Privacy Policy
Last updated: 2026-07-25
This Policy explains what personal data MirrorUploadX collects, why, and your rights. A central point: we do not retain your files — they pass through transient staging and are deleted after distribution.
Template for review — not legal advice. Have counsel adapt this to your jurisdiction and corporate details before relying on it.
1. Who we are
MirrorUploadX operates this transfer and link-management service and is the controller of the personal data described here. Contact us at [email protected].
2. Data we collect
Account data: your email address, authentication data (password hashes, 2FA settings), and roles.
Upload metadata: file name, size, MIME type, scan result, chosen providers, job and share status, and timestamps. This is metadata about the transfer — not the file contents kept long-term.
Technical data: a hashed form of your IP address, request logs, and security events. We avoid retaining raw IP addresses where we can.
Connection data: if you connect a provider, we store your provider API key encrypted (AES-256-GCM); it is never displayed back to you.
3. How we handle your files
Your file is placed in a temporary staging area only for as long as needed to distribute it to your chosen providers — and, where virus scanning is enabled, to scan it first. After distribution completes (or fails past retry), the staging copy is deleted under our retention policy.
We do not keep a durable copy of your file, we do not read its contents beyond automated virus scanning where that is enabled, and we do not use it to train models or for advertising.
4. How we use data
To provide the service (staging, scanning, distribution, share pages), to secure it (abuse prevention, rate limiting, fraud), to communicate with you (verification, security, service notices), and to meet legal obligations.
We do not sell your personal data.
5. Legal bases (GDPR/UK GDPR)
We rely on: performance of our contract with you (to run the service); our legitimate interests (security, abuse prevention, improving the service); your consent (non-essential cookies); and legal obligation (responding to lawful requests, copyright notices).
7. International transfers
Where data is transferred across borders, we use appropriate safeguards such as standard contractual clauses.
8. Your rights
Subject to law, you may access, correct, export, or delete your data, object to or restrict certain processing, and withdraw consent. You can export your data and delete your account from the Security page in your dashboard.
You also have the right to complain to your local data-protection authority.
9. Retention
Staging file copies: deleted after distribution per our retention policy. Account and metadata: kept while your account is active and for a limited period afterwards as needed for legal, security, and accounting purposes, then deleted or anonymized.
10. Security
We use encryption in transit, encryption of stored provider credentials, access controls, and audit logging. No system is perfectly secure, but we work to protect your data and to notify you of incidents where required.
11. Children
The service is not directed to children below the age of digital consent, and we do not knowingly collect their data.
12. Changes and contact
We may update this Policy; material changes will be signposted.
Contact [email protected] for privacy requests or to reach our data-protection contact.