Storage architecture

Client-side encrypted storage in your own Google Drive

SovaSpace uses Google Drive as the customer-controlled cloud location for encrypted objects, while readable content remains on authorized devices.

What “your own Google Drive” means

SovaSpace does not ask customers to move their working library into a general-purpose NURSOVA content cloud. The app creates dedicated locations in the Google Drive connected by the customer and writes encrypted SovaSpace objects there. Unrelated Drive files are outside the requested storage model.

Titles, Entry text, tags, supported attachments, subtitles and separate annotation data files are encrypted on the device before upload. An authorized SovaSpace client downloads those encrypted objects and decrypts them locally when the required keys are available.

What the architecture changes

The storage account is visible to the customer in Google Drive, and encrypted objects count against that account's Google storage quota. This makes quota and account ownership concrete instead of hiding them behind an application-specific capacity number.

It also separates responsibilities:

  • Google Drive stores the encrypted cloud objects and necessarily processes Drive account, quota and object metadata.
  • NURSOVA's service layer coordinates limited account, trusted-device, entitlement and synchronization facts.
  • The SovaSpace client encrypts and decrypts supported user content on the authorized device.
  • The customer controls the Google account, endpoint security, exported plaintext and independent backups.

What encryption does not hide

Client-side encryption protects the readable contents of supported SovaSpace objects. It does not make all activity invisible. Google can observe that objects exist, their approximate sizes and access timing. NURSOVA can process limited operational facts needed for account, device and synchronization functions. The Security model explains these boundaries in detail.

An unlocked or compromised endpoint can also expose what the authorized user can see. Files deliberately exported as plaintext are no longer protected by SovaSpace's encrypted object format.

Quota remains a real limit

SovaSpace does not create additional Google storage. The practical cloud capacity is the available quota of the connected Google account, subject to Google's plan, regional availability, API rules and account status. Device storage, filesystem limits, memory and network conditions can impose separate constraints.

Encryption protects confidentiality; it is not a substitute for quota monitoring or an independent recovery copy.

Why this can be useful

This model is designed for people who want a private workspace without losing sight of where the cloud copy lives. It can also make use of storage capacity the customer already has, instead of requiring a second content-storage subscription solely to hold the encrypted objects.

For a practical explanation of eligible Google plans and existing capacity, read Use the Google Drive storage you already have.

See how the complete workspace fits together.

Review the full feature map, current platform availability and security boundaries before choosing a workflow.