Privacy Policy

Last updated: April 2, 2026

1.Information We Collect

We collect and store the minimum information needed to provide the service: your email address (from Clerk authentication), file metadata (names, sizes, types, upload dates), and the files you choose to upload. We do not collect browsing history, analytics data, or any personal information beyond what you explicitly provide.

2.How We Use Your Information

Your email address is used solely for authentication and to send you notifications you request (such as file download emails). File metadata powers your dashboard — folders, search, previews, share links, and usage statistics. Your files are stored as-is and served back to you or your share recipients on demand.

3.File Storage (Your Organization's Bucket)

FileDrop does not host files. Your organization connects its own S3-compatible storage bucket (any S3-compatible endpoint), and all uploaded files are stored in that bucket under your control. We generate temporary presigned URLs to allow your browser to upload and download files directly to/from your bucket — we never proxy file data through our servers during transfer. Storage provider credentials are encrypted at rest in our database; only the organization's administrators can manage them.

4.Authentication (Clerk)

User authentication is handled entirely by Clerk. We never see or store your password. Clerk provides us with a user identifier and email address after successful authentication. For more details, see Clerk's privacy policy at https://clerk.com/privacy.

5.Email Delivery (Resend)

When you share a file via email, we send the message through Resend. Resend receives the recipient's email address and the content of your message. We track delivery status (sent, delivered, opened, bounced) to show you real-time updates in your dashboard. For more details, see Resend's privacy policy at resend.com/legal/privacy-policy.

6.Third-Party Services

We use Clerk (authentication), MongoDB (database), and Resend (email delivery). Your organization's storage bucket is provided by the S3-compatible provider you choose. Each service processes data only as necessary to provide its function. We do not sell, rent, or share your data with any third parties for their own purposes.

7.Data Transfers & CDN

Downloads and previews are served directly from your organization's storage bucket via presigned URLs. Files are streamed directly from storage to the recipient — no intermediate servers.

8.Data Retention

Files are retained until you delete them. Share links are purged once they expire. Email logs are retained until you manually delete them from your dashboard.

When you delete your account, all your files are removed from storage, all share links are deleted, and all file metadata is removed from our database.

9.Cookies

We use essential cookies required for authentication (Clerk session tokens) and a minimal admin session cookie if applicable. No tracking, analytics, or marketing cookies are used. You can block all cookies via browser settings, but authentication will not work.

10.Your Rights

You can download, delete, or export your files at any time from your dashboard. To delete your account entirely, click "Delete account" in your dashboard settings. If you need help, contact us at [email protected].

11.Changes to This Policy

We may update this policy from time to time. Significant changes will be communicated via email or a notice on the dashboard. Continued use of FileDrop after changes constitutes acceptance of the updated policy.