When you hand a black-and-white photo to a colorization tool, you're really handing over something more valuable than the file itself: a piece of family history, a client's archive, an estate's private records. So the question underneath "will this look good?" is quieter but more important — is photo colorization safe? Where does my picture actually go?
For most web-based tools, the honest answer is uncomfortable. You upload your originals to a company's servers, they get processed somewhere you can't see, and you take it on faith that the copies are deleted afterward. Revive is built on the opposite premise. It's a Google Workspace add-on that colorizes photos inside Google Drive, and the defining fact of its design is this: your files never leave Google's infrastructure.
This post walks through exactly what that means, why it matters for photo colorization privacy, and how the drive-native model differs — concretely — from the "upload your photos here" tools you'll find everywhere else.
The problem with "upload your photos here"
The typical colorization service is a website with a drop zone. You drag in a photo, it travels across the public internet to that company's storage bucket, a model runs on it, and a colorized result is sent back to your browser. Along the way your original has been copied onto a third party's servers — often in a region and under a retention policy you never see.
That's fine for a single throwaway snapshot. It's a real problem when you're colorizing hundreds of family portraits, a museum's archive, or a studio's production stills. Every upload is a copy you no longer fully control, and "we delete after 24 hours" is a promise, not a mechanism.
How Revive is different: the file never leaves Google
Revive doesn't have a drop zone, because there's nothing to upload. It runs as an add-on inside Google Drive. When you open the side panel and pick a folder or a set of files, Revive reads those images through Google's own Drive APIs, colorizes them, and writes the finished copies straight back into the same folder — named filename-color.jpg. The picture is read from Drive and written to Drive. It is never staged in a third-party storage bucket you don't control.
Here's the full path a photo takes, with nothing hidden between the steps:
Because the whole round trip happens within Google's environment, the usual privacy questions largely dissolve. There's no "which region is my data in," no separate account holding copies of your originals, and no retention policy to audit on a third-party service — the files stay where they already lived. For a fuller walkthrough of the mechanics, see how it works.
Narrow permissions: the drive.file scope
Not every add-on that touches Drive is equally trustworthy, and the difference usually comes down to scope — how much of your Drive an app is allowed to see. Many tools request broad read access to your entire Drive. Revive uses the narrow drive.file scope, which means it can only see the specific files and folders you explicitly hand it through the picker.
In practice: Revive cannot browse your Drive on its own, cannot read documents you didn't select, and cannot reach into folders you never pointed it at. It sees the photos you queue for colorization and nothing else. That's the smallest possible footprint for a tool that has to read and write image files.
Tip: When you install any Workspace add-on, read the consent screen. A tool that asks to "see, edit, and download all your Google Drive files" is requesting far more than a colorizer needs. Revive asks only for access to files you specifically open with it.
Your originals are never modified
Safety isn't only about where a file goes — it's also about what happens to the one you started with. Revive never overwrites or alters your originals. Colorization always produces a new copy saved alongside the source as filename-color.jpg. Point it at a folder tree and the sub-folder structure is preserved, so a 10,000-image archive comes back organized exactly the way you left it, with every black-and-white original still intact.
That matters for archives and estates especially, where the original scan is often the record of authority. You get the colorized version as an addition, never as a replacement.
You pick the files
Open the side panel in Drive and select photos or a whole folder. Nothing is touched until you choose it — that's the drive.file scope at work.
Revive reads them in place
Images are read through Google's Drive APIs. No copy is uploaded to any outside server; processing stays within Google's infrastructure.
Color copies are written back
Each result lands in the same folder as filename-color.jpg. Your originals are left exactly as they were.
Every job is logged
Count, files, images spent, and who ran it appear in the usage report — so a team can account for exactly what was processed.
Built for teams, with a clear audit trail
Privacy at the individual level is one thing; accountability across an organization is another. Revive is domain-installable, and its credits are tied to a shared billing account that every Workspace user can draw on. Crucially, every job is attributed in the usage report — count, files, images spent, and who ran it. So when a library, studio, or agency colorizes a collection, there's a record of exactly what was processed and by whom, without anyone's files ever leaving the organization's own Drive.
Drive-native vs. upload-and-hope
Put the two models side by side and the difference in exposure is stark:
Typical upload tool
- Your original is copied to a third-party server
- Data may sit in an unknown region under an opaque retention policy
- Deletion is a promise you can't verify
- Often requests broad access or a full re-upload per batch
- No shared, attributable record of who processed what
Revive (drive-native)
- Files are read and written in place inside Google Drive
- Nothing leaves Google's infrastructure; no third-party storage
- Originals are never modified — color copies are added alongside
- Narrow
drive.filescope: only the files you select - Every job attributed in a shared usage report
None of this comes at the cost of speed or scale. Revive colorizes a photo in roughly 50–100 milliseconds and can push through about 1,000 images in a minute — folder-aware, batched, and entirely within Drive. Staying private and staying fast are not a trade-off here.
What you actually pay for
The privacy model has a pricing consequence worth naming: because there's no subscription and no data being warehoused on Revive's side, you simply buy image credits and use them when you like. 1 image = 1 colorized photo, credits never expire, and failed jobs are auto-refunded — you only pay for results. Packs start at $9 for 100 images ($0.09 each) and scale down to about 5¢ per photo at volume. Full numbers are on the pricing page.
| Pack | Price | Images | Per image |
|---|---|---|---|
| Basic | $9 | 100 | $0.09 |
| Standard | $29 | 400 | $0.073 |
| Premium | $59 | 900 | $0.066 |
| Enterprise | $129 | 2,000 | $0.065 |
| Custom | Talk to sales | 2,000+ | down to 5¢ |
Trying it safely
The best way to satisfy yourself that photos are safe is to watch the model work on your own Drive. Signing up gives you 3 free images with no credit card, so you can colorize a few photos, confirm the color copies appear right next to your originals, and see that nothing else in your Drive was touched. If you're setting it up for a team, the setup guide covers domain install and shared billing, and our piece on colorizing an entire Drive folder shows the folder-aware workflow end to end.
Photo colorization safe enough for a family archive shouldn't require you to ship that archive across the internet first. With a drive-native design, it doesn't.
See it on your own photos
Install Revive, pick three photos in your Drive, and watch the color copies appear right beside your originals. Nothing leaves Google.
Start free — 3 photos
Revive

