Terms of Service
Last updated: May 13, 2026
1. Acceptance of Terms
By accessing or using the filez.zone file-sharing service ("Service"), you agree to be bound by these Terms of Service ("Terms"). If you do not agree to all of these Terms, do not use the Service.
2. Description of Service
filez.zone provides an end-to-end encrypted file-sharing service. Files are encrypted in your browser before upload and can only be decrypted by recipients who possess the unique link containing the encryption key. Files are automatically deleted from our servers after a single download ("burn after reading").
Important: We never have access to your encryption keys or the plaintext content of your files. The key is embedded in the URL hash fragment, which is never transmitted to our servers.
The Service also offers optional user accounts that enable the ability to save and manage shared capability URLs. Creating an account is entirely voluntary — the core file-sharing functionality works without one. When you upload a file while authenticated, the capability URL is automatically saved to your account for later access.
3. User Responsibilities
You are solely responsible for:
- The content of files you upload through the Service.
- Ensuring that you have the right to share any files you upload.
- Maintaining the security of any capability links you generate.
- Any consequences of sharing decryption links with third parties.
If you create a user account, you are additionally responsible for:
- Providing accurate and truthful registration information.
- Maintaining the confidentiality of your account credentials (email and password).
- All activity that occurs under your account, including any saved URLs and file uploads.
- Managing your saved URL collection — you can delete your account at any time via the user menu, which permanently removes all associated data.
4. Acceptable Use
You agree not to use the Service to:
- Share content that is illegal, harmful, threatening, abusive, or violates any applicable law.
- Share content that infringes on the intellectual property rights of others.
- Distribute malware, viruses, or any other harmful code.
- Attempt to compromise the security or integrity of the Service.
- Use the Service in any manner that could damage, disable, or overburden our infrastructure.
- Create accounts through automated means or impersonate other individuals without authorization.
5. Data Retention & Deletion
Files uploaded through the Service are automatically and permanently deleted from our storage infrastructure immediately after the first successful download. We do not retain copies of uploaded files, encryption keys, or decryption links after download.
If a file is never downloaded, it may remain on our servers until it is purged by routine maintenance. We make no guarantees about the duration an undownloaded file will be retained.
User account data (email, display name, hashed password, and saved URL records) is retained until you choose to delete your account. Account deletion is available from the
user menu and permanently removes all associated data from our database. Saved URL records are
only accessible to you through authenticated requests using a valid JWT token in the Authorization: Bearer <token> header.
6. Privacy & Encryption
All file encryption and decryption occurs exclusively in your browser using AES-256-GCM via the Web Crypto API. The encryption key is never transmitted to our servers — it is conveyed to recipients only through the URL hash fragment, which browsers do not send in HTTP requests.
For authenticated users, we use bcrypt to hash passwords with unique
per-password salts — plaintext passwords are never stored. Session management uses JSON Web Tokens (JWT) signed with a server-side secret. The JWT is stored
in your browser's localStorage and sent to protected endpoints via the Authorization: Bearer <token> header, which is validated by server middleware before handlers execute.
We cannot read, modify, or decrypt your files. We cannot recover lost capability links or account passwords. For more details, see our Privacy Policy.
7. Service Availability
The Service is provided "as is" and "as available." We do not guarantee uninterrupted or error-free operation. We reserve the right to modify, suspend, or discontinue the Service (or any part thereof) at any time without prior notice.
8. Limitation of Liability
To the maximum extent permitted by law:
- The Service is provided without warranties of any kind, express or implied.
- We are not liable for any loss of data, including files that fail to upload, download, or decrypt correctly.
- We are not liable for the loss of saved URL records or account data resulting from account deletion, service interruption, or database failure.
- We are not liable for any direct, indirect, incidental, or consequential damages arising from the use or inability to use the Service.
- We are not responsible for the content shared by users through the Service.
9. Changes to Terms
We may update these Terms from time to time. Changes will be effective immediately upon posting the updated Terms on this page. Your continued use of the Service after any changes constitutes your acceptance of the revised Terms.
10. Contact
If you have questions about these Terms, please reach out to us at legal@filez.zone.
