What we keep depends on which way you run Satchel.
We ask for the drive.file scope only: we can see and change files this app created, and nothing else in your Drive.
We don't train models on your data. We don't sell it. We don't read it except to operate the service or when you ask us to help with your account. Request logs record the path of a file and which agent touched it, never the contents.
Export everything as a zip at any time (satchel_export from any agent, or /export). Delete everything with satchel_delete_everything or DELETE /me; hosted files are removed immediately, Drive files stay in your Drive.
Contact: pat.edwards@pm.me