SendFlo

Privacy Policy

Last updated: September 30, 2026

This policy explains what SendFlo LLC ("SendFlo", "we") collects when you use SendFlo, why, and what your rights are. The short version: your email is your identity, your files are yours, direct transfers never touch our servers, and we don't sell data — to anyone, ever.

1. What we collect

  • Account data — your email address (every account has one; it anchors your sign-in methods: email codes, a password if you set one — stored only as a salted hash by our authentication service — Google, Facebook, X and passkeys), plan and team membership, the preferences you set, and your home storage region, derived once from the country you signed up from.
  • Device data — the devices you register (name, platform, app version), their activity heartbeats, and the IP address each device last connected from, which we show you in Settings → Network & Devices so you can recognise your own devices. Everywhere else we keep IP addresses only as salted hashes, used for nearby-device discovery, security and rate limiting.
  • Transfer data — metadata about your transfers (file names, sizes, recipients, timestamps) for your history; and, for staged transfers only (links, relays, file requests), the file content itself while it awaits delivery or expiry. Files sent directly device-to-device travel peer-to-peer or through an encrypted relay and are never stored on our servers.
  • Payment data — handled entirely by Paddle.com, our reseller and merchant of record, which processes your payment details under its own privacy policy; we receive plan, status, and receipt metadata, never your card number.
  • Support & service data — messages you send us by email or through the support chat, copies of the service emails we send you, and minimal operational logs.

2. How we use it

To run the service you asked for: delivering transfers, syncing your devices, showing your history, sending the notifications you enabled, billing your plan, preventing abuse (staged content passes automated abuse scanning — no human reads your files), and meeting legal obligations. We send product email only per your notification preferences, and marketing email only with consent you can withdraw in one click.

3. Legal bases (EU/UK)

Where GDPR applies: performing our contract with you (the service itself, billing), legitimate interests (abuse prevention, service security, minimal logs), consent (marketing), and legal obligation (tax and accounting records).

4. Who we share with

The recipients you choose receive what you send them — that is the product. Beyond that, data is processed only by the infrastructure providers the service runs on — hosting, content delivery and relay, cloud storage, email delivery, customer-support chat, and payment processing (Paddle.com, our merchant of record) — each bound by data-processing agreements and used only to operate the service. We do not sell or rent personal data, and we disclose it to authorities only when legally compelled.

5. International transfers

Our providers operate globally; where personal data leaves the EU/UK it travels under standard contractual clauses or an equivalent lawful mechanism.

6. Retention and deletion

While your account exists:

  • Staged files: deleted on their expiry schedule, or when File Restore lapses.
  • Transfer history, device records (including each device's last IP address), copies of the emails we send you, and support conversations: kept while your account exists — for a team, while the team exists.
  • Salted IP hashes and operational logs: rotated automatically and kept no longer than 30 days.
  • Database backups: taken daily and kept for 30 days, used only to recover from failures. File contents are not backed up.

When you delete your account (Settings → Sign In & Security → Delete account — see how it works), it is disabled on every device at once, your share links and upload pages stop working, and everything — files and their copies (including File Restore copies), links, collections, history, devices, settings, sign-in methods, copies of our emails to you and your support conversations — is permanently deleted no later than 14 days after your request. Until then you can restore the account by signing in. We keep only:

  • Payment and refund records, for 7 years, because tax and accounting law requires it.
  • Security and audit records, with your email replaced by an anonymous identifier.
  • Abuse reports, with your email replaced by an anonymous identifier, for up to 2 years.
  • Support conversations only while a refund dispute, chargeback or abuse case about the account is open.
  • A bounce or complaint record for your address, if one exists, so we never email it again.
  • This month's usage totals, linked to a hashed form of your email until the month ends plus 35 days, so limits can't be reset by deleting and re-creating an account.
  • A deletion record (a hashed form of your email and the dates) for 37 days. Backups expire within 30 days and are never used for anything else; if we ever restore one, your deletion is applied again before the service resumes.

Files other people already downloaded, and their own records of what you shared with them, stay with them. Teams: files shared in a team workspace belong to the team. When a member leaves, the team keeps them; the team's owner or an admin can instead delete a member's data (it is gone within 14 days), and only the owner can delete the whole team (everything is deleted within 14 days; members are told first and can download their files meanwhile).

7. Security

All traffic is encrypted in transit (TLS; direct transfers use end-to-end encrypted peer connections). Staged content is stored on access-controlled infrastructure, and internal access follows least privilege. No service can promise absolute security — see the Terms for our liability framework — but security decisions here consistently favor storing less: hashed IP addresses except each device's last one, passwords only as salted hashes, no card data.

8. Compliance posture (incl. health data)

Plain statements, so nobody has to guess: GDPR and CCPA rights apply as described below. SendFlo is not HDS-certified (France's certification for hosting personal health data) and is not certified under ISO 27001 — please do not use SendFlo to store personal health data subject to HDS. We publish an internal readiness roadmap and will only ever claim a certification after an accredited audit, with the certificate to show for it. End-to-end encrypted links keep the decryption key in the link fragment, which never reaches our servers — for those transfers we cannot read the content we host.

9. Your rights

You can access, correct, export, or delete your data — most of it directly in the app (history, devices, and deleting your whole account from Settings → Sign In & Security → Delete account), the rest by writing to support@sendflo.app from your account email. EU/UK residents additionally have GDPR rights (objection, restriction, portability, and complaint to a supervisory authority); California residents have the corresponding CCPA rights. We do not discriminate for exercising them.

10. Cookies

We use only functional cookies and local storage: your session, your preferences, and service state. No advertising cookies, no cross-site tracking, no third-party analytics beacons on file content pages.

11. Children

The service is not directed at children under 13, and we do not knowingly collect their data; if you believe a child has an account, contact us and we will delete it.

12. Changes

We will update this policy as the service evolves and give notice of material changes by email or in the app before they take effect.

Questions about this document: support@sendflo.app · Terms · Privacy · Refunds & Cancellation