Privacy Policy

This translation is provided for convenience. The English version is the authoritative text.

Last updated: August 26, 2026

This Privacy Policy explains how uploadthefile.com (“we,” “us”) collects, uses, and shares information when you use our websites and services (the “Service”). The Service is operated by uploadthefile.com.

We are the data controller for the data described in Part A below (“Data we are responsible for”). For the files and content you upload (“Your Content”) and the personal data inside them, we act as a processor on your instructions, as described in Part B and in our Data Processing Terms.

1. Information we collect

Part A: Data we are responsible for (controller)

Account & sign-in. When you create an account we collect your email address. If you sign in with a third-party provider (such as Google, GitHub, or Microsoft), we receive your email address and basic profile information from that provider so we can create and secure your account. We do not receive your password from these providers.

Usage & device data. We collect technical information such as IP address, browser/device type, and basic analytics about how links and pages are accessed (for example, click counts), to operate, secure, and improve the Service. IP addresses are stored only in hashed form.

Payment. If you purchase a paid plan, our payment processor handles your payment details. We do not store full card numbers; we receive limited information such as subscription status and the last digits or brand of your payment method.

Support & abuse. When you contact support, or when you submit or are named in an abuse report, we process the information provided and the related records to respond, investigate, and keep the Service safe.

Connector activity. If you connect an AI agent or other application to your account (for example over our MCP or A2A endpoints), we record which registered application made each request, the operation performed, whether it succeeded, and the date, and we label content published this way with the channel it came from. When you approve a connection on our consent screen, we also record how you arrived at that screen as a broad category only: from a page on our own site, from an external site, or directly. We never record the address of an external page. We retain these activity records for 13 months and completed agent task records for 90 days; both are included in your data export. We do not receive or store your conversations with your AI assistant. We only receive and record what the connected application sends to our API.

Part B: Content we process for you (processor)

We also process the files and content you upload (“Your Content”), including any personal data contained within them; the metadata needed to serve them (such as file name, size, type, and the links or subdomains you create); and the visitor email addresses captured through the email-gate feature when you configure it on a link or page you publish. We handle this content as your processor, on your instructions, as set out in our Data Processing Terms.

2. How we use information

We process personal data where we have a lawful basis to do so, to perform our agreement with you, with your consent, to comply with a legal obligation, or for our legitimate interests in operating and securing the Service. We use information:

  • To provide, maintain, and improve the Service;
  • To create and secure your account and authenticate sign-ins;
  • To detect, prevent, and respond to abuse, malware, fraud, and security issues;
  • To process payments and manage subscriptions;
  • To communicate with you about your account, security, and service changes; and
  • To comply with legal obligations.

Hosting and delivering Your Content and the links you create is something we do as your processor, on your instructions, rather than for our own purposes. See Part B above and our Data Processing Terms.

3. Sign-in providers

We offer sign-in with Google, GitHub, and Microsoft. When you choose one, you authenticate with that provider and they share a limited set of information with us (your email and basic profile). Their handling of your information is governed by their own privacy policies.

4. Automated processing & AI features

Some features process your content automatically. In particular, our “chat with your PDF” feature uses an automated model running on Cloudflare Workers AI to read and answer questions about a document, and only runs when the content owner enables it for that document, or when our support team enables it for a specific document in response to a request or review; when it does, the content of that document is processed to generate responses. We do not use your uploaded content to train third-party models, and we do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. You can object to automated processing of your personal data, or ask for a person to review a matter, by contacting us at contact@uploadthefile.com.

5. Cookies

We use strictly necessary cookies to keep you signed in and to secure the Service. These are always on because the Service cannot function without them; they are set as HttpOnly and Secure where applicable, and we do not use them to track you across unrelated websites.

We also use analytics cookies (Google Analytics) to understand how the Service is used. These are set only if you accept them through our cookie banner, and you can decline. Declining analytics cookies does not affect your access to the Service.

Separately, our marketing pages use a cookieless analytics tool (Ahrefs Web Analytics) to count visits. It sets no cookies and stores nothing on your device, so it is not covered by the cookie banner and there is nothing to accept or decline. It records the page visited, the referring site, your browser type and language, and an approximate location; your IP address is used only in transit to derive a daily, non-reversible count and is discarded rather than stored. It does not identify you and does not track you across other websites. We rely on our legitimate interest in understanding how our pages perform. It does not run on pages published by our users.

6. How we share information

We do not sell your personal information. We share it only:

  • with service providers who process data on our behalf, under appropriate confidentiality and data-protection terms: Supabase (hosting data and content storage), Cloudflare (hosting, content delivery, and AI inference), Polar (payment processing), Resend (transactional email), and our sign-in providers (Google, GitHub, Microsoft);
  • with Google Analytics, only if you consent to analytics cookies (see Section 5);
  • with Ahrefs, which provides the cookieless analytics on our marketing pages described in Section 5;
  • with safety services that receive limited data to prevent abuse: Google Safe Browsing (URLs), urlscan.io (URLs), and VirusTotal (file hashes);
  • with internal operations alerting tools that receive minimal event notifications (such as an account identifier and event type) to run the service securely;
  • to enforce our terms, investigate abuse, or protect the rights, safety, and security of our users and the public (including reporting unlawful material to the appropriate authorities);
  • to comply with applicable law or a valid legal or regulatory order; and
  • in connection with a merger, acquisition, or sale of assets, subject to this policy.

7. International data transfers

We are established in the United Arab Emirates, and our service providers process personal data in other countries: in the United States (Polar, Resend, Google, VirusTotal, and Ahrefs), in the European Union (urlscan.io), and globally at the network edge (Cloudflare). Ahrefs stores its data in the United States, but the entity we contract with, Ahrefs Pte. Ltd., is established in Singapore. Supabase processes data in the region configured for our deployment. Where personal data is transferred out of the UAE or out of your country, we rely on a lawful transfer basis, your consent, the necessity of providing the Service you requested, or appropriate contractual safeguards with the recipient.

8. Security

We use technical and organizational measures to protect your information, including encryption in transit (HTTPS) and HttpOnly, Secure session cookies. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal-data breach affects your rights, we will act without undue delay and notify you and the competent authority where the law requires it.

Who can reach your content. Access to a hosted page is controlled by its link. Links are randomly generated, pages carry instructions asking search engines not to index them, and we do not publish a directory of hosted content. Even so, anyone who has a link can open it, and a custom name you choose yourself is readable by design, so treat it as guessable. You can put a password in front of a link, delete a page at any time, and let links expire.

We are not a zero-knowledge service. Your Content is not end-to-end encrypted. We hold it in a form we can read, which is what allows us to serve it, to detect and respond to abuse, malware, and illegal material as described in section 2, and to act on reports and lawful orders as described in our Terms. Access by our personnel is limited to what is needed to operate the Service, is subject to confidentiality obligations, and administrative actions are logged. See our Data Processing Terms. If you need content that we cannot read, encrypt it yourself before uploading.

9. Data retention

We retain account information for as long as your account is active and as needed to provide the Service. Content you upload is retained until it expires, you delete it, or you close your account; expired or deleted content is removed from active systems by automated cleanup. Uploads that are still in flight are purged on short timers if they do not complete. Residual copies in backups are purged in the ordinary course. We may retain limited information as required for legal, security, or accounting purposes.

When content is removed because it expired, was taken down by us for a policy or legal violation, or was cleared following a plan change, we may keep a copy of the file and limited related metadata in a separate, access-restricted archive for a bounded period after removal (by default, and depending on the reason for removal, up to approximately 90 days; the exact window is configurable by us and may be shorter) so it can be restored on request, for example to recover a file after an expired link or a mistaken takedown. We do not create this kind of recovery copy when you delete content yourself or delete your account. Separately, where content is flagged or confirmed as involving a serious legal violation (such as child sexual abuse material), we are required by UAE law to preserve it, regardless of any deletion request, for as long as needed to meet our evidence-preservation and mandatory-reporting obligations; such preserved copies are kept apart from the live Service, are never restored or re-published, and are accessed only through a limited, logged internal process.

10. Your rights & choices

Subject to applicable law (including the UAE Personal Data Protection Law), you may have rights to access, correct, export, delete, or restrict the processing of your personal data, to object to certain processing (including automated processing), and to withdraw consent. Withdrawing consent is as easy as giving it and does not affect processing already carried out. You can delete your content at any time, and delete your account from your account settings, or contact us to exercise your rights at contact@uploadthefile.com.

If your personal data appears in content that someone else uploaded, you can report it through our reporting page or by emailing contact@uploadthefile.com. Where the uploader is the controller of that data, we will forward your request to them and assist as their processor; we act ourselves where the law requires us to (for example, to remove illegal content).

11. Children’s privacy

The Service is not directed to children. We do not knowingly collect personal data from children under 13 (or the minimum age of digital consent in your country) without verified parental or guardian consent, and we do not profile children or serve them targeted advertising. If you believe a child has provided us information, contact us and we will take appropriate steps, including deletion where required.

12. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice.

13. Contact

uploadthefile.com is responsible for your personal data. Questions about your privacy or this policy? Email contact@uploadthefile.com.