home / privacy
Privacy Policy
Effective October 3, 2026
StreamFS ("StreamFS", "we", "us") provides software that streams your cloud object storage as a local filesystem. This policy explains what we collect, why, and the choices you have. We designed StreamFS to hold as little of your data as possible — most notably, we never have access to your storage credentials or the contents of your files.
information we collect
- Waitlist. If you join the waitlist, we collect your email address so we can send a confirmation and, later, an invitation.
- Account. When you register, we collect a username and email address. Your password is stored only as a salted one-way hash (Argon2id) — we never store it in plain text. We also store a public encryption key your client generates.
- Workspaces & sessions. We store the organizations, workspaces, and membership you create, plus session records (such as the device name and workspace of an active mount, and timestamps) so you can see and manage where you're signed in.
- Billing. If you purchase managed storage, payments are handled by our third-party payment processor. We receive confirmation and billing metadata but do not store full payment-card numbers.
- Technical & security data. Our infrastructure and security providers process standard request data (such as IP address and request metadata) to serve the site and protect it from abuse.
your storage credentials & files (zero-knowledge)
Your object-storage credentials are encrypted on your own device with a key that only you and the people you share a workspace with control. They are stored only in encrypted form, and the StreamFS server never receives or can decrypt them. File contents stream directly between your device and your storage provider — we do not store, copy, or inspect your files.
how we use information
- To provide, operate, and secure the service and authenticate you.
- To send transactional email — waitlist confirmations, invitations, and account or security notices.
- To process billing for paid plans and managed storage.
- To detect, prevent, and respond to fraud, abuse, and security incidents.
We do not sell your personal information, we do not use it for advertising, and we do not use third-party tracking or analytics cookies.
cookies
StreamFS uses only strictly-necessary cookies:
- Authentication. After you sign in we set a secure,
HttpOnlysession cookie (token) so the app knows you're logged in. It is not used for tracking, and the signed-in app cannot function without it. - Security. Our content-delivery and security providers may set essential cookies to keep the site available and to distinguish humans from automated abuse.
Because we use only essential cookies, we do not show a cookie-consent banner. You can block or delete cookies in your browser settings, but the signed-in app will not work without the authentication cookie. If we ever add analytics or non-essential cookies, we will update this policy and ask for consent where required.
service providers
We share limited data with vendors who process it only to provide their part of the service: an email-delivery provider (to send our emails), a payment processor (to handle paid plans), and cloud infrastructure, storage, and security providers (to host and protect the service). They are bound to use the data only as needed to perform these functions.
data retention
We keep waitlist emails until you ask to be removed or until they are no longer needed. We keep account and workspace data for as long as your account is active. When you delete your account, or ask us to delete your data, we remove it within a reasonable period, except where we must retain limited records to meet legal, tax, or security obligations.
security
We protect data in transit with TLS and at rest with encryption. Passwords are hashed with Argon2id, and your storage credentials are held under zero-knowledge encryption we cannot reverse. No system is perfectly secure, but we work to protect your information and to limit what we hold in the first place.
your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. If you are in the EEA or UK (GDPR) or California (CCPA/CPRA), those rights apply to you; we do not sell or "share" personal information as those laws define it. To exercise any right, email us at [email protected] and we will respond as required by law.
international transfers
We and our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards for such transfers.
children
StreamFS is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
changes
We may update this policy as the service evolves. We will revise the effective date above and, for material changes, provide a more prominent notice.
contact
Questions about this policy or your data? Email [email protected].