notonlyfiles
PlansSign in

Privacy notice

Effective from October 3, 2026

This notice describes the personal data NotOnlyFiles handles, the reasons, how long we keep it and the rights you have under the EU General Data Protection Regulation (GDPR, Regulation 2016/679).

Controller

The controller of your data is NOTONLYFILES.COM, ITALY, . Privacy questions: hello@notonlyfiles.com.

Data we handle

When you upload

  • your files, their names and sizes;
  • the note for the recipient, if you write one;
  • your reply-to address and the recipients' addresses, if you enter them;
  • the recipient passcode and your owner key, saved only as one-way hashes that nobody, including us, can read back;
  • the time of the upload and of your agreement to the terms.

When you have an account or a paid plan

  • email address and password (hashed);
  • plan, subscription status, renewal date and the customer and subscription IDs assigned by Stripe;
  • a list of your live deliveries and the date you accepted the terms.

Card and billing details are typed directly on Stripe's checkout pages. We never receive your full card number.

When you receive files

  • your email address, if the sender asked us to notify you;
  • how many times the files were downloaded and when last, which the sender can see.

For every visitor

  • IP address and connection details (browser, time, page) recorded by the web server for security;
  • the essential cookies listed in the Cookies section.

If, and only if, you allow it in the cookie banner (each purpose separately), we also use Google Analytics to measure visits and the Google Ads tag to measure our advertising. Until you say yes, no third-party script is loaded; our fonts and scripts are served from our own server.

Please avoid uploading health data or other special categories of data about other people unless you have a lawful basis for doing so.

Purposes and legal bases

  • Running deliveries – storing files, locking them, letting recipients download them, sending notification emails and letting you track or erase them. Basis: performance of the service you asked for (Art. 6(1)(b) GDPR).
  • Accounts and subscriptions – sign-in, password resets, starting, renewing and ending plans via Stripe. Basis: contract (Art. 6(1)(b) GDPR).
  • Security and abuse prevention – per-IP limits on emails and free deliveries, defending against attacks and handling reports of illegal content. Basis: our legitimate interest in a safe service (Art. 6(1)(f) GDPR).
  • Usage statistics – aggregated figures on visits, traffic sources and pages viewed. Basis: your consent (Art. 6(1)(a) GDPR and Art. 122 of the Italian Privacy Code), which you can withdraw anytime via "Cookie settings".
  • Advertising measurement – learning how many visitors, sign-ups and subscriptions come from our Google ads. Basis: your consent (Art. 6(1)(a) GDPR and Art. 122 of the Italian Privacy Code), which you can withdraw anytime via "Cookie settings".
  • Legal duties – bookkeeping and tax records for payments, and answering lawful requests from authorities. Basis: legal obligation (Art. 6(1)(c) GDPR).

Mandatory form fields are needed to provide the service; optional ones (email addresses, note) can be left blank.

Recipients' email addresses

An address you enter for a recipient is used once, to send the link, and is shown to you in your owner area. It is not used for anything else or passed to anyone. By entering it you confirm you are allowed to.

Retention

  • Files, file names, note, email addresses and hashed passcodes: until the expiry the sender chose (1 to 60 days) or until the sender erases the delivery, then deleted automatically.
  • Unfinished uploads: removed within 24 hours.
  • Account data: as long as the account exists; you can close it yourself once no plan is running.
  • Payment records: 10 years, as Italian tax and civil law requires (Art. 2220 Civil Code).
  • IP addresses for anti-abuse limits: 1 hour (email limit) and 24 hours (Free daily limit).
  • Web server logs: for the period set by the hosting provider, usually a few months at most.

Processors and other recipients

The site and its email service are hosted by MOCHAHOST, acting as our processor. We do not sell your data or share it with anyone else, except where the law requires us to disclose it to authorities.

Uploaded files are stored with Backblaze, Inc. (USA) in the EU region of its B2 Cloud Storage service, in data centres located in the European Union. Backblaze acts as our processor under a data processing agreement that includes the European Commission's standard contractual clauses. Everything else (accounts, delivery details) stays with MOCHAHOST.

Payments are handled by Stripe Payments Europe, Ltd. (Ireland), which acts as an independent controller for its own legal and fraud-prevention duties and as our processor otherwise (see stripe.com/privacy). Stripe may transfer some data to the USA under the EU-U.S. Data Privacy Framework and standard contractual clauses.

Files and notes can be seen by anyone the sender gives the link and passcode to.

We process data inside the European Union. Should a transfer outside the EU ever become necessary, it will rely on the safeguards the GDPR requires.

Cookies

Essential cookies, set only when needed:

  • nof_session: set when you sign in or unlock a delivery, so you stay signed in. Lasts up to 30 days or until you sign out.
  • nof_consent: stores your cookie choices for 6 months.

Because these are strictly necessary or store a choice you made, they do not need consent.

Optional third-party cookies (consent required). In the banner you can allow all, keep essential only, or pick categories with "Choose":

  • Analytics – Google Analytics 4 (Google Ireland Limited): _ga and _ga_*, up to 13 months. GA4 does not log or store IP addresses. Besides page views we count a few actions (delivery created, download, sign-up, plan purchase) without sending emails, file names or delivery codes.
  • Marketing – Google Ads (Google Ireland Limited): cookies such as _gcl_au, 90 days, to link sign-ups and purchases to the ads that were seen.

Google acts as our processor (Analytics) or as an independent controller (Ads) under its own policy (policies.google.com/privacy) and may transfer data to the USA under the EU-U.S. Data Privacy Framework. Page addresses sent to Google never include delivery codes. If you choose essential only or close the banner, no Google tag is loaded. Change your mind anytime in Cookie settings; we will ask again after 6 months.

Stripe's checkout pages set their own cookies under Stripe's policy.

Security

Files are saved under random names outside the public web space, can only be fetched with the right link and passcode, and passcodes are stored only as hashes. Use a secure (https) connection and strong passcodes.

Your rights

You can ask us to access, correct or erase your data, restrict processing, object to processing based on legitimate interest, or receive your data in a portable format (Arts. 15–22 GDPR). Senders can also erase their files instantly from the owner area. Write to hello@notonlyfiles.com to exercise your rights.

You may also complain to the Italian Data Protection Authority (www.garanteprivacy.it) or to the supervisory authority where you live.

Changes

We may update this notice. The version in force, with its effective date, is always published here.

Every upload has an expiry date and is erased automatically afterwards.

PlansTerms of servicePrivacy noticeCookie settings

© 2026 NotOnlyFiles

Your cookie choicesEssential cookies keep the site running. With your permission we would also use Google Analytics to count visits and Google Ads to see which ads bring people here. You can change this later via "Cookie settings" in the footer. Details