Introduction
FileGrab.Link ("we", "our", or "us") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use our file sharing service.
Information We Collect
Account Information
When you create an account, we collect:
- Email address (for authentication and account recovery)
- Mobile phone number (optional, for SMS notifications)
- Account creation date
- Subscription status (free or Pro)
Usage Data
We automatically collect:
- Anonymous unique visitor counts (hashed, not tied to your identity)
- Files uploaded (metadata only: name, size, type)
- Links created and accessed
- Storage usage statistics
We do not store or track your IP address. For link statistics, we only count unique visits using anonymized, one-way hashes that cannot be traced back to you.
Files You Upload
We store files you upload on Cloudflare R2 infrastructure. We do not access or analyze the content of your files except in the following cases:
- Executable files: Files such as .exe, .dll, .dmg, and other executable types are automatically scanned for malware at upload time.
- When required by law
- To investigate reported violations of our Terms of Service
How We Use Your Information
- To provide and maintain our file sharing service
- To authenticate your account via magic link emails
- To process payments (Pro subscriptions)
- To enforce our Terms of Service and prevent abuse
- To respond to legal requests and prevent harm
- To send service-related communications (email and, if opted in, SMS)
SMS/Text Messaging
If you provide your mobile phone number, we may send you SMS text messages for account notifications such as new file uploads or account activity alerts. Message frequency varies based on your account activity and notification preferences.
We will never share your mobile phone number with third parties for marketing or promotional purposes. Your phone number is used solely by FileGrab for service-related notifications that you have opted into.
You can opt out of SMS notifications at any time by updating your notification preferences in your account settings or by replying STOP to any message. Message and data rates may apply. For help, reply HELP or contact us at privacy@filegrab.link.
Data Storage and Security
Your files are stored on Cloudflare's global edge network with encryption at rest. We use industry-standard security measures including:
- HTTPS encryption for all data in transit
- Secure, httpOnly session cookies
- Rate limiting to prevent abuse
- Automatic file expiration and deletion
End-to-End Encryption (Pro)
Pro users can create encrypted links where files are encrypted in the browser before upload using AES-256-GCM. The encryption key is stored only in the URL fragment (after the #) which is never sent to our servers. This means:
- We cannot decrypt or access your encrypted files
- Only people with the complete link (including the key) can decrypt files
- If you lose the link, the files cannot be recovered
Data Retention
- Free tier files: Automatically deleted after 7 days
- Pro tier files: Retained until manually deleted or subscription ends
- Account data: Retained while your account is active
- Server logs: Retained for 30 days for security purposes
Account Deletion
You can permanently delete your account at any time from your account settings. When you request deletion:
- You'll receive a confirmation email (security measure)
- After confirming, you have 7 days to cancel the deletion by logging in
- After 7 days, all your data is permanently deleted including:
- Your account information
- All files you uploaded
- All links you created
- Your subscription (no prorated refund)
- We retain anonymized billing records for 7 years as required by law
Your Rights (GDPR)
If you are in the European Economic Area, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Portability: Request your data in a portable format
- Object: Object to certain processing of your data
To exercise these rights, contact us at privacy@filegrab.link
Third-Party Services
We use the following third-party services:
- Cloudflare: Infrastructure, CDN, and security
- Google Analytics: Website usage analytics (pages visited, session duration, general location)
- Resend: Email delivery for authentication
- Stripe: Payment processing (Pro subscriptions)
Each service has its own privacy policy governing their use of your data.
Cookies
We use the following cookies:
- Session cookie: To keep you logged in
- Theme preference: To remember your light/dark mode choice
- Analytics cookies: Google Analytics uses cookies to collect anonymous usage data such as pages visited, session duration, and general geographic location. This data helps us improve the service. No personally identifiable information is collected through analytics.
We do not use third-party advertising cookies.
Children's Privacy
FileGrab.Link is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.
Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes by posting a notice on our website or sending you an email.
Contact Us
For privacy-related questions or concerns, contact us at:
privacy@filegrab.link