Plain-language summary. Legal review required before launch — translation to Hungarian is a follow-up.
§ 01
What we collect
- Account email and a one-way password hash (bcrypt) — for registered users.
- Uploaded file content, original filename, size in bytes, and SHA-256 fingerprint.
- Uploader IP address for every upload (anonymous and authenticated).
- Downloader / share-page-viewer IP address for every successful file download and every share-page resolution. Stored append-only in the analytics event tables that power the owner's Feed dashboard rollups (see § 02 for retention).
- Recipient email addresses for share-by-email links — supplied by the file owner when sharing a file via email (see § 04c).
- Guest uploader name and email address for Collect-mode submissions — supplied by a visitor when they submit files through an owner-created Collect link (see § 02 for retention).
§ 02
How long we keep it
- Account-owned files: until you delete them or your account.
- Anonymous uploads: stored until the uploader deletes them (after claiming them into an account) or an administrative / abuse action removes them. There is no automatic time-based expiry.
- Forensic record (uploader IP, SHA-256 hash, original filename, size): the uploader-IP record for a live anonymous upload is erased 180 days after upload; the record of an already-purged file is deleted 180 days after its upload. Neither action touches the file itself or its share link — those persist until the uploader, an administrator, or an abuse action removes them.
- Analytics events (download events, share-page views): raw rows are retained for 90 days, after which a scheduled retention sweep aggregates older rows into monthly summaries and deletes the raw rows.
- Share-email recipient addresses: retained for the share's lifecycle — purged automatically when the share is revoked by the owner, the share link expires, the file is deleted, or the owner's account is deleted.
- Abuse reports (DMCA, ILLEGAL, SPAM, OTHER): retained indefinitely for legal record-keeping.
- Collect-mode guest uploader name and email: retained for as long as the Collect link owner's account exists. There is no separate retention window — the data is hard-deleted together with the rest of the owner's account data when the owner deletes their account.
§ 03
Why we collect IP addresses
Two purposes. Fraud and abuse prevention (rate limits, abuse-report investigation, protection from automated abuse) under GDPR Article 6(1)(f) — legitimate interest. Owner-side analytics for the Feed dashboard (the file owner sees aggregate download / share-view counts on their own files); event rows carry the IP for forensic continuity but the dashboard itself only shows totals, never IPs. Neither use case involves selling or sharing data with marketing partners.
§ 04
Cookies and advertising
Share pages may display Google AdSense advertisements when you have given consent via the cookie banner. Your consent choice is recorded in your browser's localStorage under the key ads_consent. Rejecting consent does not affect downloads or any other functionality.
§ 04b
Payment processing
When you upgrade to the paid tier, payment is processed by Stripe, a contractually-bound subprocessor (PCI-DSS Level 1 certified). Your account email is shared with Stripe at checkout time as part of payment processing — Stripe needs it to issue receipts and to match returning customers to their existing payment methods. Card and bank-account details are entered on Stripe-hosted pages and never reach our servers. We only store the resulting Stripe customer and subscription IDs alongside the period-end timestamp so the app knows whether your subscription is currently active.
The legal basis for sharing your email with Stripe is GDPR Article 6(1)(b) — performance of the subscription contract you entered into when upgrading.
§ 04c
Share-email recipients
When a file owner uses the share-by-email feature, share links are emailed to the recipient addresses the owner supplies. Those recipient email addresses are stored by us to power per-recipient open/download tracking — so the owner can see which recipients have accessed the shared file.
The legal basis for processing recipient addresses is GDPR Article 6(1)(f) — legitimate interest of the file owner in knowing whether their shared content was received and accessed.
Recipient addresses are retained for the share's lifecycle and are purged automatically when the share is revoked by the owner, the share link expires, the file is deleted, or the owner's account is deleted. Recipients may contact us to request erasure of their address at any time (see § 06 for contact details).
§ 04d
Collect mode
Collect mode lets a file owner create a password-protected drop-box link (/collect/<token>) so visitors can upload files directly into one of the owner's Drive folders. When a visitor submits files through a Collect link, we store the name and email address they provide alongside the submission.
The legal basis for processing the guest uploader's name and email is GDPR Article 6(1)(f) — legitimate interest of the link owner in knowing who submitted the files.
This data is retained for as long as the link owner's account exists and is hard-deleted together with the rest of the owner's account data when the owner deletes their account (see § 02). Guest uploaders may contact us to request erasure of their name and email at any time (see § 06 for contact details).
§ 05
Your rights
- Access — request a copy of the personal data we hold about you.
- Deletion — request that we erase your account and uploads.
- Correction — ask us to fix inaccurate data.
- Complaint — lodge a complaint with your national supervisory authority.
§ 06
Contact
For privacy questions or requests under the rights above, contact privacy@filemv.local. (Placeholder address — replaced with the operating company's contact at launch.)