Privacy Policy
Data Collection & Third Parties
We respect your privacy. We do not intentionally log or retain IP addresses or other Personally Identifiable Information (PII) unless you explicitly provide it to us.
However, our infrastructure relies on the Cloudflare ecosystem (Workers, Analytics, R2). These services may collect technical information as part of their operation. Please refer to Cloudflare's Privacy Policy for more details.
Information We Store About Files
When you upload a file, we store the following metadata to manage the service:
- CID (Content Identifier): A unique ID for the file content.
- Owner ID: To link the file to your account (if logged in).
- Encrypted File Metadata: New uploads store the original filename, MIME type, and original size in an AES-GCM encrypted metadata payload.
- Operational Size & Type Values: Limited values required to enforce storage limits and operate encrypted object storage. These values are not used to decrypt file content.
- Timestamps: When it was uploaded and when it expires.
- Operational Metadata: Limited operational, security, account, billing, and storage metadata may remain, including identifiers, ownership, quota usage, subscription status, abuse handling records, and infrastructure logs.
Encryption Guarantee
The actual content of your files and the user-facing file metadata are encrypted by your browser or SDK for every upload before they reach our servers. Standard download links keep the decryption key in a URL fragment (
#key=...), which is not included in HTTP requests. Downloads and interactive previews are decrypted in browser Workers, and public page metadata never contains decrypted file metadata.Embedding is an explicit exception. If you enable it, the Embed URL places the decryption key in a query parameter (
?key=...). The key is then sent to EasyOne, Cloudflare and other network infrastructure, and may be observed by crawlers or systems that process the URL. EasyOne uses it to decrypt eligible metadata and video chunks for each embed request, without persisting the key or decrypted output. Anyone who obtains the Embed URL can decrypt the file. Do not enable embedding for sensitive files.
Document Privilege
All plans receive the same content and user-facing metadata encryption. Basic, Pro, and Enterprise plans may additionally enable Document Privilege, which restricts file and metadata access to the uploader. This is access control, not an additional encryption tier. Document Privilege cannot be combined with embedding.
Information We Store About Accounts
If you create an account, we store:
- User UUID: A unique internal identifier.
- Public Key: Used for verifying your identity securely without passwords.
- Plan Status: Information about your current subscription plan.
- Email Address (Optional): stored using industry-standard encryption at rest (only if provided).
Email Address Usage
You may optionally provide an email address for account recovery or notifications. If you do so, we use it ONLY for:
- Account Recovery: Sending a temporary login key if you lose access.
- DMCA/Legal Notices: Notifying you if your content is removed due to a legal request.
- Critical Notifications: Rare, urgent system alerts.
We do NOT link your email to your uploaded files for public view.
Zero-Share Guarantee
We NEVER sell your email address to third parties, except where required by law. We strictly only share your email with our delivery provider, MailGun, for the sole purpose of sending you verification codes and critical notifications.
Payments
If you purchase a paid plan, our payment processing partners may collect necessary billing information to process the transaction. We do not store your credit card information directly. EasyOne does not provide any information other than your User ID to our payment processing partners.