1. The short version
- File processing happens on your device. Your files never reach our servers — by design, not just by policy. (Optional cloud processing is planned but not yet available; it will always be opt-in per job.)
- We never log or store the contents of your files. Our systems record job metadata only: operation type, file counts, byte sizes, settings, status, and timestamps. Not filenames, not contents.
- No analytics, no advertising trackers. We use no third-party analytics and no tracking cookies — see our Cookie Policy.
- We don’t sell your data. Payments are handled by Square; your full card number never touches our servers.
2. What we process, by category
2.1 File contents
| Processing mode | What happens to your file | Retention |
|---|---|---|
| Local (the only mode today) | Processed entirely in your browser. The file is not transmitted to our servers. | Nothing to retain — we never receive it. Working data stays in your browser’s memory and is gone when you close or reload the page. |
| Cloud (planned, not yet available) | When offered, files would be uploaded over HTTPS to our processing infrastructure, processed, and returned to you — always opt-in and clearly indicated per job. | Committed schedule for launch: inputs and outputs auto-deleted within 24 hours of job completion. See the Data Retention & Deletion Policy. |
| Connected storage (opt-in) | Outputs saved directly to your Google Drive at your direction. The file content passes through our API only transiently to complete the upload you requested; we keep no copy. | Governed by your Google account; we keep no copy of the file. |
| Private/enterprise engine | Processed on your organization’s infrastructure. | Governed by your organization’s policies and the enterprise agreement. |
Each job’s processing mode is recorded on its job record, which you can review in your job history when signed in.
2.2 Account data (if you register)
Email address, name (optional), an Argon2id hash of your password (we never store plain passwords), plan/entitlement state, and settings such as saved presets. Saved presets store processing options only (e.g., target size or output format); they cannot contain file names, paths, or file contents — our API rejects such fields. Sign-in is currently by email and password only.
2.3 Usage and job metadata (metadata-only logging)
For service operation, plan-limit enforcement, security, and billing we record metadata such as: product and operation type, engine, execution mode (browser/desktop/cloud), file counts, total input/output sizes in bytes, compression savings, operation settings (e.g., target format or quality), status (success/failure and a safe error code), and timestamps. We do not log file contents, file names, extracted text, image pixels, or document contents. Our API is built to reject metadata fields that could contain filenames, paths, or file data.
2.4 Billing data
Handled by Square, Inc. Your card details are entered into Square’s secure payment form and tokenized in your browser; our API receives only an opaque single-use token, never a card number. We store only your Square customer/subscription identifiers, plan, and subscription status. Square processes your payment data under its own privacy policy (https://squareup.com/privacy).
2.5 Cloud connector tokens
If you connect Google Drive, we store the OAuth refresh token encrypted at rest (AES-256-GCM) and request only the least-privilege scope needed: drive.file, which limits our access to files the Service creates or that you explicitly open with it. Short-lived access tokens are cached in memory only and never persisted. We use the connection solely for actions you initiate (saving an output file to your Drive). We do not read, scan, or index your Drive contents. When you disconnect, we revoke the grant at Google and delete the stored token immediately.
2.6 Technical data
IP address, browser/device type (user agent), and error codes needed for security, abuse prevention, and rate limiting. Sign-in, connector, and billing events are recorded in a security audit log that is scrubbed of anything resembling a password, token, filename, or file content. Server logs are retained for up to 30 days and then deleted or anonymized.
2.7 Analytics and cookies
We currently use no analytics trackers, no advertising cookies, and no cross-site tracking on geniefolder.com — no Google Analytics, no ad-tech SDKs, no third-party cookies of any kind. The only cookies we set are strictly necessary session cookies — see our Cookie Policy. If we ever add privacy-respecting analytics, we will update this policy and the Cookie Policy before they ship.
2.8 Error tracking
We do not currently use any third-party error-tracking service (e.g., Sentry). Errors are recorded in our own systems as error codes and safe metadata only — never file data.
3. What we do NOT collect
- File contents — files are processed on your device and never transmitted to us.
- File contents or filenames in logs, analytics, or error reports. Error records capture error codes and metadata, not file data.
- Advertising identifiers; we do not run third-party ad networks.
- Precise location data, contacts, or device identifiers beyond what is described above.
4. Legal bases for processing (GDPR)
| Purpose | Data | Legal basis |
|---|---|---|
| Provide the Service you request | Job metadata, settings | Performance of a contract (Art. 6(1)(b)) |
| Account administration, entitlements | Account data | Contract (Art. 6(1)(b)) |
| Billing, tax, accounting | Billing records | Legal obligation (Art. 6(1)(c)) |
| Security, abuse prevention, rate limiting | Technical data, metadata, audit log | Legitimate interest (Art. 6(1)(f)) |
| Product improvement (aggregate, metadata only) | Usage metadata | Legitimate interest (Art. 6(1)(f)) — you may object |
| Cloud connectors | OAuth tokens, drive actions you initiate | Contract / your explicit action (Art. 6(1)(b)); consent where required (Art. 6(1)(a)) |
5. Sharing and subprocessors
We do not sell personal data. We share data only with the following service providers, each bound by data-processing terms:
| Provider | Role | Data involved |
|---|---|---|
| Amazon Web Services (us-east-1) | API and database hosting | Account data, job metadata, audit logs |
| Cloudflare | Website hosting and content delivery (CDN) | Technical data (IP address) inherent to serving the site |
| Resend | Transactional email (verification, team invites) | Your email address and name |
| Square | Payment processing | Billing data as described in §2.4 |
| OAuth authorization for the optional Google Drive connector | Only when you connect Drive, and only the actions you initiate |
We may also disclose data where required by law or to protect rights and safety. International transfers: where personal data is transferred outside the EEA/UK, we rely on our vendors’ data-processing agreements, including Standard Contractual Clauses or equivalent safeguards where required. This subprocessor list is kept current on this page; material changes are announced per Section 10.
6. Retention summary
| Data | Retention |
|---|---|
| Your files | Never received by us (local processing); cloud jobs will auto-delete within 24 hours when that mode launches |
| Job metadata | Kept while your account is active so your job history works; deleted or anonymized when you delete your account |
| Account data | While your account is active; deleted within 30 days of a verified deletion request, except billing records kept as tax law requires (up to 7 years) |
| OAuth tokens (Google Drive) | Deleted immediately when you disconnect the connector |
| Security audit log | Up to 12 months, then deleted or anonymized |
| Server logs | Up to 30 days, then deleted or anonymized |
See the Data Retention & Deletion Policy for the full schedule, including token and invite lifetimes.
7. Your rights
GDPR/EEA/UK: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent (without affecting prior lawful processing). You also have the right to lodge a complaint with your supervisory authority.
CCPA/CPRA (California): the right to know, delete, correct, and to opt out of sale/sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising, and we do not use or disclose sensitive personal information beyond permitted purposes. You will not be discriminated against for exercising rights.
How to exercise rights: email info@geniefolder.com from your account address, or use in-product controls where available (connector disconnect, preset deletion). We respond within 30 days. Account deletion removes account data per Section 6; files in your connected cloud storage are not affected (they are yours, in your accounts).
8. Security
- TLS encryption in transit; AES-256-GCM encryption at rest for stored OAuth tokens.
- Passwords stored as Argon2id hashes; session refresh tokens stored only as SHA-256 hashes, rotated on every use, with automatic revocation of all sessions if a reused token is detected.
- Least-privilege OAuth scopes; backend-enforced plan entitlements; rate limiting on all authentication and billing endpoints.
- No file-content logging by design; metadata-only observability with automated scrubbing of sensitive-looking fields.
- If a security incident affects your personal data, we will notify you and the relevant authorities as required by applicable law.
9. Children
The Service is not directed at children under 13, and we do not knowingly collect their data. If you believe a child under 13 has provided us data, contact us and we will remove it.
10. Changes to this policy
We will post changes here and notify registered users by email or in-product notice at least 30 days before material changes take effect.
11. Contact
- Privacy requests: info@geniefolder.com
- Data Protection Officer: not appointed — not required at our current scale; privacy requests are handled directly at the address above.
- EU/UK representative under Art. 27 GDPR: not appointed at this stage; you may contact us directly at the address above for any data-protection matter.
- Postal address: available on request via info@geniefolder.com.