Privacy Policy
1. Data we collect
- Account data: your chosen username and a bcrypt hash of your password. If you enable two-factor authentication, we store a TOTP secret.
- Cloud credentials you choose to store: for connectors you set to “store with CloudRoam,” we hold your access keys or OAuth refresh tokens encrypted with AES-256-GCM. For connectors you set to “browser only,” these never reach our servers.
- Operational logs: an audit log of actions (e.g. sign-in, file list, upload) including timestamp, IP address, and user agent, used for security and troubleshooting.
- File contents: we do not copy or retain the contents of your files. Data passes through the service transiently to complete transfers you request and is not stored by us.
2. How we use data
We use your data to operate the service, authenticate you, execute the cloud operations you request, maintain security, and comply with law. We do not sell your personal data or use it for advertising.
3. Encryption & security
Stored credentials are encrypted at rest with AES-256-GCM under a master key held as a platform secret, not in our database. Traffic is encrypted in transit with TLS. Passwords are hashed with bcrypt. Two-factor authentication is required before credentials may be stored on our servers. No system is perfectly secure; see our Terms.
4. Third parties
We rely on infrastructure providers to host the service. When you connect a cloud account, your use of that provider (Amazon, Microsoft, Dropbox, etc.) is governed by their own terms and privacy policies. We access those accounts only to perform actions you initiate.
5. Data retention & deletion
We retain account data and stored credentials until you delete the connector or your account. Deleting a connector removes its stored credentials from our systems. You may request deletion of your account and associated data at any time.
6. Your choices
- Choose per connector whether credentials are stored by us or kept only in your browser.
- Enable or disable two-factor authentication (required for server-stored credentials).
- Delete connectors or your account.
7. Cookies and consent
On your first visit we show a consent banner with equal Accept all, Reject all, and Customize options. No non-essential cookies load until you make a choice, and rejecting is exactly as easy as accepting. We group cookies into four categories:
- Strictly necessary — sign-in, security, and remembering your consent. These cannot be turned off.
- Functional — remember preferences such as language and layout.
- Analytics — anonymous, aggregated usage that helps us improve the product. We do not sell data.
- Marketing — measure the effectiveness of our messaging. Off by default and never required.
Your choice is stored in your browser per category and expires after 180 days, after which we ask again. You can change or withdraw consent at any time using the Cookie settings link in the footer. We use no third-party consent or tracking scripts, so nothing runs before you opt in.
8. Your GDPR rights & international transfers
The service is operated from the European Union (Cyprus). If you are in the EU/EEA, you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing; you may also lodge a complaint with your local supervisory authority (in Cyprus, the Office of the Commissioner for Personal Data Protection). Where data is transferred outside the EEA (for example, to the cloud providers you connect), such transfers rely on appropriate safeguards. To exercise any right, use the contact address on our website.
9. Children
The service is not directed to children under 13, and we do not knowingly collect their data.
10. Changes & contact
We may update this policy; changes are posted here with a new date. For privacy questions, use the contact address on our website.