Privacy Policy
1 Overview
At PROTOCOLIX, we take your privacy seriously. This Privacy Policy explains how FileIO ("the Service", "we", "us", or "our") collects, uses, and protects your personal information when you use our platform.
By using FileIO, you agree to the collection and use of information in accordance with this policy. We will not use or share your personal data with anyone except as described in this Privacy Policy.
2 Data We Collect
We collect information in the following categories:
Account Information — when you register:
- Email address
- Password (stored as a bcrypt hash — we never store plaintext passwords)
- Account creation date and last login timestamp
Usage Data — automatically collected when you use the Service:
- IP address (used for rate limiting and abuse prevention)
- Browser type, operating system, and device type
- Pages visited and features used
- Credit usage history and transaction records
- File upload metadata (file name, size, type, expiry settings)
Payment Information — we use Stripe to process payments. We do not store your card details; Stripe handles all payment data under their own privacy policy.
3 How We Use Your Data
We use the information we collect to:
- Provide, operate, and maintain the Service
- Authenticate your identity and secure your account
- Process payments and manage your credit balance
- Send transactional emails (account verification, password reset, receipts)
- Detect and prevent fraud, abuse, and Terms violations
- Respond to your support requests and inquiries
- Analyse aggregate usage trends to improve the Service
- Comply with legal obligations
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
4 Your Files & Content
Files you upload to FileIO are processed solely to provide the requested service (sharing, PDF manipulation, image processing, etc.).
- Uploaded files are automatically and permanently deleted after 24 hours
- Files are stored encrypted using AES-256 at rest
- We do not access or inspect the contents of your files except where required to investigate a reported abuse violation
- Image and PDF tools process your files in memory or temporary server storage and do not retain processed results after delivery
- AI-generated images are stored only in your session and are not linked to your account unless you save them
5 Cookies & Tracking
We use cookies and similar tracking technologies to improve your experience:
- Session cookies — keep you logged in during your session (deleted when you close the browser)
- Authentication cookies — remember your login if you choose "Remember me" (30-day expiry)
- CSRF tokens — protect against cross-site request forgery attacks
- Preference cookies — store your theme (light/dark mode) setting
We do not use advertising cookies, cross-site tracking pixels, or third-party analytics cookies. You can disable cookies in your browser settings, but some features may not function correctly.
6 Third-Party Services
We integrate with the following third parties to deliver the Service:
- Stripe — payment processing. Your card data is handled exclusively by Stripe and subject to their Privacy Policy.
- jsDelivr CDN — delivers static assets (JavaScript libraries, fonts). May log your IP per their own policy.
- Bootstrap Icons / Google Fonts — UI assets served from external CDNs.
We are not responsible for the privacy practices of these third-party services. We encourage you to review their respective privacy policies.
7 Data Retention
We retain different types of data for different periods:
- Uploaded files — deleted automatically after 24 hours
- Account data — retained for as long as your account is active, plus 30 days after deletion to allow recovery
- Transaction records — retained for 7 years to comply with financial regulations
- Server logs — retained for 30 days for security and debugging purposes, then purged
- Support correspondence — retained for 2 years after ticket closure
You may request deletion of your account and associated data at any time by contacting us. Deletion requests are processed within 30 days.
8 Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate or incomplete data
- Erasure — request deletion of your personal data ("right to be forgotten")
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing of your data for certain purposes
- Restriction — request that we limit how we use your data
To exercise any of these rights, email us at privacy@protocolix.com. We will respond within 30 days. We may need to verify your identity before fulfilling certain requests.
9 Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction:
- All data transmitted between your browser and our servers is encrypted using TLS 1.2+
- Files at rest are encrypted with AES-256
- Passwords are hashed using bcrypt with a work factor of 12
- Access to production systems is restricted by role and protected by multi-factor authentication
- We conduct regular security reviews and dependency audits
Despite these measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
10 Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us:
- Email: privacy@protocolix.com
- Security issues: security@protocolix.com
- Company: PROTOCOLIX
- Response time: within 2 business days
We may update this Privacy Policy from time to time. Material changes will be notified via email or an in-app notice at least 14 days before they take effect.