At FileShareFast, we prioritize your data privacy and security. This Privacy Policy outlines our practices regarding the collection, use, and disclosure of your information when you use our service.
1. Information We Collect
FileShareFast is designed with privacy-focused principles. We collect information necessary to provide our service:
- Uploaded Files: The files, names, sizes, and media types you submit for storage and sharing.
- Account Information: If you register, we collect your email address and basic profile information.
- Usage and Security Data: Authentication, administration, download, and analytics events may include an IP address, user-agent information, access time, and requested resource. The current contact and trust-report endpoints do not write the raw source IP for new submissions; when configured, the service derives a keyed, pseudonymous source fingerprint for short-window abuse throttling.
2. How We Use Your Information
We use the information we collect to operate and improve the FileShareFast platform:
- To process file transfers, store uploaded objects, and deliver authorized downloads.
- To manage your account and provide customer support.
- To detect, prevent, and address technical issues and abusive behavior.
3. Data Security and Encryption
Production traffic is intended to use HTTPS for data in transit. Storage-at-rest controls and storage location depend on the provider configured for the deployment; FileShareFast does not implement browser-side, end-to-end file encryption. If you use password protection, the application stores a password hash and checks it before granting time-limited browser access. A share password is an access gate, not a file-encryption key.
4. Link Expiration and Data Retention
Guest share links have a fixed expiry of 14 days after upload; the guest upload flow does not offer a duration selector. Expiry stops access to the link. An expired share can remain in a recovery state for up to 30 days and becomes eligible for permanent storage and database removal when the cleanup process runs. Signed-in shares currently have no automatic expiry, although their owners can expire, trash, recover, or permanently remove them through the available controls. Account deletion also removes shares owned by that account. Operational backups and third-party retention, if any, depend on the configured deployment and applicable obligations.
Contact messages and trust-and-safety reports are stored in the operational database for review. The current application does not apply an automatic deletion schedule to those records. The operator must define and publish a retention schedule that reflects its legal and operational obligations, then implement the corresponding deletion process.
5. Data Sharing and Disclosure
We do not sell your personal data. We may share your information only in the following limited circumstances:
- Service Providers: We may use the hosting, storage, authentication, email, and analytics providers configured for the deployment to operate the service. The operator is responsible for keeping provider disclosures and agreements current; this policy does not identify an unverified provider by name.
- Legal Requirements: If required by law, subpoena, or other legal processes, we may disclose information to law enforcement agencies.
6. Your Data Rights (GDPR & CCPA)
Depending on your location, you may have rights to access, correct, or delete your personal data. You can exercise these rights by contacting our support team. We provide easy-to-use tools within your dashboard to manage and delete your files and account at any time.
7. Changes to This Policy
We may update our Privacy Policy from time to time. We will notify you of any significant changes by posting the new Privacy Policy on this page and updating the "Effective Date" at the top.
8. Contact Us
If you have any questions about this Privacy Policy or our data practices, please use our contact form.