Privacy Policy

Effective Date: April 2026

At fpod, we build for digital minimalists. Our core philosophy is that your text is yours alone. We have designed our system architecture to protect your data with strict cryptographic boundaries.

1. Server-Side Envelope Encryption

To maintain seamless compatibility with standard WebDAV and S3 clients, your notes and files undergo server-side envelope encryption (XChaCha20-Poly1305) before being written to disk. Encryption and decryption happen dynamically at the server edge. This protects your data against physical storage inspection, hosting-provider leaks, and unauthorized database access: the encrypted bytes on disk are not readable without the server's keys. Because these keys are held server-side, this layer is not a substitute for client-side encryption.

Note: /fvault provides client-side encryption for files that need a stronger local encryption boundary.

2. Minimal Data Collection & Metadata

We collect and manage only the data required to operate the service:

  • Email Address: Used solely for account authentication, subscription management, and critical service notifications.
  • Payment Information: Processed securely by our payment provider (Creem). We do not store or process your full credit card details.
  • Usage Metrics: We track aggregate storage usage (against the fixed 32MB quota) to enforce limits and ensure service stability.
  • File Metadata: To support standard WebDAV protocols and incremental synchronization, file metadata (such as directory structures, filenames, and modification times) is stored in your private, isolated database.

Tip: For the strongest privacy of both file content and filenames, use the root /fvault directory. Its filenames are client-side encrypted and their paths are automatically masked as ***** in all sync logs.

3. How We Use Information

Your information is used strictly to provide and maintain the fpod service. We do not sell, rent, or share your personal data with third parties for marketing purposes.

4. Cookies and Sessions

We use minimal, strictly necessary JSON Web Tokens (JWT) and local storage mechanisms to keep you securely logged in. No tracking, analytics, or advertising cookies are used on the dashboard.

5. Data Retention & Deletion

When you delete a file, it is moved to the Trash and permanently purged after 30 days. If you choose to delete your account, all associated data, files, and encryption keys are destroyed immediately and irretrievably. Due to our strict encryption boundaries, we cannot recover deleted data.