Privacy Policy
Effective October 8, 2026
Terebyte is built so that we can’t read what you store. This policy explains the little we can see, why we keep it, who helps us run the service, and the choices you have. Terebyte, Inc., a Delaware corporation, is responsible for your information (the “controller”).
In short
- Your files and file and folder names are encrypted on your device. We can’t read them, and neither can our providers.
- We know your email address, how much you store and download, and the sizes and times of your uploads.
- No ads. No tracking. No AI training. No advertising or analytics scripts, no tracking pixels, and we don’t sell or share your information for advertising.
- You can delete your account, and everything in it, at any time in Settings.
1. What we can’t see
Your browser encrypts each file, and its name, before upload, with keys made from your vault passphrase on your device. The passphrase and your recovery key never reach us. So we can’t see:
- the contents of your files, or their types;
- the names of your files and folders;
- your vault passphrase or recovery key;
- the keys and passwords of your share links (the key is in the part of a link after “#”, which browsers don’t send to us).
Our download servers and our storage provider only ever handle encrypted bytes. No one at Terebyte can open your files, and we can’t hand their contents to anyone, whoever asks.
2. What we keep, and why
| Information | Why |
|---|---|
| Your email address, and an optional name (and profile picture if you sign in with Google) | To sign you in, send sign-in links and service emails, and keep to one account per inbox |
| Your plan, storage used, and this month’s download totals | To apply your plan’s space and download allowance, and warn you before you reach it |
| For each file: its encrypted name, size (before and after encryption), upload time, folder and versions | To store your files, show them to you (decrypted on your device), and count your space |
| Your vault’s encrypted keys and the settings needed to unlock them | So you can unlock your vault on any device. They’re useless without your passphrase or recovery key |
| For each share link: when it was made and expires, whether it has a password, and how often it’s been downloaded | To run your links, apply their limits, and let you see their use |
| When your account was created, and when you last signed in or unlocked your vault | Security, and the inactivity rule for free accounts (see the Terms) |
| Sign-in sessions and one-time sign-in links (stored only as secure hashes) | To keep you signed in for up to 30 days and make sign-in links work once |
| Your IP address, briefly | To stop abuse. We don’t store the address itself, only a coded form that can’t be turned back into it, deleted within days |
| The partner who referred you, if you came through a partner’s link | To pay the partner their share of what you pay |
| Whether you joined from a shared link | To understand, in total, how people find Terebyte |
| Billing details (see section 5) | To give you the plan you paid for |
| Emails you send us | To answer you |
If you live in the European Economic Area or the UK, our legal bases are: performing our contract with you (running your account and storage, and sending the emails the service needs); our legitimate interests in keeping Terebyte secure and free of abuse (rate limits, the bot check, backups, and acting on reports); and legal obligations (such as tax records and lawful requests).
3. The bot check at sign-in
When you ask for a sign-in link, your browser runs a short check that tells people apart from automated programs. It’s provided by Vercel, our hosting provider, with its security partner Kasada, and runs from our own web address. It looks at technical signals from your browser and device, such as the browser type and version, system and display settings, how the page was loaded and interacted with, together with your IP address, and returns a verdict: person or bot.
We use the verdict for one thing: deciding whether to send the sign-in link. We don’t keep the signals, and they aren’t used for advertising, analytics or profiling. The check sets no tracking cookies and runs only on the sign-in and sign-up forms.
4. Cookies and local storage
We use only what the service needs to work:
- a session cookie that keeps you signed in (up to 30 days), and short-lived cookies that protect the sign-in form;
- a short-lived cookie that holds an invitation code, if you used one, until your account is created;
- if you came through a partner’s link, a cookie holding that partner’s code for up to 30 days, so the partner is credited if you sign up;
- if you came to Terebyte from someone’s shared link, a cookie containing only the word “share” for up to a week, so we can count such sign-ups in total; it identifies no one;
- settings saved in your browser, such as light or dark appearance and how soon your vault locks itself, and, while your vault is unlocked, a sealed copy of your keys so a page reload doesn’t lock you out. It can only be opened with a secret our server forgets as soon as your vault locks.
No advertising or analytics cookies, no tracking pixels, no third-party analytics, ever. There’s nothing to opt out of.
5. Payments
Paid plans are sold through Link, a service of Stripe, as reseller and merchant of record. Link collects your payment details, billing address and email to take your payment and calculate tax, and handles that information as an independent controller under the Link Privacy Policy. We receive what we need to give you your plan: a customer and subscription reference, your plan and billing period, the amounts paid, and your country. We never receive your full card number.
6. Who helps us run Terebyte
These companies process information for us, under contracts that limit its use to providing their service to us. We don’t sell your information, and we don’t share it for advertising.
| Provider | What it does | Where |
|---|---|---|
| Vercel | Hosts the website and app; runs the bot check (with Kasada); keeps short-lived request logs | United States |
| Neon | Hosts our database (account and file information listed in section 2, on Amazon Web Services) | United States |
| Backblaze | Stores your encrypted files, and our encrypted database backups | United States |
| OVHcloud | Runs our download servers, which pass encrypted bytes from storage to your browser and keep no access logs | United States |
| Resend | Sends our emails (sign-in links and service notices), and receives email sent to our addresses | United States |
| Stripe and Link | Payments (see section 5) | United States and worldwide |
| GitHub | Runs our nightly database backup, which is encrypted as it’s made, with a key only we hold, before it’s stored | United States |
| Hosts the mailbox where emails you send to our addresses arrive | United States |
Terebyte is run from the United States, and your information is stored there. Where the law of your country requires it, transfers to the United States are protected by the European Commission’s standard contractual clauses or an equivalent safeguard.
7. How long we keep things
- Your account information and files: for as long as you keep your account.
- Deleted files and versions: removed from storage within hours of deleting them, with no hidden copy kept. Deleted share links stop working at once.
- Deleted accounts: removed from our database right away, and their files from storage within hours. Encrypted database backups that still contain the account’s records age out within 32 days.
- Free accounts unused for 12 months: removed, after two emails (see the Terms).
- Rate-limit codes: within two days. Hosting request logs: a few days. Emails we send: kept by Resend for a limited time.
- Billing records: as long as tax and accounting law requires, usually up to seven years.
8. Security
Files are encrypted with AES-256-GCM in your browser, with keys derived from your passphrase (PBKDF2 and HKDF) using your browser’s built-in Web Crypto. Everything travels over HTTPS. Our database connections verify the database’s certificate, our backups are encrypted before they’re stored, and every key we use is limited to the one job it does. No system is perfectly secure, but even if our servers were breached, your files and their names would remain encrypted.
9. Your choices and rights
- Delete: delete your account and everything in it at any time in Settings → Delete account.
- Download: your files are yours to download at any time.
- Access, correct or export your account information, or object to how we use it: write to privacy@terebyte.com. We answer within 30 days, and may ask you to confirm the request from your account’s email address.
Depending on where you live (for example the EEA, the UK, or US states such as California), you have rights to access, correct, delete and port your personal information, to object to or restrict its use, and to complain to your data protection authority. We honor these rights for everyone, wherever they live. We don’t sell personal information or share it for cross-context behavioral advertising, and we don’t use it to make decisions about you by automated means.
10. Requests from authorities
We respond only to valid legal process, and we can only provide what we have: the account information in section 2. We can’t provide the contents or names of anyone’s files, because we don’t have the keys. Where we’re allowed to, we tell the member before we disclose anything.
11. Children
Terebyte isn’t meant for children under 16, and we don’t knowingly collect their information. If you believe a child has an account, write to privacy@terebyte.com and we’ll remove it.
12. Changes
If we change this policy in a way that matters, we’ll tell you by email or in the app before the change takes effect. The date at the top shows when it last changed.
13. Contact
Privacy questions and requests: privacy@terebyte.com.
Terebyte, Inc., a Delaware corporation
Postal address on request: legal@terebyte.com
Email: privacy@terebyte.com