Privacy policy

Effective 30 August 2026

This policy explains how Filencrypt handles information when you visit the site, create an account, store encrypted files, share a file or purchase a subscription.

Information we collect

We collect the information needed to provide and protect Filencrypt: your email address and authentication identifier; account, session, device-pairing, plan and storage-usage records; billing customer and subscription identifiers supplied by Stripe; encrypted file objects; and limited file metadata such as encrypted names, coarse file type, size and timestamps. We may also process an IP address and technical request details for fraud prevention, rate limiting and troubleshooting.

Your files and encryption

Files are encrypted in your browser before upload. Filencrypt stores ciphertext and does not receive the plaintext file or vault key. Password-protected shares remain encrypted until a recipient enters the password. Encryption protects file content, but account, billing, storage-usage and request metadata remain visible to the service as described above.

How we use information

We use information to create and authenticate accounts, operate vaults and sharing, process subscriptions, enforce storage limits, prevent abuse, respond to support requests, maintain security and comply with legal obligations. We do not sell personal information or use third-party advertising cookies or behavioural advertising analytics.

Service providers and international processing

We use Vercel for application hosting, Google Firebase and Google Cloud for authentication, databases and storage, and Stripe for billing. These providers process information under their own privacy and security terms and may process it in countries other than your own. We share only the information reasonably needed for them to provide those services or when disclosure is required by law.

Retention and deletion

Files and account records remain while your account is active or as needed to provide the service. Deleting a file removes its active ciphertext object. The in-product Delete account control permanently removes active vault files, shares, pairings, sessions and account data and ends any active subscription. Limited payment, security, support or backup records may remain where required for accounting, fraud prevention, legal compliance or disaster recovery, and are removed or anonymised when no longer needed.

Your choices and rights

You can access and correct core account information through the service, manage billing through the Stripe customer portal, delete individual files, or permanently delete your account from the vault. Depending on where you live, you may also request access, correction, deletion, restriction, portability or objection by contacting support. We may need to verify that you own the account before acting on a request.

Security and your responsibility

We use access controls, transport encryption and client-side file encryption, but no online system can guarantee absolute security. Keep your account password, vault credentials, file passwords and recovery information private. Filencrypt cannot recover a lost vault or shared file password.

Children and policy changes

Filencrypt is not intended for anyone under 18. We may update this policy as the service or law changes. Material updates will be posted here with a revised effective date.

Contact

For privacy or support requests, call or message +91 94866 23749.