Media2URL
Privacy

Privacy Policy

How Media2URL handles account data, uploaded files, public links, security signals, abuse reports, and legal requests.

Last updated: September 30, 2026

This Privacy Policy explains what Media2URL processes when you visit the service, create an account, upload or share a file, use an integration, contact support, or submit an abuse or copyright report. It is written to describe the real operating purposes of the platform; it is not a promise that every security or privacy risk can be eliminated.

The policy applies to visitors, account holders, workspace members, recipients of shared links, API and integration users, reporters, and people who contact us about safety or legal matters. Rights available under the law that applies to you are not limited by this policy.

1. Who Operates Media2URL

Media2URL is operated by Sagar Kumar Sahu, sole proprietor trading as Sagarvo Labs, with a business address at Infocity Road, Bhubaneswar, Odisha 751021, India. Where applicable privacy law uses the concept of a controller or a similar responsible business, Sagar Kumar Sahu, sole proprietor trading as Sagarvo Labs is responsible for the personal information that Media2URL processes for its own product operations.

For privacy questions or requests, contact support@media2url.com. Account related requests should normally be sent from the email address connected to the account because this helps us verify that information is not disclosed or deleted for the wrong person.

2. Information We Process

Account and workspace data: We process the email address and authentication information needed to sign in, workspace membership and roles, plan and entitlement information, integration identifiers, and account-support communications. Payment providers process full payment credentials; Media2URL receives the billing status and transaction details needed to operate subscriptions.

Files and asset metadata: We process the file supplied to the service and the records needed to store, validate, transform, deliver, organize, replace, and remove it. This can include the original filename, file type, size, checksum or signature results, storage object key, dimensions or duration, folder and workspace relationship, link slug, privacy setting, expiry, download or view settings, and password hash where password protection is used.

Security and abuse signals: Requests may produce IP address or IP-derived rate-limit values, user agent, request time, route, status, bandwidth and quota events, authentication events, upload validation results, abuse reports, moderation actions, and integration or API activity. We use the minimum information reasonably needed for security, fraud prevention, troubleshooting, and enforcement. We do not need to retain a readable copy of a password to verify password-protected links.

3. Why We Use This Information

Service delivery: We use account, asset, link, workspace, and usage data to upload, store, process, organize, replace, share, and delete files; enforce plan entitlements and quotas; provide direct URLs and share pages; and respond to support requests.

Security and abuse prevention: We use validation results, rate limits, account and workspace signals, delivery events, reports, and other security data to detect spam, automated abuse, malware or phishing indicators, privacy violations, copyright complaints, evasion, and attacks against the platform. This may involve automated checks followed by human review.

Legal and operational purposes: We process information to comply with lawful requests, protect users and the service, investigate incidents, maintain records, resolve disputes, prevent fraud, improve reliability, and enforce the Terms of Service and Acceptable Use Policy. We do not sell uploaded files or use the contents of uploaded files for behavioral advertising.

4. Public Links Are Not Confidential Storage

A public or unlisted link can be opened by anyone who obtains the URL. A direct media URL, embedded image, custom delivery-domain URL, share page, QR code, or downloaded copy can be forwarded or copied by a recipient. Unlisted means less discoverable, not private or confidential.

Private and password-protected links use additional access checks, but they cannot prevent a recipient from copying a URL, sharing a password, taking a screenshot, or redistributing a file after access. Do not upload passwords, recovery codes, private keys, regulated records, or other material that requires a dedicated confidential-storage system.

Media2URL may use no-index controls on appropriate user-generated pages, but search-engine controls cannot guarantee that a URL will never be discovered or that a third party will not publish a copy elsewhere.

5. Abuse Reports, Review, and Strict Response

A report may include the exact hosted URL, category, explanation, reporter contact details, safe evidence, and technical information required to prevent repeated submissions. Do not download, attach, or email suspected illegal material or live malware merely to make a report.

Reports are triaged by urgency. Credible child-safety concerns, active malware or phishing, non-consensual intimate content, serious threats, and similar immediate risks may cause access to be restricted before the investigation is complete. Repeated independent reports may also trigger a temporary delivery block while an operator reviews the asset; a report count is a triage signal, not by itself a final finding.

When enforcement is required, Media2URL may disable the file and its links across direct delivery, share pages, variants, transformations, downloads, and verified custom delivery domains; quarantine or remove versions and generated outputs; restrict uploads; suspend or terminate an account or workspace; revoke integration credentials; preserve limited evidence; and report conduct to authorities or rights holders when required or appropriate.

6. Service Providers and International Processing

Media2URL uses service providers for application hosting, authentication and database services, object storage and CDN delivery, email, payments, monitoring, and related operations. Providers receive only the information needed for their assigned function and may process it in the countries where they operate.

Examples of current infrastructure providers include Supabase, Cloudflare R2/CDN, application hosting providers, payment processors, and transactional email providers. The provider list and processing arrangements may change as the service grows; material changes will be reflected in this policy where required. For specific disclosures regarding data collected through Google APIs, please see Section 7 below.

When a Merchant of Record processes a paid Media2URL transaction, that provider acts as the seller for the payment and processes the billing information needed to complete the purchase, calculate applicable taxes, prevent fraud, issue receipts, handle refunds, and manage payment disputes. The Merchant of Record processes that information under its own privacy notice and legal responsibilities.

Media2URL does not need to receive a complete payment card number or card security code from the Merchant of Record. We may receive a customer or transaction identifier, subscription status, plan information, payment status, billing country, refund status, and other limited information needed to activate the plan, provide support, reconcile billing, and respond to a payment issue.

Where applicable law requires safeguards for international transfers, Media2URL will use a lawful transfer mechanism and appropriate contractual or organizational protections. Nothing in this paragraph promises a particular legal mechanism in every country.

7. Google Workspace API & User Data Policy (Data Sharing and Transfer Disclosures)

Google Workspace Data Access: When you install and use the Media2URL Google Workspace Add-on (for Google Docs, Google Sheets, Google Slides, and Google Drive), Media2URL accesses only the minimum Google user data necessary to provide document-conversion, publishing, and link/QR code generation services. Specifically, this includes: (a) your Google account email address (used solely to associate published assets with your Media2URL account and display your connection status), (b) document and file metadata (such as file ID, title, and MIME type, accessed solely to display active file context in the add-on sidebar), and (c) the binary contents of documents or images that you explicitly select to export, convert, or publish.

How Google User Data Is Used: Google user data is processed strictly in response to explicit, real-time user actions within the Google Workspace interface—specifically when you choose to export a document as a PDF or DOCX, upload a selected image from a document or sheet, or generate a public CDN link and QR code. Media2URL does not access, scan, or process your Google Drive files or document contents in the background without your explicit action.

With Whom Google User Data Is Shared, Transferred, or Disclosed: Media2URL only transfers Google user data to necessary, trusted cloud infrastructure sub-processors strictly for the operational purpose of executing the user's requested actions: (1) Cloudflare (Cloudflare R2 Object Storage and Global CDN), which stores published files and delivers the generated public URLs and QR codes requested by the user, and (2) Supabase, which provides secure database and authentication session management to track file ownership and usage quotas. Both sub-processors process data under strict confidentiality obligations and enterprise security standards.

No Sale, Advertising, or Unauthorized Transfer: Media2URL does not sell, rent, lease, trade, or transfer Google user data to any third parties, data brokers, advertising networks, or marketing platforms. Google user data is never shared with third parties for promotional or behavioral tracking purposes.

Prohibition on AI/ML Model Training: Google Workspace user data obtained through Google Workspace APIs is NEVER used, transferred, or disclosed to develop, improve, or train generalized artificial intelligence (AI) and/or machine learning (ML) models.

Google Limited Use & Developer Policy Compliance: Media2URL's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and the Google Workspace API User Data and Developer Policy.

Data Retention, Revocation, and Deletion: Google user data is retained only for as long as necessary to maintain the published files and links you create. You can disconnect and revoke Media2URL's access to your Google account at any time using the 'Log Out / Disconnect' button directly inside the Google Workspace Add-on sidebar, or through Google Account Security Settings at myaccount.google.com/connections. You may also request complete deletion of your account, published assets, and associated data at any time by contacting privacy@media2url.com.

Data TypeCollection & Processing PurposeWith Whom Data Is Shared / TransferredRecipient Role & Safeguards
Google Account EmailUser authentication, session linking, and displaying connected account status in the Add-on sidebarSupabase (Database / Auth)Strict sub-processor confidentiality; encrypted in transit and at rest. Never sold or shared with advertisers.
Drive File Metadata (File ID, Name, MIME type)Displaying active document context and filename preview in the Add-on sidebarNone (Processed ephemerally in Google Apps Script runtime)Not stored on external servers or transferred to third parties.
Exported Document & Image ContentConverting documents to PDF/DOCX, extracting selected images, and generating direct CDN links and dynamic QR codes as explicitly requested by userCloudflare (Cloudflare R2 Object Storage & CDN)Enterprise-grade encrypted storage and CDN delivery. Strictly used to host user-requested public links. Never used for AI/ML training.

8. Retention, Deletion, and Legal Holds

Files and asset metadata are retained while needed to provide the service, honor link settings, maintain versions, enforce quotas, investigate abuse, resolve disputes, or comply with law. Expired, deleted, or disabled content may become inaccessible immediately while technical deletion completes asynchronously.

A file restricted after an abuse report is not automatically deleted merely because it was reported. It may remain in a restricted state for operator review. After a confirmed violation, Media2URL may permanently remove the asset, versions, variants, and storage objects, while retaining limited report, audit, or legal records when reasonably necessary.

Deletion may be delayed or limited by legal holds, fraud prevention, security investigations, billing records, dispute handling, backup cycles, or another legal obligation. Backups are for service recovery and are not a customer archive or a promise of selective restoration.

9. Privacy Rights and Requests

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of certain personal information. Send requests to support@media2url.com from the account email when possible. We may verify identity, request clarification, and apply lawful exceptions before completing a request.

A request to delete information does not require Media2URL to restore content, remove records that must be preserved, or erase information that has already been copied by another person. We may retain a limited record of the request and its outcome for accountability and legal compliance.

10. Security Boundaries and Incident Response

Media2URL uses access controls, restricted storage credentials, HTTPS, validation, rate limits, controlled object keys, and delivery-state checks to reduce unauthorized access and abuse. No online service, CDN, browser, or storage system can guarantee perfect security.

If we confirm a security incident, we will investigate, contain affected access, revoke or rotate credentials where appropriate, preserve relevant evidence, and provide notices required by applicable law. Report suspected account compromise, exposed credentials, harmful files, or platform vulnerabilities promptly.

11. Children, Policy Changes, and Contact

Media2URL is not directed to children. A person using the service must meet the minimum age required by the law that applies to them and must have any authorization that the law requires.

If we learn that personal information was submitted by a person who could not lawfully provide it without the required authorization, we may restrict the account and remove the information where required by law. A parent, guardian, or other authorized person can contact support@media2url.com if they believe this situation has occurred.

We may update this policy when the service, providers, legal requirements, or abuse-response practices change. The effective date shown on this page identifies the current version. If a change materially affects how we use personal information, we will provide notice where required.

For privacy, security, abuse, copyright, or account questions, contact support@media2url.com or use the Contact page. Do not send passwords, secret keys, live malware, or unnecessary sensitive files in a support message.

Contact Media2URL about this page

If you have questions about this policy, your account, billing, uploads, abuse reports, DMCA notices, privacy requests, refunds, or legal/safety concerns, visit the Contact page or email us directly. For account specific requests, email from the account address when possible.