Skip to content
FilesUp
How it worksTrustAppsQuestions
PTEN
Open FilesUp
Home/Privacy Policy

Data protection

Privacy Policy

We explain what data we process, why, for how long and how you can exercise your rights under the GDPR.

Effective from 13 August 2026

On this page
  1. 1. Who controls your personal data
  2. 2. Data we process
  3. 3. Purposes and lawful bases
  4. 4. How long we keep data
  5. 5. Providers, recipients and transfers
  6. 6. Artificial-intelligence suggestions
  7. 7. Security and link limitations
  8. 8. Your rights
  9. 9. Changes and contact

Contacts

Privacy and rightsprivacy@filesup.appContent and abuseabuse@filesup.app
TermsPrivacyCookiesAcceptable useReport

1. Who controls your personal data

The service and its controller operate under the FilesUp brand.

For questions or requests about personal data, contact privacy@filesup.app. To report hosted content, use abuse@filesup.app or the Report page.

2. Data we process

If someone sends you files before you have an account, we receive your email address or phone number from the sender to deliver the share. The sender is responsible for having a lawful basis to provide your contact details.

CategoryExamples
Account and authenticationEmail address or phone number, display name, language, one-time codes, session identifiers, timestamps and account status.
Consents and preferencesVersion and language of accepted terms; optional marketing choice, source, date and changes; language preference.
Content and recipientsFiles, messages, recipient email or phone, names and relative paths, type, size, technical hashes, thumbnails, availability and expiry times.
Sharing and activityTopics, transfers, upload/delivery state, protected forms of public links, downloads, participants, timestamps and audit events.
Device and securityIP address and technical request information, browser, errors, usage limits, authentication attempts and signals needed for security, diagnosis and abuse prevention.
Requests and reportsRequester's identity and contact, request contents, reported URL or identifiers, evidence, review and decision. The abuse form also includes the IP observed by the API, request date and origin, browser/device, language, time zone, screen/viewport, navigation type, page and referrer without query parameters or fragments, resource identifier and a random reporting-session identifier. The form does not read general browser history or create a persistent canvas, audio or font fingerprint.

3. Purposes and lawful bases

PurposeLawful basis
Create and manage accounts; authenticate; upload, store, deliver and download filesPerformance of a contract or steps you request before entering one.
Deliver a share to the nominated contact, keep the timeline and confirm activityOur contract with the sender and legitimate interests in providing the requested delivery, balanced against recipient rights.
Security, fraud/abuse prevention, quotas, diagnosis and legal claimsLegitimate interests of FilesUp and its users and, where relevant, compliance with a legal obligation.
Codes, invitations, security alerts, operational and legal noticesContract, legitimate interests in secure operation or legal obligation. These are transactional messages.
Marketing by email or SMSOptional, specific and withdrawable consent. It is not required to open an account or receive the service.
Handle rights, orders, reports and illegal contentLegal obligation and legitimate interests in protecting rights and the service.

4. How long we keep data

Deletion in distributed systems may be asynchronous. We may isolate and preserve specific data beyond general criteria when a legal duty, valid order, dispute or report requires proportionate retention.

DataRetention criterion
File binaries and download archivesAccessible for 240 hours (10 days) from availability, or less if deleted/revoked; technical object deletion then begins.
Timeline, messages, metadata, thumbnails and delivery/download historyWhile the account and relevant topic exist, unless deletion is requested or a lawful need to preserve them applies.
Public link/token and public-access cookieUntil the share expires, no more than 10 days for the cookie, or earlier revocation.
OTP challenges and sessionsCodes are one-time and short-lived; sessions last until expiry, sign-out or revocation. Minimal records may remain as needed for security.
Consents and termsWhile the account exists and afterwards as needed to demonstrate choices, comply with obligations or establish and defend claims.
Logs, support, requests and reportsAs needed for the purpose, risk, investigation, legal duties and applicable claim periods, subject to review and minimisation.

5. Providers, recipients and transfers

These providers process data under applicable contracts and instructions or as independent controllers for operations they determine. If processing involves a transfer outside the European Economic Area, we will use the legally required mechanism, such as an adequacy decision or Standard Contractual Clauses, and supplementary safeguards where necessary.

  • Cloudflare R2: object storage, including files, archives and thumbnails, and delivery through signed URLs as configured.
  • MessageBird: sends and verifies SMS one-time codes when access uses a phone number.
  • FilesUp's configured SMTP provider: sends email codes, share invitations and other transactional email.
  • OpenAI: only when you expressly request a message suggestion; receives the recipient display name and file names, extensions and sizes, not file binaries. FilesUp sends the request with store: false, without prejudice to limited processing the provider may perform for security and compliance with its terms.
  • Authorities, courts, advisers or prospective acquirers only where a lawful basis and appropriate safeguards apply.

6. Artificial-intelligence suggestions

The AI feature does not run automatically. A request occurs only after you click to obtain suggestions. FilesUp does not send file binaries to OpenAI and configures the response with store: false.

Suggestions are assistive and editable and do not make decisions with legal or similar effects. If you choose and send one, the selected text becomes part of the timeline like any other message.

7. Security and link limitations

We use proportionate technical and organisational measures, including protected connections, hard-to-guess tokens, HttpOnly session and public-access cookies, credential hashing where applicable, rate limits and short-lived storage URLs.

FilesUp does not provide end-to-end encryption. FilesUp and its infrastructure providers can process content as needed to operate the service. A public link is a bearer credential: anyone with the full link can access it while valid. Share it only with the right people.

No system is absolutely secure. If you suspect compromise, revoke the share where possible and contact us promptly.

Do not use FilesUp as your only copy

File binaries are temporary and are deleted after ten days. Keep originals and assess whether the information is suitable for a service without end-to-end encryption.

8. Your rights

Under the GDPR, you may request access, correction, erasure, restriction and portability and object to legitimate-interest processing. You may withdraw marketing consent at any time without affecting earlier lawful processing or necessary transactional messages.

Send your request to privacy@filesup.app. We may request proportionate information to verify identity and protect others. We will respond within legal time limits and explain any restriction or refusal.

You can lodge a complaint with Portugal's Comissão Nacional de Proteção de Dados (CNPD), without prejudice to other administrative or judicial remedies.

  • Individual rights — CNPD (opens in a new window)
  • Comissão Nacional de Proteção de Dados (opens in a new window)

9. Changes and contact

We may update this policy when the service, providers or legal requirements change. We will appropriately highlight material changes and show the effective date here.

Privacy contact: privacy@filesup.app. Content or abuse contact: abuse@filesup.app.

FilesUp

Files, sent like a message.

How it worksTrustAppsSend large files onlineShare files online securelyContact
TermsPrivacyCookiesAcceptable useReport

© 2026 FilesUp. Made in Portugal for sharing without complications.