This policy explains what personal data FileFortress processes when you browse, download, upload or contact us, why, on what legal basis, for how long, and what rights you have. It is provided under Articles 13 and 14 of the EU General Data Protection Regulation (GDPR).
1. Who is responsible
The controller responsible for data processing on this website within the meaning of the GDPR is The operators of FileFortress, reachable through a moderator (use the “Report” link on any resource). We are based in the European Union. We are not required to appoint a data protection officer (§ 38 BDSG), but you can send any data protection question or request to the contact above.
2. The short version
- You do not need an account. We never ask for your name, email address or any other contact details to browse, download or upload.
- We never store your IP address in readable form. Where we need to recognise a network (likes, spam protection), we store only a keyed hash of it.
- We use only cookies that the site needs to work. No advertising, no analytics or tracking tools, no social media plugins, no externally loaded fonts or scripts.
- We never sell your data or use it for advertising.
3. Visiting the site
When you open a page, your browser necessarily sends technical data such as your IP address, the date and time, the page requested, and your browser’s user agent. We use this only to deliver the page and the files you request. Our website itself does not write these details to access logs. The hosting providers that deliver the site and its files (see section 11) may keep short-lived technical logs for security and to fend off attacks, for the period set by that provider, usually no more than a few weeks.
We also count page views per resource. That count is a plain number with no link to you.
Legal basis: Art. 6(1)(f) GDPR. We have a legitimate interest in providing a working, secure website.
4. IP addresses and likes
Your IP address is turned into a keyed one-way hash (HMAC-SHA-256 with a secret key) as soon as a request reaches us, and only that hash is stored. For IPv6 addresses only the network part (the first half, which a household or phone connection shares) is hashed. We cannot read your IP address back from it. Because we hold the key, however, the hash legally counts as pseudonymised personal data, not anonymous data, so we treat it with the same care. We use it to:
- Likes: allow one like per network and resource. The hash and time of the like are stored.
- Spam and abuse protection: rate limits (e.g. on uploads, PIN attempts and reports) count recent requests per hash. While an upload waits for review, the hash is stored with it, so that moderators can see several uploads came from the same network and stop a flood of spam. It is erased as soon as the upload is approved. If moderators block a network for spam, its hash, the reason and the date are kept on a block list until the block ends.
- “I'm not a robot” check: the upload form uses a CAPTCHA that runs on our own server (the open-source ALTCHA). Your browser solves a small computing task. Nothing is sent to a third party, no cookies are set and no images need to be clicked. A fingerprint of the solved task (not linked to you) is kept for up to 24 hours so it can't be used twice.
Legal basis: Art. 6(1)(f) GDPR. We have a legitimate interest in fair like counts and in protecting the site from abuse. Downloads are only counted as a total per resource; no record of who downloaded what is kept. Retention: rate-limit entries are deleted after 24 hours; the hash stored with an upload is erased when it is approved (or deleted with the upload); block-list entries are deleted when the block ends, at the latest after 30 days. Likes are deleted together with the resource they belong to.
5. Cookies
We use only first-party cookies (set by FileFortress itself). Each is strictly necessary to provide a feature you use, so under § 25(2) no. 2 TDDDG no consent is required and we do not show a cookie banner. We do not use cookies for analytics, advertising or tracking. Blocking cookies in your browser will break forms and uploads.
| Cookie | Purpose | Lifetime |
|---|---|---|
ff_anon | A random ID with no link to your identity. It protects forms against cross-site request forgery (CSRF), ties an upload in progress to your browser, and remembers which surveys you already answered. | 30 days |
ff_edit_… | Keeps you signed in to your upload’s edit page after you enter your PIN. | 30 minutes |
ff_flash | Carries a one-time notice (e.g. “Saved”) to the next page. | Until you close the browser |
ff_no_surveys | Remembers that you chose not to see surveys. Only set if you ask for it. | 1 year |
ff_session | Sign-in cookie for staff members only. | 30 days |
Any processing of personal data linked to these cookies is based on Art. 6(1)(f) GDPR. We have a legitimate interest in a secure site that works as requested.
6. Uploading and editing
When you upload a resource we process what you enter and provide: title, descriptions, category, tags, licence, version, creator name and collaborator aliases (optional, and they may be pseudonyms), credits, the files, images or download link you add, and the time of submission. You choose a PIN and receive a private edit link, which your browser also downloads as a small text file to your device (we keep no copy of that file). We store the PIN and the link only as one-way hashes, so we cannot read them or send them back to you. If you add an optional recovery phrase, it is stored as a one-way hash too. Its hint is stored as you type it and is shown to moderators only; never put the answer or personal data in it. The phrase is only used when you ask a moderator for help because you lost your link or PIN: they can check a phrase you tell them. The site only answers whether it matches; moderators never see the stored phrase. Each check is logged for all staff, and a matching phrase is then deleted, so you set a new one.
Every upload and every edit is reviewed by a moderator. Once approved, the content and the creator name you entered are publicly visible. Please do not put personal data you do not want published (such as your real name or email address) into an upload. Cover images are converted to the WebP format for display. Other files are stored unchanged.
Legal basis: Art. 6(1)(b) GDPR, because we are providing the hosting service you ask for. Moderation is also based on Art. 6(1)(f) GDPR (our legitimate interest in keeping unlawful content off the site) and Art. 6(1)(c) GDPR (our obligations as a hosting provider under the Digital Services Act).
7. Reports and copyright notices
When you report a resource we store the reason you pick, your optional message, the time, the report’s status and any reply from staff, together with the hash of your IP address (to stop duplicate and abusive reports). If you send a copyright or other legal notice by email, we process the details in it, including your name and contact details, to handle it. Where the law requires, we may pass a notice on to the uploader or to the authorities (see section 11).
Legal basis: Art. 6(1)(c) GDPR (notice-and-action obligations under Art. 16 DSA) and Art. 6(1)(f) GDPR (our legitimate interest in a lawful, safe site). Retention: reports are kept while the reported resource exists, or until staff delete the report. Legal notices are kept as long as needed to handle them and to defend against possible claims.
8. Surveys
We sometimes show a short, optional survey. If you answer or skip it, we store your answer (or that you skipped), the time and the random ff_anon ID, so that you are not asked the same question twice. We look only at combined results. Answering is voluntary.
Legal basis: Art. 6(1)(f) GDPR. We have a legitimate interest in improving the site. Retention: until staff delete the survey.
9. Contacting us
If you contact us (for example by email), we process your message and your contact details to answer you. Legal basis: Art. 6(1)(f) GDPR, or Art. 6(1)(b) GDPR where your message concerns your upload. Retention: we delete it once your request is fully dealt with, unless we must keep it longer by law or to defend against legal claims.
10. Staff and creator accounts
Trusted creators: staff may invite individual creators to an account. For them we store a username, display name, a hashed password and a hashed PIN, active sign-ins (kept on the device for up to 90 days), the time of the last sign-in, whether their uploads skip review, and which uploads belong to them. Sign-in attempts are logged as described below. Legal basis: Art. 6(1)(b) GDPR. Retention: until staff remove the account; their uploads then stay on the site without the account link.
Apart from that, only moderators and administrators have accounts. For them we store a username, display name, email address, a salted password hash, an optional bio and avatar, the role, the time of the last sign-in and active sessions. Their moderation actions and notifications are recorded. To detect password-guessing attacks, every sign-in attempt is logged with the account or name typed, the time, the result, the hashed network address and the country; the log is deleted after 30 days. Legal basis: Art. 6(1)(b) and (f) GDPR. Retention: until the account is removed. Sessions expire after 30 days.
11. Service providers and recipients
We use carefully selected technical service providers to run the site: providers of web hosting, the database, file storage servers and the network connection that delivers our files. They process data only on our instructions under data processing agreements (Art. 28 GDPR) and may not use it for their own purposes.
Apart from that we only share data where we are legally required to, for example with law enforcement or courts on a valid order, or with the authorities where content suggests a criminal offence threatening someone’s life or safety (Art. 18 DSA). Content you upload is public once approved, so anyone can see it. We do not sell data, and we do not share it with advertisers or data brokers.
12. Where your data is stored
Our data is stored on servers in the European Union and in the United Kingdom. Transfers to the United Kingdom are covered by an adequacy decision of the European Commission (Art. 45 GDPR), which confirms an equivalent level of protection. Some of our service providers belong to groups headquartered in the United States. Where data could be accessed from there, the transfer is covered by the EU-U.S. Data Privacy Framework (Art. 45 GDPR) or the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). You can ask us for a copy of the safeguards.
13. How long we keep data
- Published uploads: until you delete them with your edit link and PIN, or a moderator removes them.
- Rejected uploads: deleted automatically, including their files, 30 days after rejection unless you resubmit them.
- Replaced files (for example an old version of a download): kept for at least 30 days, then deleted once they have not been downloaded for 60 days. This lets people finish downloads that were already in progress.
- Likes and reports: deleted together with the resource. Downloads are only counted, not recorded individually.
- Rate-limit entries: 24 hours. Spam block list: until the block ends (at most 30 days). Cookies: see section 5.
- Backups may hold deleted data for a short time until they are overwritten.
Where the law requires us to keep data for longer (for example as evidence in legal proceedings), we restrict its processing to that purpose.
14. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased (Art. 17);
- have processing restricted (Art. 18);
- receive your data in a portable format (Art. 20);
- object to processing (Art. 21, see section 15);
- lodge a complaint with a data protection supervisory authority (Art. 77), in particular in the EU country where you live or work, or where you believe the infringement took place.
To use these rights, contact a moderator (use the “Report” link on any resource). Because there are no visitor accounts, we can often only link data to you if you give us something that identifies it, such as your upload’s edit link (never send us your PIN). Where we cannot identify you, the rights in Art. 15 to 20 apply only once you give us such information (Art. 11 GDPR). You can edit or delete your own uploads at any time yourself with your edit link and PIN.
15. Your right to object
Right to object (Art. 21 GDPR): where we process your data on the basis of our legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation. We will then stop processing it, unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims. Contact a moderator (use the “Report” link on any resource).
16. Security
We protect data with technical and organisational measures appropriate to the risk (Art. 32 GDPR). These include encrypted connections (HTTPS), one-way hashing of PINs, edit links, passwords and IP addresses, signed and time-limited upload and download links, access limited to staff, strict browser security rules (Content Security Policy), and rate limits. No system is completely secure. If a breach is likely to put your rights at high risk, we will inform you as required by Art. 34 GDPR.
17. Children
FileFortress is not directed at children under 13. Users under 18 should use the site only with a parent’s or guardian’s permission. Since we do not ask for identifying information we cannot verify age, but if you believe a child has published personal data here, contact us and we will remove it.
18. External links
Some resources link to downloads or pages on other websites. When you follow such a link, that site’s own privacy policy applies. We have no control over what it processes.
19. Changes to this policy
We do not make decisions based solely on automated processing that produce legal effects on you (Art. 22 GDPR). We will update this policy when the site or the law changes. The date at the top shows the current version. Questions? Contact a moderator (use the “Report” link on any resource).