Privacy Policy
In effect from 5 August 2026.
This policy explains what FileDeck does with personal data in FileDeck Embed, the hosted document library at filedeck.co. It is written to be read, not to be survived.
Two different roles
We handle two kinds of people’s data, and our responsibilities differ for each:
- Account holders. If you sign up for FileDeck Embed, we are the data controller for your account. This policy governs that.
- Library visitors. If you arrived at a document library embedded on somebody else’s website, we are a processor acting for the owner of that library. They decide what is published and what is collected; their privacy policy governs it. We handle that data only to run the service for them.
What we collect from account holders
- Account: your email address and a hashed password (or your sign-in provider’s identifier), and the date you signed up.
- Library content: the documents you upload, their titles, summaries, categories, custom fields and any text extracted from them for search.
- Usage: download and search events for your own libraries, which is what the analytics in your dashboard is built from.
- Billing: your plan, subscription status and Stripe customer reference. Card numbers are handled by Stripe and never reach us.
- Support: whatever you tell us when you get in touch.
Embedded libraries: what visitors are and are not tracked with
The embed is deliberately the quietest part of the product, because it runs on somebody else’s website and their visitors never chose us.
- Embedded libraries set no cookies and carry no FileDeck analytics tag. Our own usage measurement runs on the FileDeck website and dashboard only.
- We record download events — which document, and when — so the library owner can see what is being used. Where the owner has enabled rate limiting or download caps, a short-lived, truncated record of the requesting network address is used to enforce them.
- Unlocking a password-protected library stores a signed token in the browser’s partitioned session storage. It is scoped to that embed, cleared when the tab closes, and is not a tracking identifier.
- If a library uses lead capture, terms gates, feedback or visitor submissions, the visitor is told what is being asked for at the point of asking, and it goes to the library owner.
- If the owner configures their own Google Analytics property, we send events to their property from our server. That is their collection, under their policy.
Why we are allowed to process it
- Contract — running the service you signed up for: your account, your libraries, your billing.
- Legitimate interests — keeping the platform secure and abuse-free, measuring how the website performs, and telling you about material changes to the service you use.
- Legal obligation — keeping the tax and accounting records we are required to keep.
- Consent — anything optional, such as marketing email, which you can withdraw at any time.
Who else processes it
We keep this list short on purpose, and it is complete. We do not sell personal data, and we do not share it for anyone else’s advertising.
| Processor | What it does | Where |
|---|---|---|
| Railway | Application hosting — runs the FileDeck Embed service itself. | European Union / United States |
| Supabase | Account authentication and the platform database (library, document and event records). | London, United Kingdom (eu-west-2) |
| Cloudflare | R2 object storage for uploaded files and generated thumbnails; DNS and domain registration. | Global edge network |
| Stripe | Payment processing and subscription billing. Card details are entered directly with Stripe and never reach FileDeck. | European Union / United States |
| Brevo | Transactional email (account, trial and notification messages) and, where an owner configures it, contact-list sync. | European Union |
| Google Analytics 4 | Usage measurement on the FileDeck website and dashboard only. Deliberately not present on embedded libraries. | European Union / United States |
| OpenAI / Anthropic | AI features only, and only when the library owner supplies their own API key. Document text is sent to the provider that key belongs to. | United States |
AI features
AI features are off unless a library owner turns them on and supplies their own provider API key. When they do, document text is sent to that provider to build a search index and answer questions, under the provider’s terms and the owner’s account. If no key is configured, nothing is ever sent to an AI provider.
International transfers
Account records and library metadata are held in the United Kingdom. Some processors above operate in the United States or route traffic globally. Where data leaves the UK or EEA we rely on the safeguards those providers offer — adequacy decisions, or standard contractual clauses in their data processing terms.
How long we keep it
- Account and library data: for as long as the account exists. Delete a library or your account and it goes immediately, including the stored files.
- Download and search events: retained to power your dashboard analytics, and removed with the library they belong to.
- Billing records: kept for as long as tax law requires, typically six years, even after an account closes.
- Backups: deleted data can persist in encrypted backups for a short period before those rotate out.
Your rights
You can access, correct, export, delete or restrict the processing of your personal data, and object to processing based on legitimate interests. Two of these are built into the product rather than being a request you have to make:
- Export — your dashboard has a one-click export of everything your account holds, in JSON, plus CSV exports per library.
- Deletion — you can delete an individual library or your whole account from the dashboard. It is immediate and cannot be undone.
For anything else, contact us and we will respond within one month. If you are a library visitor rather than an account holder, the library’s owner is the right first contact — we will pass your request on to them if you reach us instead.
If you think we have handled your data badly, tell us first so we can fix it. You also have the right to complain to the UK Information Commissioner’s Office at ico.org.uk, or to your local supervisory authority.
Security
Traffic is encrypted in transit. Passwords are hashed, never stored in readable form. Files are served through short-lived signed links rather than public URLs, and every library’s data is isolated at the database level so one account cannot read another’s. No system is perfect; if a breach affects you we will tell you and the regulator within the timescales the law sets.
Children
FileDeck Embed is a business product and is not directed at children. We do not knowingly collect data from anyone under 18.
Changes
If we change this policy materially we will tell account holders by email or in the dashboard before it takes effect, and update the date at the top. The terms of service sit alongside this policy.
Contact
Privacy questions and data requests go through FileDeck support.