Trust & legal
Privacy Policy
This policy explains what FiloSpace handles when you create an account, store files, and choose to share them.
Last updated: August 12, 2026
1. Scope
This policy applies to the FiloSpace website and file-management application. The operator is [legal entity name — configure before launch]. FiloSpace acts on account and service information needed to run the product. You decide what files to upload and who receives a share link.
2. Information we collect
- Account information: name, email address, authentication identifiers, and profile details you provide.
- Uploaded content: the files you choose to store and generated copies you ask FiloSpace to create.
- File metadata: file names, types, sizes, folders, tags, timestamps, storage keys, favorites, processing state, and sharing settings.
- Service activity: actions such as uploads, downloads, folder changes, link creation, processing jobs, and rate-limit events.
- Technical information: information routinely present in requests and infrastructure logs, such as time, browser or device information, and network data.
- Google sign-in information: if you choose Google, FiloSpace receives the account details Google makes available for authentication, such as your email, name, and profile image where provided.
3. How we use information
FiloSpace uses this information to:
- create and authenticate your account;
- upload, organize, process, download, and share files at your request;
- apply storage, file-size, security, and rate limits;
- show activity and file status inside your workspace;
- diagnose failures, protect the service, and respond to support requests; and
- meet applicable legal obligations and enforce the service terms.
The current application does not include advertising or behavioral analytics code, and uploaded file contents are not used to build advertising profiles.
4. File storage and access
File contents are stored as private objects in Amazon S3. File metadata and account data are stored in Supabase PostgreSQL. The browser uploads to and downloads from S3 using time-limited signed URLs issued only after server-side authorization checks.
Files remain private to the account owner unless the owner creates a share link. A valid, unexpired, non-revoked share link lets its holder access the linked item. Do not send a share link to someone who should not have access.
6. International transfers
Service providers may process operational data in countries other than your own. The current S3 bucket is configured in AWS region Europe (Stockholm), eu-north-1. That configuration does not mean every category of account, authentication, support, or infrastructure data stays in that region.
Provider terms and legally recognized safeguards may apply to international transfers. See the Subprocessors page for provider documentation.
7. Retention and deletion
Account information and stored files are kept while the account is active and as needed to provide the service. Deleting a file revokes its share links and removes it from the workspace immediately. The stored object is kept for a short grace period, long enough to undo the deletion, and is then permanently removed: the S3 object is deleted before its database record.
FiloSpace does not currently promise a fixed account-deletion period. Activity records remain until cleared through the product or removed as part of service administration. Limited information may need to be retained where required by law, needed to resolve disputes, prevent abuse, or present in provider backups subject to the provider's lifecycle.
To request account-level deletion or access that is not available in the product, email support@filospace.online.
8. Your privacy rights
Depending on where you live and which law applies, you may be able to ask for access, correction, deletion, restriction, portability, or other action concerning personal information. FiloSpace may need to verify your identity and may deny or limit a request where the law permits.
This selection stays on this page and is not stored or used to infer your location.
9. Security and incidents
FiloSpace uses private-by-default object storage, signed access URLs, authenticated server operations, ownership checks, PostgreSQL row-level security, and file validation. More detail is available on the Security page.
No system can guarantee absolute security. If FiloSpace becomes aware of an incident affecting personal information, it will investigate, contain the issue where possible, and make notices required by applicable law.
10. Children
FiloSpace is a general file-management service and is not directed to children. Do not create an account if you cannot legally agree to the Terms in your location. If you believe a child has provided personal information without appropriate authorization, contact us.
11. Changes and contact
This policy may change when the product, providers, or legal requirements change. The date at the top will be updated, and material changes will be communicated in an appropriate way.
Privacy requests can be sent to support@filospace.online. Include the email address connected to your account and the request you want us to review.