1. Who controls your personal data
The service and its controller operate under the FilesUp brand.
For questions or requests about personal data, contact privacy@filesup.app. To report hosted content, use abuse@filesup.app or the Report page.
2. Data we process
If someone sends you files before you have an account, we receive your email address or phone number from the sender to deliver the share. The sender is responsible for having a lawful basis to provide your contact details.
| Category | Examples |
|---|---|
| Account and authentication | Email address or phone number, display name, language, one-time codes, session identifiers, timestamps and account status. |
| Consents and preferences | Version and language of accepted terms; optional marketing choice, source, date and changes; language preference. |
| Content and recipients | Files, messages, recipient email or phone, names and relative paths, type, size, technical hashes, thumbnails, availability and expiry times. |
| Sharing and activity | Topics, transfers, upload/delivery state, protected forms of public links, downloads, participants, timestamps and audit events. |
| Device and security | IP address and technical request information, browser, errors, usage limits, authentication attempts and signals needed for security, diagnosis and abuse prevention. |
| Requests and reports | Requester's identity and contact, request contents, reported URL or identifiers, evidence, review and decision. The abuse form also includes the IP observed by the API, request date and origin, browser/device, language, time zone, screen/viewport, navigation type, page and referrer without query parameters or fragments, resource identifier and a random reporting-session identifier. The form does not read general browser history or create a persistent canvas, audio or font fingerprint. |
3. Purposes and lawful bases
| Purpose | Lawful basis |
|---|---|
| Create and manage accounts; authenticate; upload, store, deliver and download files | Performance of a contract or steps you request before entering one. |
| Deliver a share to the nominated contact, keep the timeline and confirm activity | Our contract with the sender and legitimate interests in providing the requested delivery, balanced against recipient rights. |
| Security, fraud/abuse prevention, quotas, diagnosis and legal claims | Legitimate interests of FilesUp and its users and, where relevant, compliance with a legal obligation. |
| Codes, invitations, security alerts, operational and legal notices | Contract, legitimate interests in secure operation or legal obligation. These are transactional messages. |
| Marketing by email or SMS | Optional, specific and withdrawable consent. It is not required to open an account or receive the service. |
| Handle rights, orders, reports and illegal content | Legal obligation and legitimate interests in protecting rights and the service. |
4. How long we keep data
Deletion in distributed systems may be asynchronous. We may isolate and preserve specific data beyond general criteria when a legal duty, valid order, dispute or report requires proportionate retention.
| Data | Retention criterion |
|---|---|
| File binaries and download archives | Accessible for 240 hours (10 days) from availability, or less if deleted/revoked; technical object deletion then begins. |
| Timeline, messages, metadata, thumbnails and delivery/download history | While the account and relevant topic exist, unless deletion is requested or a lawful need to preserve them applies. |
| Public link/token and public-access cookie | Until the share expires, no more than 10 days for the cookie, or earlier revocation. |
| OTP challenges and sessions | Codes are one-time and short-lived; sessions last until expiry, sign-out or revocation. Minimal records may remain as needed for security. |
| Consents and terms | While the account exists and afterwards as needed to demonstrate choices, comply with obligations or establish and defend claims. |
| Logs, support, requests and reports | As needed for the purpose, risk, investigation, legal duties and applicable claim periods, subject to review and minimisation. |
5. Providers, recipients and transfers
These providers process data under applicable contracts and instructions or as independent controllers for operations they determine. If processing involves a transfer outside the European Economic Area, we will use the legally required mechanism, such as an adequacy decision or Standard Contractual Clauses, and supplementary safeguards where necessary.
- Cloudflare R2: object storage, including files, archives and thumbnails, and delivery through signed URLs as configured.
- MessageBird: sends and verifies SMS one-time codes when access uses a phone number.
- FilesUp's configured SMTP provider: sends email codes, share invitations and other transactional email.
- OpenAI: only when you expressly request a message suggestion; receives the recipient display name and file names, extensions and sizes, not file binaries. FilesUp sends the request with
store: false, without prejudice to limited processing the provider may perform for security and compliance with its terms. - Authorities, courts, advisers or prospective acquirers only where a lawful basis and appropriate safeguards apply.
6. Artificial-intelligence suggestions
The AI feature does not run automatically. A request occurs only after you click to obtain suggestions. FilesUp does not send file binaries to OpenAI and configures the response with store: false.
Suggestions are assistive and editable and do not make decisions with legal or similar effects. If you choose and send one, the selected text becomes part of the timeline like any other message.
7. Security and link limitations
We use proportionate technical and organisational measures, including protected connections, hard-to-guess tokens, HttpOnly session and public-access cookies, credential hashing where applicable, rate limits and short-lived storage URLs.
FilesUp does not provide end-to-end encryption. FilesUp and its infrastructure providers can process content as needed to operate the service. A public link is a bearer credential: anyone with the full link can access it while valid. Share it only with the right people.
No system is absolutely secure. If you suspect compromise, revoke the share where possible and contact us promptly.
8. Your rights
Under the GDPR, you may request access, correction, erasure, restriction and portability and object to legitimate-interest processing. You may withdraw marketing consent at any time without affecting earlier lawful processing or necessary transactional messages.
Send your request to privacy@filesup.app. We may request proportionate information to verify identity and protect others. We will respond within legal time limits and explain any restriction or refusal.
You can lodge a complaint with Portugal's Comissão Nacional de Proteção de Dados (CNPD), without prejudice to other administrative or judicial remedies.
9. Changes and contact
We may update this policy when the service, providers or legal requirements change. We will appropriately highlight material changes and show the effective date here.
Privacy contact: privacy@filesup.app. Content or abuse contact: abuse@filesup.app.