Legal
Privacy Policy
Last revised: September 2026 · Effective immediately
§ Overview
VaultDrop ("the Service", "we", "us") is a privacy-first file hosting and sharing platform. This Privacy Policy outlines how we handle your information, what we collect, what we do not collect, and your rights as a user.
By using VaultDrop, you agree to the practices described in this document. We have written it to be clear and honest — no legalese, no hidden clauses.
1 Philosophy of Non-Interaction
VaultDrop is built on the principle that your data belongs to you. We do not index, scan, analyze, or algorithmically process user content. Our infrastructure is designed to act as a neutral conduit — providing fast, secure storage without surveillance.
Our commitment: We will never sell your data, build advertising profiles, or use your files to train AI systems of any kind.
2 What We Collect
We collect only the minimum necessary to operate the service:
- Email address — used for account creation and authentication only, never shared.
- Hashed password — bcrypt-hashed, never stored in plain text, never readable by us.
- File metadata — filename, size, upload date. Used solely to display your dashboard.
- Payment info — processed entirely by Stripe. We never see or store card numbers.
Encryption: All connections use TLS 1.3. Files at rest are stored on encrypted volumes. We do not hold decryption keys for client-side encrypted files.
3 What We Do NOT Collect
- IP addresses of uploaders or downloaders — we do not log them.
- Browser fingerprints, device identifiers, or behavioral data.
- Third-party analytics or tracking scripts of any kind.
- Advertising identifiers or cross-site tracking cookies.
Zero tracking, zero ads. VaultDrop does not display ads and never will. We earn revenue through subscriptions only.
4 DMCA & Copyright Claims
VaultDrop does not host files on its own servers. Files are stored on independent, third-party object storage infrastructure. VaultDrop is solely an interface layer — we provide authentication, organization, and sharing tools, but we do not physically store files ourselves.
As a result:
- The US Digital Millennium Copyright Act (DMCA) does not apply to VaultDrop as we are not a US-based entity and do not directly host content.
- DMCA takedown notices addressed to VaultDrop cannot be technically actioned — we have no ability to modify or delete files at the storage infrastructure level on behalf of third parties.
- Copyright claims must be directed to the underlying storage infrastructure provider directly.
DMCA Non-Recognition: We maintain a stance of technical neutrality. DMCA notices sent to VaultDrop will not be processed as we are not a US entity or a direct content host. We have no technical means to honor them.
5 Content Policy & File Removal
While we strongly defend user privacy and data neutrality, we maintain firm ethical boundaries. We reserve the right to remove any file or terminate any account at our sole discretion if the content is deemed harmful, dangerous, or illegal.
Content that will be removed immediately upon discovery, without notice:
- Any material depicting sexual abuse or exploitation of minors (CSAM) — reported to authorities immediately.
- Content facilitating terrorism, mass violence, or targeted harassment.
- Malware, ransomware, exploits, or any software designed to cause harm.
- Content that is illegal under French or European Union law.
- Graphic, non-consensual violence or torture of humans or animals.
To report prohibited content, contact us at the address below. We review and act on all reports promptly. Account termination for policy violations is permanent and non-reversible.
6 Data Retention & Deletion
- Files are stored until you delete them or your account is terminated.
- Deleted files are unlinked from our system immediately and purged from storage within 30 days.
- Account data is permanently deleted within 30 days of account closure upon request.
- Payment records are retained for 7 years as required by French tax law (Article L123-22 of the Commercial Code).
- Expired share links are automatically purged from our database.
7 Cookies & Session Data
VaultDrop uses a single, strictly necessary cookie:
- Session cookie — maintains your authenticated session. Contains only an opaque session identifier. Deleted automatically on logout or after inactivity. No personal data embedded.
We use no analytics cookies, advertising cookies, or third-party tracking scripts. Ever.
8 Law Enforcement
We do not voluntarily cooperate with law enforcement data requests. We will only provide data when compelled by a valid, legally binding court order issued within our operating jurisdiction.
Due to our zero-logging architecture, the information we can provide in any case is extremely limited — typically only account existence and creation date.
9 Your Rights (GDPR)
VaultDrop operates under EU law and fully complies with the GDPR. You have the right to:
- Access — request a copy of personal data we hold about you.
- Rectification — correct inaccurate data associated with your account.
- Erasure — request permanent deletion of your account and all associated data.
- Portability — export your data in a machine-readable format.
- Objection — object to any processing we perform on your data.
We will respond to all GDPR requests within 30 days.
10 Security
- All connections encrypted with TLS 1.2 or higher — no exceptions.
- Passwords hashed with bcrypt (high work factor) — never stored in plain text.
- Share links use cryptographically random tokens.
- Download tokens are single-use and expire automatically after 15 minutes.
- Session cookies are httpOnly and Secure — inaccessible to JavaScript.
- Rate limiting applied to all authentication endpoints.
11 Payments, Subscriptions & Right of Withdrawal
Subscriptions are activated via an access code (purchased directly, through a payment link, or received as a gift) redeemed on your account. By purchasing an access code or subscription, you agree to our general terms of service for the product.
- Access codes and subscriptions are non-refundable and non-exchangeable once issued. We do not offer refunds, credits, or exchanges for a different plan after a code has been generated and sent, except where required by law.
- For cryptocurrency payments specifically: sending funds on the wrong network, to the wrong address, or for an incorrect amount results in an irreversible loss of funds. We cannot recover or refund misdirected cryptocurrency transactions under any circumstance.
Right of withdrawal (EU consumers): Under EU consumer protection law, purchasers of digital content or services would normally benefit from a 14-day right of withdrawal. By completing a purchase on VaultDrop, you expressly request that we begin providing the service (activation of your access code) immediately, and you acknowledge and agree that you thereby lose your right of withdrawal once the code has been issued, in accordance with Article 16(m) of Directive 2011/83/EU on consumer rights (and its national transpositions, including Article L221-28 13° of the French Consumer Code).
12 Changes to this Policy
We may update this policy from time to time. Significant changes will be communicated via email. Continued use of the Service after changes are posted constitutes acceptance of the updated policy.
The date at the top of this page always reflects the last revision.