Privacy Policy
Last updated: September 10, 2026
This policy describes what the hosted Fernfiles service collects about you and how it is used. If you self-host Fernfiles, this policy does not apply to your own installation — you operate that yourself.
What we collect
- Account information. The email address and/or phone number you sign in with, the handle you choose, and passkeys you add to your account.
- Your content. The files and notes you store, along with their version history and an activity log of what happened to each file — that history exists so you can recover your own data.
- Operational logs. Server logs and metrics (such as request paths, timestamps, IP addresses, and error details) used to run the service, debug problems, and prevent abuse.
- Product analytics. Pageviews and aggregate file-search usage — whether a search returned results and whether you opened one, never the text you typed — collected through our PostHog proxy at
/ph/*so your browser talks only to us, never to PostHog directly. Your IP address is forwarded to PostHog for coarse location. Signed-in activity is tied to an internal account id, never your email address or phone number, and administrator traffic is excluded entirely. To opt out, enable Do Not Track in your browser. If you self-host Fernfiles, none of this applies to your installation: analytics runs only when the operator configures a key, and this hosted service is the only installation we operate.
A separate operator switch can include the text of your searches for relevance tuning; it is disabled, and turning it on requires updating this policy first.
How we use it
We use this information only to operate the service: to sign you in, store and serve your content, deliver the sign-in codes and sharing notifications you initiate, keep the service secure, and fix problems. Your content is private to you and the people you explicitly share it with — we access it only to operate the service or when you ask us to help with a problem.
We do not sell your personal data
We do not sell your personal data, and we do not share it with third parties for their marketing. We use a small number of service providers to run the service — for example to deliver sign-in emails and text messages — and they receive only what they need to do that. We may disclose information if required to do so by law or a valid request from a public authority.
Security
We work to protect your data with access controls, encryption in transit, and the durability practices the product is built around. No online service can promise perfect security, and we do not either — but keeping your data safe is the reason Fernfiles exists, and we treat it that way.
Exporting and deleting your data
Your files are yours: you can download them from the service at any time. If you want your account and its data deleted, email us and we will remove them. Operational logs age out on their own.
Changes to this policy
We may update this policy as the service evolves. The "Last updated" date above reflects the current version. If we make a change that meaningfully affects how we handle your data, we will make a reasonable effort to notify you — for example by email or a notice in the app — before it takes effect.
Contact
Questions about your data or this policy? Email privacy@fernfiles.com. See also our Terms of Service.