Skip to content

Draft — not legal advice. This document was drafted from the product’s operating decisions and has not been reviewed by a lawyer. It must be reviewed and, where required, localised before launch or before submission to a payment provider.

Privacy Policy

Last updated 7 August 2026

This policy explains what TransferMyCloud collects, where your data goes while a transfer runs, and how long anything is kept.

1. What we collect

  • Account data — email address, display name, password hash, and the timestamps of sign-up and verification.
  • Transfer metadata — source and destination, file names and sizes, byte counts, timings, and the outcome of each job.
  • Destination credentials — the keys or OAuth refresh tokens you supply, encrypted at rest.
  • Billing records — credit balance and an append-only ledger of every change. Card details are handled by our payment provider and never reach our servers.
  • Operational logs — IP address, user agent and request timing, used for abuse prevention and debugging.

2. Where your files go during a transfer

This is the part most worth reading. A transfer is performed server-side, which means your file passes through infrastructure we operate and, depending on the source, infrastructure operated by others.

Sub-processors

  • Baidu (Pan Baidu) — used in two ways. When you import from a Baidu share link, the file is read from, and may be temporarily saved into, a Baidu account we control. Separately, we may hold your My Cloud files in a Baidu account we control as your account’s storage. Which storage your account uses is our operational decision, not a setting you choose, and you cannot opt out of it while keeping the account.
    Either way, that data is processed on infrastructure located in China and is subject to Baidu’s own terms and to Chinese law. If that is unacceptable for your content, do not store it here.
  • Object storage provider — holds My Cloud files, paid storage and transfer staging. Named on request; we change providers without changing this policy.
  • Oracle Cloud — the servers that run the API and transfer workers.
  • Your chosen destination — Google Drive, your own S3 or R2 bucket, Cloudinary. Once delivered, the file is governed by that provider’s policy, not ours.
  • Resend — transactional email (verification, job results, expiry warnings).

3. How long we keep things

  • Files on the free tier — deleted 7 to 30 days after upload.
  • Files on paid plans — for the life of the subscription, plus a 30-day read-only grace period.
  • Transfer staging copies — removed within 72 hours by a storage lifecycle rule, and on job completion by a cleanup task.
  • Share passwords — discarded once the job reaches a final state.
  • Ledger records — retained as long as required for accounting and tax purposes.
  • Operational logs — rotated on a short schedule.

4. Security

Third-party credentials are encrypted with AES-256-GCM before storage. Outbound requests made on your behalf are restricted so that a supplied URL cannot be used to reach internal systems. Download links are short-lived and issued per request rather than being permanent.

No system is perfectly secure. If you discover a vulnerability, please report it to [email protected].

5. What we do not do

  • We do not sell personal data.
  • We do not use your file contents to train models.
  • We do not make your files publicly discoverable or indexable.
  • We do not run third-party advertising trackers on the product.

6. Your choices

You can download or delete your files at any time, disconnect a destination, and delete your account from the profile page. Account deletion removes files after a 30-day grace period. Depending on where you live you may have additional rights of access, correction, export or erasure; write to [email protected] to exercise them.

7. Children

The service is not directed to children and accounts may not be created by anyone under the age required by their local law to consent to data processing.

8. Changes

Changes to this policy are announced in the product before taking effect. Adding a sub-processor that changes where files are processed will always be announced.

Privacy Policy · TransferMyCloud