fileLOADED ("fileLOADED", "we", "us") lets you move files of any size between your devices, share them,
and hand them to AI tools. This policy explains what we collect, how we use it, and the choices you have.
We tried to write it in plain English.
⚠️
Encryption, honestly stated. Your files are encrypted at rest with AES-256-GCM.
This protects your data on our disks and in our backups. It is
not end-to-end / "zero-knowledge"
encryption: our servers hold the keys needed to serve your files back to you, so in principle we can
access the content of ordinary projects. The one exception is the
Vault: a Vault's key is derived
from a PIN or passphrase that we never store, so while a Vault is locked, no one — including us — can open it.
If you lose a Vault PIN, that data cannot be recovered.
Information we collect
- Account information — your email address, and (if you sign in with Google) your name and profile
photo. If you use a password, we store only a salted hash, never the password itself.
- Content you upload — the files, folders, notes, and file names you add. These are stored encrypted.
- Security & device data — the sessions you're signed in on, including a device label derived from
your browser's user-agent, IP address, and last-seen time, so you can review and revoke your linked devices.
- Operational logs — a limited audit log of account and security events (sign-ins, shares, deletions)
to keep your account safe and to debug problems.
How we use your information
- To provide the service — store, sync, share, and serve your files across your devices.
- To secure your account — two-factor authentication, trusted-device recognition, rate limiting, abuse prevention.
- To communicate with you — password resets, share notifications, and important service notices.
- To enforce plan limits and, where applicable, the free-tier retention window described below.
We do not sell your personal information, and we do not use the content of your files to train
advertising models.
AI features
fileLOADED includes optional AI features — a per-project assistant that can rename files, organize folders,
and find files by their contents, and per-project / global API keys you can give to your own AI tools.
- The built-in assistant only processes your content when you ask it to. To carry out a request, the
relevant file names, text, and (for image tasks) downscaled thumbnails are sent to our AI provider,
Anthropic (the makers of Claude), which processes them to return a result.
- Anthropic acts as our processor for these requests and, per its terms, does not use API content to train
its models. See Anthropic's privacy terms for details.
- API keys you create are yours to manage and revoke. For your protection, Vault projects never expose an
API key and cannot be reached by any API key — they are session- and PIN-only.
Sharing & links
When you create a share link, drop link, or invite someone to a project or Family, you make that content
available to whoever holds the link or accepts the invite. You control expiry and permissions (view, download,
upload, copy). A share link is a public capability — anyone with the link can use it within the limits you set,
so share it carefully. Drop-link recipients can add and view files but cannot delete your existing content.
Data retention
- Free tier: to keep the free service sustainable, files are not stored long-term — content is
automatically and permanently erased after the free-tier window (24 hours by default). Free-tier deletions
are immediate and are not recoverable.
- Paid plans: your files are kept until you delete them. Deleted files go to a recovery area (trash)
and can be restored for 7 days, after which they are permanently purged.
- When you delete your account, we delete your projects, files, and encrypted bytes.
Service providers
We rely on a small number of providers to run fileLOADED: Anthropic (AI features), an email/SMTP
provider (transactional email), and Cloudflare (network, DNS, and content delivery). These providers
process data on our behalf under their own terms.
Security
We use encryption at rest, hashed passwords, optional two-factor authentication, trusted-device recognition,
and access controls. No system is perfectly secure, but we work to protect your data and to give you the tools
(2FA, device management, Vault) to protect it yourself.
Your choices & rights
You can access and export your files at any time, delete individual files or your whole account, review and
revoke linked devices, and manage who has access to your projects. To exercise any right, use the app or contact us.
Children
fileLOADED is not directed to children under 13 (or the minimum age in your country), and we do not knowingly
collect their information.
Changes
We may update this policy; we'll change the "last updated" date above and, for material changes, notify you in-app or by email.
Contact
Questions about privacy? Contact us through the app.