Privacy Policy
Last updated: September 18, 2026
This policy explains what file2fix collects, why, and how you can control it. It is practical product information, not legal advice; the site operator should have it reviewed before relying on it for a live business.
What we collect
- Account info — your email address, a hashed password for password accounts, and optional display information returned by a social provider. We never receive your Google, Microsoft, or GitHub password.
- Social sign-in identifiers — when you use Google, Microsoft, or GitHub login, we store the provider name and provider account ID so the account can be recognized again. We use a verified email address to create or link an account.
- Points balance and history — how many points you have bought or spent and which tools were charged, so your dashboard and purchase records are accurate.
- Payment information — handled by Stripe. File2fix does not receive or store your card number; it receives payment-session and package details needed to credit your account and keep accounting records.
- Uploaded files and pasted data — processed to produce the result you requested. Do not upload passwords, private keys, payment data, or personal information unless the selected workflow requires it.
- Operational logs — limited tool, time, account, and request-IP information used for abuse prevention, billing support, and the private dashboard activity list. Logs are rotated rather than kept indefinitely.
How long we keep files and results
Most tools process an upload in memory or in a private temporary directory and remove the working copy after the request. Tools that create a downloadable server-side result copy it into private storage for the result link, normally for one hour and never longer than one day. The result URL is an unguessable bearer link: anyone who receives it may download the file until it expires, so review the contents before sharing it.
The explicit “Shareable Fix Links” workflow keeps its uploaded file for 24 hours and serves it as a forced download. Expired result and share metadata is removed opportunistically; an operator should also schedule storage cleanup in production.
Websites, URLs, and external services
URL audit tools make bounded requests to public HTTP(S) destinations. Private and local network destinations are blocked, but you should still submit only URLs you are authorized to check. Stripe handles checkout. Optional Google, Microsoft, and GitHub login contacts the selected provider. If Google AdSense is enabled, Google may use its own cookies or similar technologies under its policies; the site owner should configure consent and disclosures appropriate to the audience and jurisdiction.
What we don't do
- We do not sell your data.
- We do not use uploaded file contents for model training, advertising profiles, or purposes other than the selected workflow.
- We do not silently replace your original file or modify a live server from a public tool.
Cookies and local storage
File2fix uses a session cookie for security and sign-in. Some browser-only tools use local storage for favorites, recent tools, or dark-mode preference; that data stays on your device. Optional third-party advertising, payment, or provider pages may set their own cookies under their policies.
Your rights
You can ask us to access or delete your account and associated data by emailing [email protected]. Purchase and fraud-prevention records may be retained as required for tax, accounting, security, or dispute handling. Deleting a result from its tool page does not undo a copy someone already downloaded.
Changes to this policy
If this policy changes materially, we will update the date at the top of this page.
Contact
Questions about this policy: [email protected]