Privacy Policy

Effective September 19, 2026 · Last updated September 20, 2026

The short version, which is not the policy. We collect what we need to run your account and deliver your work: your profile, your billing status, the files you upload, the clients you invite, and technical logs. We do not sell or share personal information, run no advertising or cross-site tracking, and never train AI models on your Content. Files you upload belong to your engagement with your client — for those, you are the controller and we only process on your instructions. Note that activity logs and the optional session watermark record a viewer’s email address and IP address; if you turn those on, tell your viewers.

1.Scope and who we are

This Privacy Policy explains how Kerry Ngan (FileSaurus, “we”, “us”) collects, uses, discloses and protects personal information when you visit filesaurus.com, use the FileSaurus application, or open a review portal or share link generated by it (together, the “Service”).

It applies to three groups of people: Creators who hold an account, Clients and reviewers who open a portal without an account, and visitors to our marketing pages. Where a rule applies to only one group, we say so.

It does not apply to the third-party services we integrate with, which have their own policies — see §7 — nor to what a Creator does with your information outside the Service.

2.Our two roles: controller and processor

FileSaurus handles personal information in two distinct capacities, and which one applies decides who you should go to with a request.

We are the controller of Creator account data
The information you give us to have a FileSaurus account and pay for it — your name, email, studio profile, plan, billing status and how you use the product. We decide why and how it is processed, and this policy governs it.
We are a processor of the Content a Creator uploads
The video, audio, images, documents, client names, client email addresses, comments and invoice details a Creator puts into the Service belong to that Creator’s engagement, not to ours. We process them only on that Creator’s instructions — to host, transcode, deliver and secure them — and the Creator is the controller. We do not use that Content for our own purposes.

If you are a Client or reviewer and want your information corrected or deleted, contact the Creator who invited you — they control it. You can also write to us at privacy@filesaurus.com and we will forward your request to them and help them act on it. See §14.

Creators who need a data processing addendum (GDPR Art. 28) for their own compliance can request one at privacy@filesaurus.com.

3.What we collect

Account and profile information
Your name, email address, and a password — which is stored only as a salted hash by our authentication provider, never in readable form. Optionally: studio name, country, logo and brand assets, accent colours, social links, custom subdomain, notification and comment-identity preferences.
Billing information
Your plan, subscription and trial status, renewal dates, invoice history, and a Stripe customer identifier. If you accept client payments, your Stripe connected account identifier and its status. We never see or store your full card number — card details go directly to Stripe, which is PCI-DSS certified.
Content you upload
Files (video, audio, images, documents) and everything attached to them: project and file names, descriptions, version history, comments and timestamps, approvals, and invoice line items. Content may itself contain personal information — faces, voices, names, embedded metadata such as EXIF location — that you or your client chose to put in it.
Client and contact information
Names and email addresses of the clients and reviewers you invite, your contacts directory, and the payer name and email on an invoice. This is information you supply about other people.
Review and delivery activity
Comments and who wrote them, and — where a project is tracked or restricted — a log of views and downloads recording the viewer’s email address, the action, and the time. Where a Creator enables the session watermark, the viewer’s email address, IP address and the date are rendered as an overlay on the media being viewed, so that the person watching is identified on screen.
Technical and log information
IP address, browser and device type, operating system, referring page, pages and features used, approximate location derived from IP (city or region level, not precise geolocation), request timestamps, and diagnostic and error logs. We collect this for every visitor, including people who only open a share link.
Product analytics and session recording
On our public marketing pages and on a Creator’s own signed-in pages, we measure which pages were visited and which actions were taken, and we record a replay of the session — what was clicked and scrolled, so we can see where people get stuck. Typed input is masked and never recorded. For a signed-in Creator this is linked to their account identifier. None of this runs on a review portal: if you are a Client opening a link a Creator sent you, you are not measured or recorded.
Communications
Emails, support requests and anything you send us, including attachments, and our replies. Delivery metadata for emails we send you — whether a message was delivered, bounced or failed.

What we do not collect

  • We do not knowingly collect sensitive personal information as defined by California and other state privacy laws — government identifiers, precise geolocation, racial or ethnic origin, religious beliefs, health, genetic or biometric data, sexual orientation, or the contents of your private communications with others — and we do not ask for it. Do not upload it. If it appears inside Content you upload, you are the controller of it and responsible for the lawful basis to hold it.
  • We do not run advertising, ad networks, ad pixels or cross-site tracking, and we do not build advertising profiles.
  • We do not use your Content to train machine-learning or AI models, and we do not license it to anyone who does.

4.Where it comes from

  • From you — when you register, fill in your profile, upload Content, invite a client, issue an invoice, comment on a review, or contact support.
  • From your device automatically — the technical and log information above, gathered as you use the Service.
  • From a Creator, about you — if you are a Client, the Creator who invited you gave us your name and email so the Service could send you a link and record your review.
  • From our providers — Stripe tells us about subscription and payment events and the verification status of a connected account; our email provider tells us whether a message was delivered.

5.Why we use it, and our legal bases

We use personal information only for the purposes below. For people in the EEA, the UK and Switzerland, the legal basis under the GDPR is shown alongside each one.

To provide the Service — contract (Art. 6(1)(b))
Creating and running your account, hosting and transcoding your files, generating portals and share links, delivering Content to the people you choose, recording comments and approvals, and producing invoices.
To take payment — contract (Art. 6(1)(b))
Charging subscriptions, managing trials and renewals, and passing invoice details to Stripe so a client can pay a Creator directly.
To communicate with you — contract, and legitimate interests (Art. 6(1)(f))
Transactional email: invitations, review notifications, invoice and payment notices, storage and expiry warnings, security alerts, and changes to our terms. These are part of the Service and are not marketing.
To secure the Service and prevent abuse — legitimate interests (Art. 6(1)(f))
Authentication, rate limiting, fraud and abuse detection, investigating misuse, enforcing quotas, and keeping logs that let us reconstruct what happened after an incident. Our interest is in running a service that is not taken over or abused.
To support, maintain and improve the Service — legitimate interests (Art. 6(1)(f))
Diagnosing errors, understanding which features are used, and planning capacity. We use aggregated and de-identified data for this wherever it will do.
Marketing — consent (Art. 6(1)(a)), or legitimate interests where permitted
Product news and offers, only where you have opted in or where the law allows us to email an existing customer about a similar service. Every marketing email has an unsubscribe link, and unsubscribing never affects transactional messages.
To comply with law and defend claims — legal obligation (Art. 6(1)(c)), legitimate interests (Art. 6(1)(f))
Tax and accounting records, responding to lawful requests, handling copyright notices, and establishing, exercising or defending legal claims.

Where we rely on legitimate interests, we have weighed them against your rights and freedoms, and you can object — see §11.

6.Cookies and similar technologies

We use only strictly necessary cookies. We run no advertising cookies, no analytics cookies that identify you across sites, and no third-party tracking pixels. That is why you do not see a consent banner: under the ePrivacy rules, cookies that are strictly necessary to provide a service you requested do not require consent.

Authentication cookies (strictly necessary)
Set by our authentication provider to keep you signed in and to refresh your session. Deleting them signs you out.
Portal access cookies (strictly necessary)
When you unlock a password-protected review portal, a cookie scoped to that share link remembers that you unlocked it, so you are not asked again on every page.
Preference storage (strictly necessary for the feature)
Local storage in your browser remembers interface preferences such as light or dark appearance. It never leaves your device.

Analytics. We measure how our website and app are used, and neither tool sets a cookie or identifies you across other sites. Cloudflare Web Analytics counts visits to our public marketing pages only. PostHog measures those same pages and a Creator’s own signed-in pages, including a session replay with typed input masked, and stores its identifier only in your browser’s memory for the life of the tab — nothing is written to your device and closing the tab ends it. Neither tool is active on a review portal. See §7 for both companies.

Fonts. Our pages load typefaces from Google Fonts. Your browser therefore makes a request to Google’s servers, which discloses your IP address and user agent to Google; Google states it does not use these requests to profile users. No cookie is set by that request.

You can block or delete cookies in your browser settings, but blocking the strictly necessary ones will stop you from signing in or opening protected portals.

7.Who we share it with

We disclose personal information only in the circumstances below. We never sell it.

Service providers (subprocessors)

These companies process data on our behalf, under contract, only for the purposes we specify. The list below is rendered from the same source as our subprocessor page, so the two cannot disagree, and it was last changed on September 22, 2026. We give at least 30 days’ notice before a new subprocessor begins processing personal data.

Vercel — application hosting and delivery
Request metadata and IP addresses. Serves the application and its pages.
Supabase — authentication and database
Accounts, credentials (stored only as salted hashes), projects, comments, contacts, activity logs and application data.
Cloudflare — file storage (R2), video encoding (Containers) and website analytics
Uploaded files and their metadata; hosts and transcodes video for playback. Processes request metadata and IP addresses at the network edge. On our public marketing pages only, records anonymous, cookieless visit counts — never on a review portal or inside the app.
Stripe — payments and subscriptions
Subscription payments, and — through Stripe Connect — client payments made directly to a creator. Billing contact details and payment method data, which we never see in full. Stripe acts as an independent controller for the payment data it handles, not solely as our processor.
Resend — transactional email
Recipient names, email addresses, message contents and delivery metadata for invitations, notifications, invoices and account email.
PostHog — product analytics
On our public marketing pages and on a signed-in creator’s own pages: pages visited, actions taken and a recording of the session, together with the account identifier of a signed-in creator. No cookie is set. Never active on a client review portal, so a client opening a shared link is not measured or recorded.
Unsplash — stock image search
Only when a creator searches for stock imagery inside the app. The search terms reach the provider; account information does not.
Pexels — stock media search
Only when a creator searches for stock media inside the app. The search terms reach the provider; account information does not.
Google Fonts — typefaces
Your browser requests font files directly from Google, which discloses your IP address and user agent to Google. No cookie is set by that request. Loaded by the browser rather than by our servers, so Google receives the request directly. Listed for completeness.

Other disclosures

  • People you share with. Content, comments and your studio profile are visible to the clients and reviewers you invite. That is the purpose of the Service, and once you send a link you no longer control who the recipient forwards it to.
  • The Creator who invited you. If you are a Client, the Creator sees your comments, your approvals, and — where enabled — a log of when you viewed or downloaded their files.
  • Legal and safety. We may disclose information where we believe in good faith it is necessary to comply with a law, regulation, subpoena, court order or lawful request; to enforce our Terms; to investigate fraud or abuse; or to protect the rights, property or safety of any person. Where we are permitted to tell you about a legal request before responding, we will.
  • Business transfers. If we are involved in a merger, acquisition, financing or sale of assets, information may transfer as part of that transaction. We will tell you before your information becomes subject to a materially different privacy policy, and you will be able to delete your account first.
  • With your direction. Anywhere else you ask us to send it.

8.We do not sell or share your personal information

We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the preceding twelve months — and we do not do so today. We do not sell or share the personal information of minors under 16 under any circumstances, because we do not knowingly collect it at all.

Because we do not sell or share personal information, there is no “Do Not Sell or Share My Personal Information” link to offer, and there is nothing for an opt-out to switch off. We nevertheless honour Global Privacy Control (GPC) and other recognised universal opt-out preference signals as a valid opt-out request under the laws of the states that require it: receiving one changes nothing about our practices only because there is no selling or sharing to stop.

If that ever changes, we will update this section, provide the opt-out mechanisms the law requires, and give notice before the change takes effect.

9.How long we keep it

We keep personal information only as long as we need it for the purpose it was collected for, or as long as the law requires.

  • Account and profile data — for as long as your account is open, and then deleted or de-identified within 90 days of account closure, except where a longer period is needed below.
  • Content — while your plan covers it. Deleting a project or file moves it to Trash for 30 days and then permanently deletes it. Expiry settings, plan downgrades, non-payment, termination and prolonged inactivity on a free-tier account can also cause deletion; see Terms §10. Keep your own master copies.
  • Activity logs (views and downloads) — retained with the project they belong to and deleted when the project is deleted, since their whole purpose is to tell a Creator who accessed that project.
  • Security and diagnostic logs — typically 30 to 90 days, longer where an entry is part of an open security or abuse investigation.
  • Billing and tax records — as long as tax and accounting law requires, generally seven years, regardless of account closure. This is a legal obligation and is not affected by a deletion request.
  • Backups — deleted data may persist in encrypted, access-controlled backups until they expire on their normal rotation, after which it is gone.
  • Records of legal claims and rights requests — for as long as needed to establish, exercise or defend a claim, and to prove we handled your request.

10.International transfers

We are based in the United States and our providers operate globally, so personal information may be transferred to, stored in, and processed in the United States and other countries whose data protection laws differ from those where you live.

Where we transfer personal information out of the EEA, the UK or Switzerland, we rely on an appropriate safeguard under Chapter V of the GDPR — normally the European Commission’s Standard Contractual Clauses (with the UK Addendum where applicable), combined with technical measures such as encryption in transit and at rest, and, where available, an adequacy decision or a provider’s certification under an approved framework. You may request a copy of the safeguard we rely on at privacy@filesaurus.com.

11.Your rights — EEA, UK and Switzerland

If the GDPR or UK GDPR applies to you, you have the right to:

  • Access the personal information we hold about you, and get a copy.
  • Rectify information that is inaccurate or incomplete.
  • Erase it (“right to be forgotten”), where one of the statutory grounds applies.
  • Restrict processing in certain circumstances.
  • Port the information you gave us, in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible.
  • Object to processing based on legitimate interests, and to object to direct marketing at any time, absolutely.
  • Withdraw consent at any time, without affecting processing already carried out.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions.
  • Complain to a supervisory authority in your country of residence, place of work, or where you believe an infringement occurred. We would appreciate the chance to address it first.

12.Your rights — California and other U.S. states

If you live in a state with a comprehensive privacy law — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky and Rhode Island — you have, to the extent your state’s law provides them, the right to:

  • Know and access the categories and specific pieces of personal information we collected, the sources, the purposes, and the categories of third parties we disclosed it to.
  • Delete personal information we collected from you, subject to legal exceptions.
  • Correct inaccurate personal information.
  • Obtain a portable copy of your personal information.
  • Opt out of the sale or sharing of personal information, of targeted advertising, and of profiling with legal or similarly significant effects — none of which we do (see §8).
  • Limit the use of sensitive personal information — we do not collect it for any purpose that would require this.
  • Not be discriminated against for exercising any of these rights. We will not deny you the Service, charge you a different price, or give you a lower quality of service.
  • Appeal a decision we make on your request. If we decline, our response will tell you how to appeal; write to privacy@filesaurus.com with “Privacy Appeal” in the subject and we will respond within the time your state allows. If we deny the appeal, you may complain to your state Attorney General.

California specifics

  • Notice at collection. The categories in §3, the purposes in §5, the disclosures in §7 and the retention periods in §9 together form our notice at collection under the CCPA/CPRA.
  • Shine the Light (Cal. Civ. Code § 1798.83). We do not disclose personal information to third parties for their own direct marketing purposes.
  • Authorised agents. An agent may submit a request on your behalf with written permission signed by you; we may still ask you to verify your identity directly.

13.How to exercise your rights

Many rights are self-service: sign in and use Settings to view and correct your profile, manage notifications, download or delete Content, and close your account. For anything else:

  1. Email privacy@filesaurus.com from the address on your account, telling us which right you are exercising and, where relevant, which state or country you are in.
  2. We will verify your identity in proportion to the sensitivity of the request — usually by confirming control of the account email, occasionally by asking for information only the account holder would know. We will not ask you for a government identifier.
  3. We respond within 45 days (US state laws) or one month (GDPR), and will tell you if we need an extension the law allows. There is no charge unless a request is manifestly unfounded or excessive, in which case we will explain before charging.

If your request concerns Content a Creator uploaded — for example a review portal you were invited to — we will pass it to that Creator, because they are the controller. See §2.

14.If you are a client or reviewer

You were invited to a portal by a Creator. In plain terms, here is what happens to your information:

  • The Creator gave us your name and email so we could send you the link and attribute your comments. They chose to do that; we did not obtain your details from anywhere else.
  • Your comments, approvals and — where the Creator turned tracking on — a record of when you viewed or downloaded each file, are visible to that Creator.
  • If the Creator turned on the session watermark, your email address and IP address are displayed over the media you are watching. This is a deliberate anti-leak measure, and the Creator chose it.
  • You do not need an account, and we do not use your information to market to you.

To see, correct or delete this information, contact the Creator who invited you. You can also write to us at privacy@filesaurus.com and we will route the request and assist. If you believe a Creator is using the Service to handle your information unlawfully, tell us at legal@filesaurus.com.

15.How we protect it

We use technical and organisational measures appropriate to the risk, including encryption in transit (TLS) and at rest, hashed passwords, row-level access control in our database so one account cannot read another’s data, signed and time-limited URLs for file access, scoped share tokens, rate limiting, least-privilege access for our own staff, and providers who maintain recognised security certifications.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You play a part too: use a strong, unique password, treat share links as keys, and use the passwords and expiry settings the Service offers for sensitive deliveries.

If a breach affects your personal information, we will notify you and the relevant authorities where the law requires, and within the deadlines it sets.

16.Children

The Service is a business tool for adults and is not directed to children under 18. We do not knowingly collect personal information from anyone under 16, and we do not knowingly sell or share the personal information of anyone under 16 — we do not sell or share personal information at all. If you believe a child has given us personal information, contact privacy@filesaurus.com and we will delete it promptly. Creators are responsible for obtaining any parental consent required for minors who appear in Content they upload.

17.Changes to this policy

We will update this policy as the Service or the law changes. The “Last updated” date at the top always reflects the current version. If a change is material — a new purpose, a new category of data, a new kind of disclosure — we will give notice by email or inside the Service before it takes effect, and, where the law requires consent for the change, we will ask for it. Please review this page periodically.

18.How to reach us

Kerry Ngan

See also our Terms of Service, which govern your use of the Service.