Trust & legal
Data Processing Overview
A practical description of the information FiloSpace handles to provide file storage, organization, sharing, and processing.
Last updated: August 12, 2026
1. Overview
This page helps customers understand the current processing architecture. It supplements the Privacy Policy but is not a signed data processing agreement.
2. Roles
FiloSpace determines how account, security, and operational information is used to run the service. For personal information contained inside files uploaded for a business or other organization, that customer generally decides why the content is stored and shared, while FiloSpace handles it to provide the requested service. Exact legal roles depend on the circumstances and applicable law.
3. Data and purposes
- Account identity and profile data for authentication and account management.
- Uploaded file contents for storage, download, preview, sharing, and requested processing.
- File, folder, tag, sharing, and lineage metadata for file management.
- Activity, processing, and rate-limit records for product state, reliability, and abuse prevention.
- Technical logs needed to diagnose errors and protect the service.
FiloSpace does not currently use uploaded content for advertising or train a general AI model on it.
4. User instructions
Uploading, renaming, moving, tagging, sharing, deleting, previewing, downloading, or processing a file supplies the instruction needed to perform that operation. Processing outputs are created as new files and linked to the source rather than overwriting it.
5. Service providers
FiloSpace uses Supabase for authentication and PostgreSQL, AWS S3 for file objects, and Google only when a user chooses Google authentication. The current provider list and documentation links are on the Subprocessors page.
6. Security and deletion
Current controls include private S3 objects, short-lived signed URLs, server-side ownership checks, database row-level security, constrained storage keys, validation, and rate limits. See the Security page for details.
Deleted files are held briefly so the deletion can be undone, then permanently removed: the S3 object is deleted before its metadata. FiloSpace does not currently publish an account-level deletion SLA.
7. Requests and contracts
Privacy or account-data requests can be sent to support@filospace.online. Customers that require a signed DPA should contact the same address; availability is not promised until the legal entity and contractual process are finalized.