Adatvédelem · Privacy
Privacy Policy.
Effective: 2026-05-16 · Version v2
Plain-language summary. Legal review required before launch — translation to Hungarian is a follow-up.
§ 01
What we collect
- Account email and a one-way password hash (bcrypt) — for registered users.
- Uploaded file content, original filename, size in bytes, and SHA-256 fingerprint.
- Uploader IP address for every upload (anonymous and authenticated).
- Downloader / share-page-viewer IP address for every successful file download and every share-page resolution. Stored append-only in the analytics event tables that power the owner's Feed dashboard rollups (see § 02 for retention).
§ 02
How long we keep it
- Account-owned files: until you delete them or your account.
- Anonymous uploads: file content is purged after 7 day(s) (configurable; matches the backend default of 7 days).
- Forensic record (uploader IP, SHA-256 hash, original filename, size): retained for 180 days after content purge for abuse-investigation purposes.
- Analytics events (download events, share-page views): currently retained append-only without rotation. Production deployments will introduce a retention sweep that aggregates older rows into monthly summaries.
- Abuse reports (DMCA, ILLEGAL, SPAM, OTHER): retained indefinitely for legal record-keeping.
§ 03
Why we collect IP addresses
Two purposes. Fraud and abuse prevention (rate limits, abuse-report investigation, protection from automated abuse) under GDPR Article 6(1)(f) — legitimate interest. Owner-side analytics for the Feed dashboard (the file owner sees aggregate download / share-view counts on their own files); event rows carry the IP for forensic continuity but the dashboard itself only shows totals, never IPs. Neither use case involves selling or sharing data with marketing partners.
§ 04
Cookies and advertising
Share pages may display Google AdSense advertisements when you have given consent via the cookie banner. Your consent choice is recorded in your browser's localStorage under the key ads_consent. Rejecting consent does not affect downloads or any other functionality.
§ 04b
Payment processing
When you upgrade to the paid tier, payment is processed by Stripe, a contractually-bound subprocessor (PCI-DSS Level 1 certified). Your account email is shared with Stripe at checkout time as part of payment processing — Stripe needs it to issue receipts and to match returning customers to their existing payment methods. Card and bank-account details are entered on Stripe-hosted pages and never reach our servers. We only store the resulting Stripe customer and subscription IDs alongside the period-end timestamp so the app knows whether your subscription is currently active.
The legal basis for sharing your email with Stripe is GDPR Article 6(1)(b) — performance of the subscription contract you entered into when upgrading.
§ 05
Your rights
- Access — request a copy of the personal data we hold about you.
- Deletion — request that we erase your account and uploads.
- Correction — ask us to fix inaccurate data.
- Complaint — lodge a complaint with your national supervisory authority.
§ 06
Contact
For privacy questions or requests under the rights above, contact privacy@filemv.local. (Placeholder address — replaced with the operating company's contact at launch.)