Privacy Policy
Last updated: 2026-06-23
Who we are and how to contact us
never-delete (never-delete.app) provides subscription-based cloud backup services. We act as the data controller for personal data described in this policy.
Privacy and data requests: privacy@mail.never-delete.app. General support: support@mail.never-delete.app.
Scope
This policy applies when you use our marketing website, web dashboard, mobile apps, and related services linked from never-delete.app. Separate app variants (Standard, E2EE, and Encrypted) may process data differently — especially vault encryption — but share this policy unless we tell you otherwise.
Data we collect
- Account data: email address, password hash (if you set a password), optional Google sign-in identifiers, email verification and password-reset OTPs, legal consent timestamps (Terms, Privacy, age attestation), and marketing email preference.
- Vault content: files and folders you upload, plus metadata such as path, size, MIME type, and checksums. On the Standard product, files are stored on our object storage and we can access them to operate the service. E2EE and Encrypted variants use stronger client-side encryption; see Security below.
- Future Sync: email addresses of nominees you designate, file/folder assignments, trigger settings (inactivity or fixed date), trigger history, and release snapshots of assigned content.
- Billing data: subscription status, plan details, payment references, invoice URLs, and related records from our payment provider. We do not store card numbers.
- Support messages: category, subject, message, and account context when you contact us through the app or email.
- Technical data: device and browser type, operational logs for security and debugging, and error reports you or the app submit. Our application uses IP addresses in memory for rate limiting only; hosting and infrastructure providers may log connection data separately.
How we use your data
- Provide, maintain, and improve the backup service
- Authenticate you and manage your account
- Process subscriptions, payments, and tax obligations
- Deliver Future Sync emails to nominees and operate release workflows
- Respond to support and privacy requests
- Detect, prevent, and address abuse, fraud, and security issues
- Comply with legal obligations and enforce our Terms of Service
Legal bases (EEA/UK)
If you are in the EEA or UK, we rely on the following legal bases:
- Contract: to provide the service you signed up for (account, vault, billing, Future Sync)
- Legal obligation: to retain billing and tax records where required
- Consent: for optional marketing email (you may withdraw anytime in your profile)
- Legitimate interests: security monitoring, fraud prevention, and service improvement, balanced against your rights
Future Sync and third-party emails
When you use Future Sync, you provide email addresses of people who may not yet have a never-delete account. We use those addresses to notify nominees when a trigger fires and to deliver access to assigned content. You are responsible for having permission to share nominee contact details and the files you assign. Release snapshots are stored as part of your vault until deleted per our retention rules.
Retention
- Active subscription: vault content retained while your plan is active
- Recycle bin: deleted items are kept for up to 30 days, then permanently removed
- After cancellation: paid access until period end, then a 30-day grace period to download; vault content is then deleted
- Closed account: vault purged; we may retain billing and audit records for legal, tax, and fraud purposes (typically up to 7 years)
- OTPs: verification and reset codes expire within minutes
- Marketing email: only if you opt in; retained until you withdraw consent
Sharing and subprocessors
We do not sell your personal data. We share data with service providers who help us operate the service (hosting, storage, payments, email, authentication). See oursubprocessor list for details. We may also disclose data if required by law or to protect rights, safety, and security.
International transfers
Your data may be processed in countries where our providers operate (including the United States and other regions where Railway, Cloudflare, Dodo Payments, Google, Resend, or similar providers host or process data). Where required, we rely on appropriate safeguards such as standard contractual clauses offered by providers.
Security
We use technical and organizational measures including password hashing, presigned upload URLs, and redacted error logging. Encryption depends on your app variant: Standard stores files on our storage; E2EE and Encrypted variants encrypt content on your device before upload. No method of transmission or storage is 100% secure.
Your rights
Depending on your location, you may have rights to access, correct, delete, or export your data; restrict or object to certain processing; withdraw consent (for marketing); and lodge a complaint with a supervisory authority. We aim to respond within 30 days.
To exercise your rights, email privacy@mail.never-delete.appor use in-app support (category: Privacy & data request). EU/UK consumers: you may have a 14-day right of withdrawal on your first paid subscription as described in ourTerms of Service.
Children
The service is not intended for anyone under 16. We do not knowingly collect data from children under 16. If you believe a child has provided us data, contact us and we will take appropriate steps.
Cookies and local storage
Our websites and dashboard use essential cookies and local storage for authentication and security. We do not use non-essential analytics or advertising cookies today. See ourCookies notice for details.
Automated decisions
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
Changes to this policy
We may update this policy from time to time. Material changes will be posted here with a new “Last updated” date. Where required, we will ask you to accept the updated policy before continuing to use the service.
Questions: support@mail.never-delete.app