1. The short version
- Most file processing happens on your device. For local jobs, your files never reach our servers — by design, not just by policy.
- We never log or store the contents of your files. Our systems record job metadata only (e.g., file count, sizes, formats, timestamps, success/failure).
- Cloud processing is optional and clearly labeled. If you choose a cloud job, temporary files are auto-deleted on a published schedule (see the Data Retention & Deletion Policy).
- We don’t sell your data. Payments are handled by Square; we never see your full card number.
2. What we process, by category
2.1 File contents
| Processing mode | What happens to your file | Retention |
|---|---|---|
| Local (default) | Processed entirely in your browser/desktop app. The file is not transmitted to our servers. | Nothing to retain — we never receive it. Temporary data in your browser (e.g., IndexedDB job state) stays on your device and is cleared by your browser or by you. |
| Cloud (opt-in per job) | Uploaded over HTTPS to our processing infrastructure, processed, and returned to you. | Inputs and outputs auto-deleted within [Pending owner/lawyer: confirm tiers, e.g., 1 hour default / 24 hours extended / enterprise custom]. Backup/log residue: [Pending owner/lawyer: specify, e.g., encrypted backups ≤ 7 days]. |
| Connected storage (opt-in) | Outputs saved directly to your Google Drive / OneDrive at your direction; inputs may be read from those services at your direction. | Governed by your third-party account; we keep no copy beyond the cloud-processing retention above. |
| Private/enterprise engine | Processed on your organization’s infrastructure. | Governed by your organization’s policies and the enterprise agreement. |
Every job displays its processing mode in the interface. [Pending owner/lawyer: verify this UI commitment ships before the policy is published]
2.2 Account data (if you register)
Email address, name (optional), authentication identifiers (including Google/Microsoft sign-in IDs if used), plan/entitlement state, and settings (e.g., saved presets). Saved presets and preferences may be synced to your account; they do not contain file contents.
2.3 Usage and job metadata (metadata-only logging)
For service operation, security, metering, and billing we log metadata such as: job type, engine, execution mode (browser/desktop/cloud), file counts, file sizes (bytes), file formats (MIME/extension), processing duration, status (success/failure and error category), and coarse timestamps. We do not log file contents, file names beyond what is necessary for job display [Pending owner/lawyer: decide whether filenames are logged at all — recommended: hash or truncate], extracted text, image pixels, or document contents.
2.4 Billing data
Handled by Square, Inc. We receive from Square: customer/subscription identifiers, plan status, invoices, and limited card metadata (brand, last 4 digits, expiry). We never receive or store full card numbers or CVVs. Square processes your payment data under its own privacy policy (https://squareup.com/privacy).
2.5 Cloud connector tokens
If you connect Google Drive or OneDrive, we store OAuth access/refresh tokens encrypted at rest, request only the least-privilege scopes needed for the features you enable, and use them solely to perform actions you initiate (e.g., saving an output file to a folder you chose). We do not read or index your drive contents beyond the files you explicitly select. [Pending owner/lawyer: list exact OAuth scopes per provider once app registrations are finalized, and complete Google verification/Limited Use disclosure]
2.6 Technical data
IP address, browser/device type, and coarse telemetry needed for security, abuse prevention, and rate limiting. Server logs are retained for [Pending owner/lawyer: e.g., 30 days] and then deleted or anonymized.
2.7 Analytics and cookies
We currently use no analytics trackers, no advertising cookies, and no cross-site tracking on geniefolder.com. The only cookies we set are strictly necessary session cookies — see our Cookie Policy. [Pending owner/lawyer: if privacy-respecting analytics (e.g., Plausible/PostHog self-hosted) are added later, update this section and the Cookie Policy before they ship]
3. What we do NOT collect
- File contents for local jobs (never transmitted).
- File contents in logs, analytics, or error reports (all modes). Error reports capture error codes and metadata, not file data.
- Advertising identifiers; we do not run third-party ad networks.
- [Pending owner/lawyer: confirm with engineering before publishing — this list must be technically true]
4. Legal bases for processing (GDPR)
| Purpose | Data | Legal basis |
|---|---|---|
| Provide the Service you request | Files (cloud jobs only), job metadata, settings | Performance of a contract (Art. 6(1)(b)) |
| Account administration, entitlements | Account data | Contract (Art. 6(1)(b)) |
| Billing, tax, accounting | Billing records | Legal obligation (Art. 6(1)(c)) |
| Security, abuse prevention, rate limiting | Technical data, metadata | Legitimate interest (Art. 6(1)(f)) |
| Product improvement (aggregate, metadata only) | Usage metadata | Legitimate interest (Art. 6(1)(f)) — you may object |
| Cloud connectors | OAuth tokens, drive actions you initiate | Contract / your explicit action (Art. 6(1)(b)); consent where required (Art. 6(1)(a)) |
5. Sharing and subprocessors
We do not sell personal data. We share data only with:
- Square — payments (billing data as described above).
- Cloud infrastructure providers — hosting and temporary file storage under data-processing terms. Our planned stack (per engineering records) is Cloudflare (web hosting, DNS, and R2 temporary object storage) and Fly.io (API containers), with managed Postgres/Redis providers. [Pending owner/lawyer: confirm the final subprocessor list before publication]
- Google / Microsoft — only when you connect Drive/OneDrive, and only the actions you initiate.
- Error tracking — [Pending owner/lawyer: e.g., Sentry] — error metadata (no file contents).
- Legal process — where required by law or to protect rights/safety.
International transfers: where data is transferred outside the EEA/UK, we rely on [Pending owner/lawyer: SCCs / adequacy decisions / DPF certification of vendors]. A subprocessor list will be maintained at [Pending owner/lawyer: URL].
6. Retention summary
| Data | Retention |
|---|---|
| Local-job files | Never received by us |
| Cloud-job files (inputs/outputs) | Auto-deleted within [Pending owner/lawyer: tiers] |
| Job metadata | [Pending owner/lawyer: e.g., 12 months, then aggregated/anonymized] |
| Account data | While account active + [Pending owner/lawyer: e.g., 30 days] after deletion request, except billing records kept per tax law ([Pending owner/lawyer: e.g., 7 years]) |
| OAuth tokens | Until you disconnect + [Pending owner/lawyer: e.g., 30 days] |
| Server/security logs | [Pending owner/lawyer: e.g., 30 days] |
See the Data Retention & Deletion Policy for the full schedule, including token and invite lifetimes.
7. Your rights
GDPR/EEA/UK: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent (without affecting prior lawful processing). You also have the right to lodge a complaint with your supervisory authority.
CCPA/CPRA (California): the right to know, delete, correct, and to opt out of sale/sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising, and we do not use or disclose sensitive personal information beyond permitted purposes. You will not be discriminated against for exercising rights.
How to exercise rights: email info@geniefolder.com or use in-product controls (account deletion, connector disconnect, data export). We respond within [Pending owner/lawyer: 30 days / statutory period]. Account deletion removes account data per Section 6; files in your connected cloud storage are not affected (they are yours, in your accounts).
8. Security
- TLS encryption in transit; encryption at rest for stored tokens and any temporary cloud files.
- Least-privilege OAuth scopes; backend-enforced entitlements; isolated processing engines.
- Automated, monitored file deletion with alerting on failure.
- No file-content logging by design; metadata-only observability.
- [Pending owner/lawyer: add incident-notification commitment wording and link to a security page; enterprise SOC 2 roadmap language only if approved]
9. Children
The Service is not directed at children under [Pending owner/lawyer: 13 (US) / 16 (or applicable digital-consent age in EEA)], and we do not knowingly collect their data. Contact us to remove any such data.
10. Changes to this policy
We will post changes here and notify registered users by email or in-product notice at least [Pending owner/lawyer: 14–30] days before material changes take effect.
11. Contact
- Privacy requests: info@geniefolder.com
- Data Protection Officer (if appointed): [Pending owner/lawyer: to be confirmed]
- EU/UK representative (if required under Art. 27 GDPR): [Pending owner/lawyer: to be confirmed]
- Postal address: [Pending owner/lawyer: to be confirmed]
Drafting note carried over from the source template: this policy makes strong architectural claims (“files never reach our servers”, “metadata-only logging”, “encrypted tokens”, “least-privilege scopes”). Each must be verified against the shipped system before publication; an inaccurate privacy promise is a larger legal exposure than a cautious one.