Privacy Policy
1. Who we are
WeDoFiles is operated by Noh Daejun, an individual established in the State of Wyoming, United States. In this Privacy Policy, "WeDoFiles," "we," "us," and "our" refer to that operator, who decides the purposes and means of the handling described here.
This Privacy Policy is version 2026-09-18 and takes effect on September 18, 2026. It is a notice describing how we handle personal information. It is not a request for consent; where consent is required for a specific activity, we ask for it separately.
Contact us about privacy at [email protected] or by post at 30 N Gould St Ste N, Sheridan, Wyoming 82801, United States. The Contact page lists every route to us. WeDoFiles operates online only and does not publish a telephone number; email is the fastest route to a person.
2. Where WeDoFiles is offered
WeDoFiles is offered from the United States. We do not offer the service to, and we block access from, the European Economic Area, the United Kingdom, Switzerland, and the European overseas territories to which those laws extend. We do not monitor the behavior of individuals in those regions. Registration, application and API access, purchases, and public share links are refused from a blocked location.
3. Information we collect
Information you give us
- Account information: your email address and a password. The password is stored only as a cryptographic hash and is never stored in a readable form.
- Settings and preferences you choose for the account.
- Files and folders you upload, the names you give them, and the sharing and controlled-embed settings you apply to them, including saved publisher domains.
- Correspondence: support, privacy, refund, copyright, counter-notice, and abuse-report messages, including the contact details and evidence they contain.
- Waitlist information: your email address and confirmation state, if you join the waitlist before an account exists.
Information created by your use of the service
- File metadata: size, type, storage location, malware-scan status, and the activity timestamps used for the file-retention rules in the Terms of Service.
- Delivery records: share and embed identifiers, permissions, expiry, download counts, and bytes delivered. For public shares we retain daily aggregate recipient-page views and completed-download counts by publisher and share. For embeds we also retain daily aggregate view and media-request counts, cache and range-request totals, and the normalized hostname of the publisher site. We do not retain a visitor's IP address, User-Agent string, full referring URL, or a recipient identifier in either aggregate usage record.
- How you first reached us: one category chosen from a fixed list (direct visit, search engine, our communities page, a public share link, or our moderators page), recorded when you register or join the waitlist. It is set once and not changed afterward. We derive it from the page you started on and, for search engines, from whether the referring site is a known search engine. We do not store the referring address, the link you followed, campaign parameters, or which share link you came from.
- Plan and usage records: storage and transfer totals, plan, account status, daily paid-publisher public-share eligibility, and the per-file and per-domain aggregate embed figures shown to the account owner.
- Download-grant records: when a public-share download first delivers file content, we keep a one-way hash of that download's single-use grant so that repeated or retried requests for the same download are counted once. The hash cannot be used to recover the grant or to identify the recipient.
- Security records: IP address, user agent, session records, request and audit identifiers, malware-scan results, moderation decisions, and abuse reports.
- Server logs, metrics, and traces. These are minimized and exclude query strings.
Information we receive from providers
- Billing records from Dodo: customer, subscription, transaction, refund, dispute, currency, tax, and invoice references and their status. We do not receive or store full payment card details.
- A country signal from Cloudflare, used to apply the geographic availability described in section 2.
Information about people who do not hold accounts
- When someone opens a share link, we add the rendered recipient page to a daily aggregate for the publisher and share. The aggregate contains no recipient identifier, IP address, User-Agent string, referrer, filename, folder name, or share address. Separate short-lived delivery and security records may include IP address, User-Agent string, and request identifiers. When someone views a controlled embed, the account owner's usage record receives only daily aggregate counts, bytes, cache/range totals, and the normalized publisher hostname; it does not receive the visitor's IP address, User-Agent string, or full page URL. Infrastructure security logs remain subject to the separate short retention periods below.
- When someone sends a copyright notice, counter-notice, or abuse report, we keep the notice, the contact details it contains, and our handling record. A copyright notice or counter-notice may be forwarded to the other party where United States copyright law requires it.
- A waitlist entry includes an IP address, recorded to prevent abuse of the queue.
4. Why we use information
We use personal information to:
- create and operate accounts, store files, and deliver downloads and share links;
- scan uploads for malware and quarantine harmful content;
- process purchases, renewals, refunds, and disputes;
- enforce plan allowances, file-activity rules, and geographic availability;
- send transactional messages such as address verification, password reset, retention warnings, failed-payment notices, and policy notices;
- secure the service and detect, investigate, and prevent fraud, abuse, and unauthorized access;
- handle copyright notices, abuse reports, legal requests, and preservation obligations;
- keep financial, tax, and audit records;
- maintain and troubleshoot the service using minimized logs, metrics, and traces;
- measure how the service is used, in aggregate, without cookies or a persistent identifier, as described in section 6; and
- comply with law.
We do not use your files for advertising, and we do not use them to train machine-learning models. We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are used in United States state privacy laws.
5. Files, scanning, and staff access
File bytes are stored with our object-storage provider and delivered from a separate content origin that sets no cookies. Uploads are streamed through a malware scanner before ordinary download is permitted; scanning does not write a separate copy of your file to disk. Scanning reduces risk and does not guarantee that a file is safe.
We do not routinely access the contents of your files. Staff access to file content requires prior authorization, is limited to a stated purpose, scope, and duration, and is recorded in an audit log. We may preserve specified files when a legal or security obligation requires it.
6. Cookies and local storage
We use only cookies that are necessary to operate the service. We do not use advertising, cross-site tracking, or analytics cookies. Our product analytics sets no cookie at all.
- Session cookie: keeps you signed in. Expires 30 days after sign-in, or after 14 days without use.
- Security token cookie: protects forms against cross-site request forgery. Expires after 12 hours.
- Share unlock cookie: records that a share password was entered correctly. Expires after 2 hours.
- Administrative re-authentication cookie: confirms a recent sign-in before sensitive administrative actions. Expires after 30 minutes.
Your browser also stores a color-theme preference locally under the key wedofiles-theme. That preference is not sent to us.
Product analytics without cookies
We measure how pages are used so we can improve the service. Page visits are counted on our servers. We also load a small analytics script in your browser to record which links and buttons are clicked and which forms are submitted. Neither sets a cookie, and nothing is written to your browser's storage. We do not record your screen, and we do not use session replay or heatmaps.
To count a visit without identifying you, we compute a one-way code from your IP address, your browser's User-Agent string, and the site you are on, using a secret that changes every day. We do not store your IP address or your User-Agent string against the code, the code cannot be reversed to recover them, and because the secret changes daily the same browser produces an unrelated code the next day. We therefore cannot use it to recognize you over time or across any other site. When you are signed in, the measurement is recorded against your account instead, and we never link a signed-out code to an account.
We record the page path, the site, the referring site, the browser's User-Agent string, and the identity of the elements you click or submit. We do not record query strings, so tokens sent in a link are never included, and we do not record what you type into a form. Our analytics provider is not given your IP address unless we enable country lookup, which is off by default.
Because we do not track users across sites and do not sell or share personal information, browser "Do Not Track" signals are not required to change how the service behaves. We honor them anyway: if your browser sends Do Not Track, we record no product analytics for that request and the analytics script is not loaded into the page at all.
Global Privacy Control is a request to opt out of the sale or sharing of personal information. We do neither, and our analytics provider may not sell or share the information it receives from us, so there is nothing for the signal to switch off. It does not stop the first-party product analytics described above. If we ever sell or share personal information, we will honor Global Privacy Control as an opt-out of that activity.
Controlled-embed measurements are first-party service and billing records, not the product analytics described above. The embedded player does not load the PostHog script, set a cookie, write browser storage, or create a persistent recipient identifier. We aggregate authorized player views, media requests, bytes, cache outcomes, range-request counts, file identifiers, and normalized publisher hostnames by day so the account owner can understand delivery and we can enforce transfer allowances.
Public-share exposure measurements are also first-party aggregate records rather than product analytics. We aggregate successfully rendered recipient pages and completed downloads by publisher, share, and UTC day. A download counts as completed when our content origin first delivers file content for it; later requests for the same download are not counted again. Visits and downloads by the share's owner are not counted. We also record whether an active paid publisher had a usable public share on a day, including days with no recipient activity. These records contain no recipient identifier or request metadata. Because they identify no visitor, they are kept even when a browser sends Do Not Track.
Product analytics connected to shares, sign-up, and billing
When product analytics is recorded for a visit, as described above, it also includes these events:
- a public share page was viewed, with only whether it holds a file or a folder and whether it is password protected;
- a download through a public share first delivered file content. This is recorded against the same daily code as the visit that requested the download, which is carried inside the download link for that purpose. It is not recorded when the visit was not measured, and it is not recorded for the share's owner;
- the sign-up button on a public share page was clicked, with only the destination page;
- a registration was attempted or completed, with the plan chosen, the outcome (account created, awaiting payment, or waitlisted), and the category of how you first reached us.
These events contain no file name, folder name, share address, email address, or anything you typed.
Some events about an account are recorded against the account itself rather than a daily code, including when no one is signed in at that moment:
- when a checkout starts, and when a paid subscription first becomes active, with the plan and the category of how the account first reached us; and
- for each day on which an account on a paid plan has a usable public share, a daily summary containing the date, the plan, the number of usable public shares, and the total recipient-page views and completed downloads across them. It contains no share identifier and nothing about the recipients.
We do not link these account events to the daily code of any earlier signed-out visit.
7. Service providers
We use the following providers, each for a defined purpose:
- Cloudflare, Inc., 101 Townsend Street, San Francisco, California, United States: content delivery, edge security, the country signal, and object storage for your files in western North America and the Asia-Pacific region. Cloudflare's handling is described in its privacy policy and its customer data processing addendum. Cloudflare documents a retention window of three to seven days for HTTP request logs where log retention is enabled, described in its log retention documentation.
- Vultr: managed PostgreSQL database hosting in California, United States. Database contents and backups are encrypted at rest, and connections are encrypted in transit.
- Railsware Products Studio LLC, trading as Mailtrap: delivery of transactional email only, never marketing email. Its handling is described in its privacy policy and data processing addendum. Sending logs, which include the recipient address and message metadata, are retained for 3 days.
- Grafana Labs, for Grafana Cloud: server logs, metrics, and traces, retained for 14 days. Its handling is described in its privacy policy.
- PostHog, Inc., 2261 Market Street, San Francisco, California, United States: product analytics, as described in section 6. It receives the daily code or, for the account events described there, the account identifier, together with the page path, the referring site, the User-Agent string, and the event details listed in section 6. It is not given your IP address. Its handling is described in its privacy policy and data processing agreement.
Dodo Payments Inc, 8 The Green, STE A, Dover, County of Kent, Delaware 19901, United States, acts as merchant of record for purchases. Dodo is therefore the seller of record and handles payment processing, tax, and invoicing. Dodo decides its own purposes for the payment information it collects and does not act only on our instructions, so its handling is governed by its own privacy policy rather than by this one. Dodo states that it retains personal information for the duration of the relationship, for any applicable limitation period, and for two months after that period ends.
8. Where information is processed
Your account, sharing, and billing records are held in our database in California, United States. File bytes are stored in object storage in western North America and the Asia-Pacific region, so a file you upload may be stored outside the United States. Our content delivery, email, and observability providers may process personal information in further countries in the course of delivering those functions. Where a provider transfers personal information across a border, that transfer is governed by the provider's own data processing terms, which include standard contractual clauses where they apply.
9. When we disclose information
We disclose personal information:
- to the providers named in section 7, for the purposes stated there;
- to a person you direct, when you create or send a share link;
- to a copyright claimant or a counter-notifying party, where United States copyright law requires it;
- to law enforcement, a regulator, or a court, where law requires it or valid legal process compels it;
- where necessary and in good faith to investigate suspected fraud, abuse, or a security incident, or to protect the rights or safety of a person; and
- to a successor, if the service is transferred, subject to notice and equivalent protection.
10. How long we keep information
We keep account information for as long as the account is open, and then apply the deletion described in section 11. File lifetimes, including Free-account inactivity, the downgrade grace period, and soft deletion before permanent purge, are governed by the Terms of Service and are not restated here.
Other records are kept as follows:
- Session records: 30 days from sign-in at most, or 14 days without use. The record is removed 30 days after it expires or is revoked.
- Address verification, password reset, and email change links: 1 hour.
- Incomplete uploads: 24 hours.
- Waitlist invitations: 72 hours. A waitlist entry is kept until an account is created or the entry is removed on request.
- Usage report identifiers used to reject duplicate reports: 7 days.
- Download-grant hashes used to count each public-share download once: 8 days.
- How you first reached us: for as long as the account is open. It is deleted with the account. A waitlist entry's category is deleted with the entry or copied to the account created from it.
- Controlled-embed daily aggregate usage: 25 months, or until the account or associated file is deleted, unless a legal preservation obligation applies.
- Public-share daily aggregate exposure and paid-publisher eligibility: 25 months, or until the account or associated share is deleted, unless a legal preservation obligation applies.
- Rate-limit counters: held in memory only and discarded when the counting window ends. They are not written to storage.
- Server logs, metrics, and traces: 14 days.
- Transactional email sending logs: 3 days.
- Database backups: 2 days.
- Moderation records, including copyright strikes: for the life of the account, because the Terms of Service count strikes over the lifetime of an account.
- Billing, tax, refund, dispute, and audit records: 7 years.
Deleted data may remain in encrypted backups until the backup window above passes. Backups are not selectively edited, and data restored from a backup is subject to the same deletion rules. Where we must continue to recognize a blocked address after deletion, we keep only a hashed or otherwise pseudonymous value.
11. Your choices and rights
When you are signed in, you can export your data or request deletion of your account from the account page. The export includes the category of how you first reached us and your public-share daily views, completed downloads, and paid-publisher eligibility records. We confirm the request from your signed-in account or by a one-time link sent to the account email address. You may also write to [email protected].
Deletion removes your files that are not under a preservation hold, your share links, public-share exposure and eligibility aggregates, the category of how you first reached us, controlled embeds, saved embed domains, embed usage, folders, incomplete uploads, sessions, sign-in tokens, other usage records, and any waitlist entry, and replaces the identifying values on the remaining account record with pseudonymous ones. We keep the billing, tax, policy-acceptance, moderation, dispute, and audit records described in section 10, which are retained for legal and security reasons and can no longer be linked to you by email address.
Depending on where you live, you may have the right to know what personal information we hold, to receive a copy of it, to correct it, to delete it, and to be free from discrimination for exercising these rights. We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising, so there is nothing to opt out of in those categories. An authorized agent may make a request for you where state law provides for it, if we can verify your written permission.
We respond within 45 days. If we need more time, we tell you within that period and may take up to 45 additional days. If we deny a request, you may appeal by replying to our decision within 30 days, and we will tell you the outcome and how to contact your state attorney general or another applicable regulator.
12. Children
WeDoFiles is not offered to anyone under 18, consistent with the capacity required by the Terms of Service. We do not knowingly collect personal information from a child. If we learn that we have, we delete the account and its data. Write to [email protected] to report an account held by a child.
13. Security
We use technical and organizational controls including password hashing, session protection and expiry, re-authentication before sensitive actions, role-based access control, malware scanning, isolated content delivery, rate limiting, audit records, encryption of provider connections, and encryption of stored data and backups at rest. No system is completely secure.
If a security incident affecting your personal information occurs, we notify affected users by email once the incident has been contained, and we notify regulators where law requires. Report a suspected security issue to [email protected].
14. Automated processing
Some controls run automatically and can restrict access without prior human review: malware scanning and quarantine, rate limiting, fraud and abuse controls, the geographic block described in section 2, and the conversion of an account to the Free plan after a failed payment or an opened chargeback as described in the Terms of Service. A person decides whether to terminate an account, whether an account is a repeat infringer, and whether to approve a refund. You may ask for human review of an automated restriction by writing to [email protected].
15. Changes to this notice
We keep prior versions and provide them on request. Where a change materially affects how we handle personal information, we give notice by email or in the application before it takes effect, and obtain consent where law requires it. The version and effective date shown on this page identify the notice that applies.
16. Contact
Write to [email protected], or to 30 N Gould St Ste N, Sheridan, Wyoming 82801, United States, about this Privacy Policy or about a privacy request.