What this policy covers
This covers everything on filexl.com, including file transfers, your account if you have one, and the peer-to-peer tool.
This policy applies to FileXL and every service we operate at https://www.filexl.com, including hosted file transfers, the Dropzone collection pages, the peer-to-peer transfer tool, and any account you create with us.
It explains what information we handle, why, and what control you have. Where this policy uses "you", it means anyone using FileXL — whether you upload a file, download one someone sent you, or simply browse the site.
Using FileXL also means agreeing to our Terms of Service, which sit alongside this policy.
Who can access your files
Your files are not public and never appear in any list or search. Only someone with your download link can open one. Guard the link the way you would guard a key.
This is the part most people care about, so we will be direct about it.
Your files are not public
FileXL publishes no directory of transfers. There is no browse page, no search index, and no way to enumerate what other people have uploaded. Every transfer is reachable only through a download link containing a randomly generated identifier. Nobody can guess their way to your file, and search engines are instructed not to crawl download URLs.
The link is the key
Anyone holding the download link can download the file. That is what makes sharing simple, and it is also the boundary of the protection. If you forward the link to five people, all five can download it. If a link is posted somewhere public, the file becomes reachable by anyone who finds it.
Send download links through a channel you trust, and set a password on the transfer when the contents are sensitive. A password means the link alone is not enough. You can also enable self-destruct, which permanently deletes the file after its first download.
What FileXL itself can see
We think you deserve an honest answer rather than a marketing one.
We do not routinely open, read, scan for content, or analyse the files you upload. We do not use them to build advertising profiles, and we do not use them to train machine learning models.
However, hosted files are encrypted with keys we control, so we cannot honestly claim it is technically impossible for us to access them. Staff access is restricted to a small number of authorised people, is logged, and is permitted only when one of the following applies:
- We receive a valid legal order or a lawful request from a competent authority.
- We are investigating a specific report of abuse, malware, or a copyright complaint against a particular transfer.
- You ask us for support that cannot be provided without it, and you consent at the time.
Automated systems may inspect files for malware signatures and for content that is illegal under applicable law. These checks are automated and are not used for advertising or profiling.
If you need a stronger guarantee
Two options give you protection we cannot undo:
- Password-protect the transfer. The file cannot be downloaded without the password, which we never display and never send on your behalf.
- Use peer-to-peer transfer. The file travels directly from your browser to the recipient's over an encrypted channel and is never written to our servers. There is nothing on our side to access, disclose, or hand over — because no copy exists.
What we collect
Without an account, we hold almost nothing about you personally. With one, we hold your email and basic account details.
| Category | What it includes | When |
|---|---|---|
| File content | The files you upload and their filenames | Only when you upload. Never for peer-to-peer. |
| Transfer metadata | File size, type, upload time, expiry date, download count | Every hosted transfer |
| Account details | Email address, hashed password, plan, preferences | Only if you register |
| Recipient details | Email addresses you enter to send a transfer | Only when you use email delivery |
| Technical data | IP address, browser type, operating system, referring page | Automatically, in server logs |
| Usage data | Pages viewed, features used, error events | Automatically, in aggregate |
| Payment data | Handled entirely by our payment processor | Only for paid plans. We never store card numbers. |
If you use FileXL without creating an account, we do not hold your name, your email address, or a password — because you never gave us one.
How we use it
To run the service, keep it secure, and improve it. Not to profile you.
- Delivering the service — storing your file until it expires, generating the download link, and delivering it to whoever you shared it with.
- Security and abuse prevention — detecting malware, rate-limiting automated attacks, and acting on abuse reports.
- Service communication — telling you a transfer was downloaded, or that it is about to expire.
- Support — answering questions you send us.
- Improvement — understanding in aggregate which features are used, so we know what to build and fix.
- Legal compliance — meeting obligations that apply to us.
We do not use file contents for advertising, do not sell personal information, and do not use your files to train AI models.
Legal basis for processing
If you are in the UK or EU, this is the legal ground we rely on for each activity.
| Purpose | Lawful basis |
|---|---|
| Delivering a transfer you requested | Performance of a contract |
| Account creation and management | Performance of a contract |
| Security, fraud and abuse prevention | Legitimate interests |
| Aggregate analytics and improvement | Legitimate interests |
| Advertising cookies | Consent |
| Marketing email | Consent, withdrawable at any time |
| Responding to legal orders | Legal obligation |
Cookies and advertising
We use essential cookies to make the site work, and we show ads on free pages. You can control advertising cookies.
Essential cookies keep you signed in, remember your day/night preference, and protect forms against cross-site request forgery. The service cannot function without them.
FileXL displays advertising on some free pages, supplied by third-party advertising partners including Google AdSense. These partners may set their own cookies to limit repetition and measure performance. We do not pass them your files, your filenames, or the contents of any transfer.
You can opt out of personalised advertising at Google Ads Settings or optout.aboutads.info. A Premium plan removes advertising entirely.
How long we keep things
Files delete themselves after 14 days. Deletion is permanent — we cannot recover a file once it has gone.
| Data | Kept for |
|---|---|
| Files uploaded without an account | 14 days from upload, then permanently deleted |
| Files uploaded to a free account | 14 days, unless you delete them sooner |
| Files on a Premium plan | 30 days, or as set out in your plan |
| Files set to self-destruct | Deleted immediately after the first download |
| Peer-to-peer transfers | Never stored. The connection record is deleted within 15 minutes. |
| Backup copies | Purged within 30 days of deletion |
| Server logs with IP addresses | 90 days |
| Account details | Until you delete your account, then removed within 30 days |
| Records required by law | As long as the relevant law requires |
Automatic deletion is a privacy feature, not a fault. Always keep your own copy of anything you send — once a file expires, it cannot be restored.
Security
Encrypted in transit and at rest, with access tightly limited. No system is perfect, and we will tell you if something goes wrong.
- In transit — TLS 1.2 or higher on every connection to filexl.com.
- At rest — AES-256 encryption on stored files.
- Peer-to-peer — DTLS with AES-GCM (mandatory in WebRTC). Encryption cannot be disabled, and no copy reaches our servers.
- Passwords — stored only as salted one-way hashes. We cannot read your password, which is why a reset is the only recovery route.
- Access control — staff access to production systems is limited, authenticated and logged.
- Download links — contain a randomly generated identifier, not sequential numbers, so they cannot be guessed or enumerated.
No online service can promise absolute security, and we will not pretend otherwise. If a breach affects your personal data, we will notify you and the relevant authorities as required by law and without undue delay.
Your rights
You can ask for a copy of what we hold, ask us to correct or delete it, and object to some uses. It is free, and we respond within 30 days.
- Access — request a copy of the personal information we hold about you.
- Correction — have inaccurate details fixed.
- Deletion — ask us to erase your account and associated data.
- Portability — receive your data in a machine-readable format.
- Restriction and objection — object to processing based on legitimate interests.
- Withdraw consent — for anything you consented to, at any time, without affecting what happened before.
- Complain — to your local data protection authority.
If you are a California resident, you additionally have the right to know what is collected and to opt out of any "sale" or "sharing" of personal information. FileXL does not sell or share personal information as those terms are defined under the CCPA and CPRA, so there is nothing to opt out of — but the right to ask stands.
To exercise any of these, contact us through the contact page. We may need to verify your identity first, particularly for deletion requests. There is no charge, and we aim to respond within 30 days.
International transfers
Our servers and providers may sit in other countries. We use recognised safeguards when data crosses borders.
FileXL operates internationally, and your information may be processed in countries other than your own, including by the infrastructure providers described in Section 07. Where information is transferred out of the UK or European Economic Area, we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision.
Children
FileXL is not for under-13s, and we do not knowingly collect their data.
FileXL is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it promptly. Where local law sets a higher age of digital consent, that higher age applies.
Changes to this policy
We will update the date at the top. For significant changes, we will tell you properly.
We may update this policy as the service evolves or the law changes. The "last updated" date at the top always reflects the current version. If a change materially affects your rights, we will give at least 30 days' notice through a notice on the site and, for account holders, by email.
Contact us
Questions about your privacy?
We would rather answer a question than have you guess. Reach us about anything in this policy, including data access and deletion requests.