Privacy Policy
Last updated: April 25, 2026
1. What We Collect
We collect the minimum data needed to provide the service:
- Email address: provided at signup, used for account identification and billing
- Uploaded files: stored on Backblaze B2 and served via Cloudflare CDN
- Usage data: upload counts, file sizes, content types, API request metadata, and basic security logs such as IP address and user agent where available
- Payment information: processed by Stripe; we never see or store your card details
- Support and content reports: messages sent to support@@postfile.net, including reported URLs and context needed to handle the request
2. How We Use Your Data
- To provide and maintain the file hosting service
- To enforce usage limits based on your plan
- To process payments via Stripe
- To communicate service updates or issues
- To send product updates, tips, and promotional emails (only with your explicit consent)
- To detect, prevent, investigate, and respond to abuse, illegal content, security incidents, and policy violations
We only send marketing emails to users who have explicitly opted in by checking the consent box during signup. You can unsubscribe at any time by emailing us.
3. Third-Party Services
We use the following third-party services:
- Hetzner: application hosting and database infrastructure
- Backblaze B2: file storage
- Cloudflare: CDN, cache, DNS, and DDoS protection
- Stripe: payment processing and subscription management
- Brevo: transactional and opted-in product emails
- Google Sign-In: optional account sign-in
- Google Analytics 4 and PostHog: analytics and product usage measurement
Each service has its own privacy policy. Some providers may process data outside the EU/EEA using their GDPR transfer safeguards. We do not sell your data to any third party.
4. Data Retention
Your files are stored until you delete them, they expire under an auto-delete setting you configured, or your account is terminated. Account data is retained for as long as your account is active. After account deletion, we remove your data within 30 days where reasonably possible. Support, security, billing, and takedown records may be retained for longer when needed to resolve disputes, prevent abuse, comply with legal obligations, or protect the service.
5. Your Rights
You can:
- Delete any file via the API at any time
- Request a copy of your data by emailing us
- Request correction or deletion of account data by emailing us
- Request account deletion by emailing us
- Report hosted content through our Report Content page
6. Security
All data is transmitted over HTTPS. Files are stored on encrypted infrastructure provided by Backblaze. API keys are generated using cryptographically secure methods.
7. Cookies and Local Storage
The API uses API key authentication and does not require browser cookies. The dashboard uses cookies for login sessions: fp_session is an HttpOnly signed session cookie, and fp_li is a non-sensitive login indicator used by the navigation UI. We also use browser localStorage to remember basic dashboard display information such as email, name, and avatar URL after sign-in.
Google Analytics and PostHog are optional analytics tools. They only load after you accept analytics cookies in the cookie banner. Your analytics choice is stored in localStorage as fp_analytics_consent, and you can change it from the Cookie Settings link in the footer.
Google Sign-In may load cookies or similar technologies from Google when you use that sign-in option.
8. Content Reports and Legal Requests
If content is reported as illegal, abusive, harmful, or infringing, we may review the report, remove or disable access to files, suspend accounts or API keys, preserve relevant records, and cooperate with valid legal requests or law enforcement where required or appropriate.
9. Changes
We may update this policy. Changes will be posted on this page with an updated date.
10. Contact
PostFile is based in Sweden. Privacy questions? Email support@@postfile.net.