials you enter yourself (Amazon S3, Backblaze B2). We use them only to perform the actions you request.
  • File metadata: file names, paths, sizes, modification dates and content hashes, read from your connected providers to detect duplicates and cleanup candidates.
  • Cleanup records: when a cleanup or a scheduled rule deletes files, we keep the paths of what was removed so you can audit afterwards what disappeared.

03Data minimization

Purgify requests the least access needed for each feature. Scans read metadata only — names, paths, sizes, dates and the content hashes your provider already publishes — so finding duplicates never requires us to read your files.

Transfers are the exception. To copy a file from one provider to another, its content has to pass through our servers: it is streamed straight from the source to the destination, held in memory only for the moment it takes to move it, and never written to disk or stored.

We do not collect browsing history, contacts, or any data unrelated to storage management.

04Moving files between clouds

Purgify can copy or move files between the providers you have connected. The transfer runs entirely on our servers: your browser never receives file content, provider credentials or signed provider URLs.

Nothing of the file content is retained. What we do keep is the checksum of each transferred file, which we compare against the source and the destination to confirm the copy arrived intact.

When you choose to move rather than copy, the original is deleted only after the copy has been verified at the destination.

05How we use your information

Your data is used exclusively to operate Purgify: scanning the accounts you connect, computing duplicate and cleanup reports, and showing you storage usage over time.

We do not sell your data. We do not show ads. We do not share your data with third parties beyond the cloud providers you explicitly connect.

06Third-party providers & OAuth

When you connect a provider through OAuth — Microsoft OneDrive, Dropbox, Box or Google Cloud Storage — you authenticate directly with that provider. Purgify never sees your provider password, and the permissions requested are always visible on the provider's consent screen before you approve them. The object stores (Amazon S3, Backblaze B2) have no consent screen: there you supply bucket credentials yourself, and they are encrypted at rest.

Purgify’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

07Data storage & security

Account data is stored with our database provider (Supabase). Provider OAuth tokens are encrypted at rest and are only decrypted server-side to perform the operations you request. All traffic between your browser, Purgify and the providers uses TLS.

08Scheduled cleanup rules

You can create rules that run on a schedule to keep storage tidy. By default every scheduled run pauses and asks you to approve the exact list of files before anything is touched, and each run is capped by the limits you set.

You can switch that confirmation off so a rule runs unattended. For providers with no recycle bin, doing so requires an explicit acknowledgement, because there the deletion cannot be undone. Rules only ever act on individual files, never on folders, and every run is recorded in your cleanup history.

09Data retention & deletion

Metadata snapshots and scan results are kept only while the related account connection exists. When you disconnect a provider, its stored tokens and scan data are deleted. When you delete your Purgify account, all associated data is removed.

10Free tools on this site

The free tools under /tools do not require an account and are not connected to the Purgify service. Every one of them — the PDF tools, the video tools, file encryption, the EXIF remover — runs entirely inside your browser: the files you open are never transmitted to us, and there is nothing for us to store. We do not operate any endpoint that accepts your files.

There is one deliberate exception, stated on the page itself:

  • Password strength checker: if you choose to run the optional breach check, the first five characters of your password's SHA-1 hash are sent to Have I Been Pwned's k-anonymity API. Your password and its full hash never leave your device, and the check only runs when you click the button.

11Usage analytics

We measure site usage with Umami, an analytics tool we host ourselves at umami.auris.cl. It sets no cookies, creates no identifier that follows you between sites, and shares nothing with third parties: the data stays on our own server.

We record page views and a handful of aggregate events about tool usage: which tool ran, with which settings (the quality level or codec chosen in the video compressor, for instance), whether the file was large or small in broad bands, and whether something failed and for which reason, from a closed list. It tells us which tools deserve more work and where people get stuck.

What never leaves your device, in an event or otherwise:

  • The name or contents of your files, or anything derived from them beyond a size band.
  • Passwords, passphrases, hashes or tokens.
  • The text you paste into a tool, or raw error messages.

12Revoking access

You can disconnect any provider from Purgify at any time. You can also revoke Purgify’s access directly from your provider’s security settings (for example Google Account permissions, Microsoft account privacy dashboard, or Dropbox connected apps). Revocation takes effect immediately.

13Changes to this policy

If this policy changes materially, we will update this page and the “Last updated” date above. Significant changes will be communicated in the app.

14Contact

Questions about privacy or your data? Write to [email protected] and we will get back to you.