Last updated: August 22, 2026
We collect the minimum data needed to provide the service:
We only send marketing emails to users who have explicitly opted in by checking the consent box during signup. You can unsubscribe at any time by emailing us.
We use the following third-party services:
Each service has its own privacy policy. Some providers may process data outside the EU/EEA using their GDPR transfer safeguards. We do not sell your data to any third party.
Your files are stored until you delete them, they expire under an auto-delete setting you configured, or your account is terminated. A first upload made before email verification is provisional for up to 24 hours unless verification promotes it to normal account retention. Account data is retained for as long as your account is active. After account deletion, we target removal from active systems within 30 days where reasonably possible.
Encrypted database backups are retained separately for recovery and automatic archives age out within 180 days. A deleted record may remain in a protected backup until that backup rotates out. Support, security, billing, and takedown records may be retained for longer when needed to resolve disputes, prevent abuse, comply with legal obligations, or protect the service.
You can:
All data is transmitted over HTTPS. Uploaded files are primarily stored in Backblaze B2 and delivered through Cloudflare; file URLs are public and must not be used for confidential material. Database backup archives are encrypted before leaving the application server and copied to two storage providers. API keys are generated using cryptographically secure methods. See Security and Data Handling for the current controls and limitations.
The API uses API key authentication and does not require browser cookies. The dashboard uses cookies for login sessions: fp_session is an HttpOnly signed session cookie, and fp_li is a non-sensitive login indicator used by the navigation UI. We also use browser localStorage to remember basic dashboard display information such as email, name, and avatar URL after sign-in.
Google Analytics and PostHog are optional analytics tools. They only load after you accept analytics cookies in the cookie banner. Your analytics choice is stored in localStorage as fp_analytics_consent, and you can change it from the Cookie Settings link in the footer.
Google Sign-In may load cookies or similar technologies from Google when you use that sign-in option.
If content is reported as illegal, abusive, harmful, or infringing, we may review the report, remove or disable access to files, suspend accounts or API keys, preserve relevant records, and cooperate with valid legal requests or law enforcement where required or appropriate.
We may update this policy. Changes will be posted on this page with an updated date.
FilePost is based in Sweden. Privacy questions? Email support@filepost.dev.