Privacy Policy
Last updated: April 9, 2026
1. Introduction
FileDroppy ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our file sharing service at filedroppy.com (the "Service").
By using the Service, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
Account Information: When you register for an account, we collect your email address, display name, and password (stored securely hashed).
Files & Transfers: When you upload files, we temporarily store the files on our servers. We collect metadata such as file names, file sizes, upload dates, and expiration dates.
Usage Data: We automatically collect information about how you interact with our Service, including:
- IP address
- Browser type and version
- Pages visited and time spent
- Download counts for your transfers
Payment Information: If you subscribe to a paid plan, payment processing is handled by Stripe. We do not store your credit card details. Stripe's privacy policy applies to payment data.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process your file transfers and manage your account
- Send you transactional emails (transfer notifications, password resets)
- Process payments through Stripe for paid subscriptions
- Scan uploaded files for malware and viruses to protect all users
- Detect and prevent fraud, abuse, and security threats
- Comply with legal obligations
4. Data Storage & Retention
Your files are stored on our servers and are automatically deleted when the transfer expires (7 days for free users, 30 days for Pro users). You can also manually delete your transfers at any time from your dashboard.
Account data is retained as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where retention is required by law.
5. Data Sharing
We do not sell, trade, or rent your personal information to third parties. We may share your data only in the following circumstances:
- With your consent: When you share a file transfer link, recipients can access the files you uploaded
- Service providers: We use Stripe for payment processing and Gmail SMTP for transactional emails
- Legal requirements: We may disclose information if required by law, regulation, or legal process
6. Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- HTTPS encryption for all data in transit
- Secure password hashing (bcrypt)
- Virus scanning of all uploaded files
- CSRF protection on all forms
- Optional password protection for transfers
While we strive to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
7. Cookies
We use session cookies to maintain your login state and CSRF tokens for security. We do not use tracking cookies or third-party advertising cookies.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and personal data
- Portability: Request your data in a portable format
- Objection: Object to certain processing of your data
To exercise any of these rights, contact us at [email protected].
9. Children's Privacy
The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.
11. Contact Us
If you have any questions about this Privacy Policy, please contact us at [email protected].