Legal
Privacy Policy
Your files are protected by client-side end-to-end encryption. Here is what InfiniDrive can process, what stays private, and how to exercise your rights.
1. Who is responsible for your data
The operator of the InfiniDrive service is responsible for personal data processed to run the service. The operator's verified legal identity is stated on checkout and billing documents, and is provided on request through privacy@infinidrive.app.
When an organization uses InfiniDrive to store personal data of its own users or clients, the organization acts as controller of that content and InfiniDrive processes it on the organization's behalf under the Data Processing Agreement.
2. What we process
InfiniDrive collects only what is needed to operate accounts, storage, billing, security, and support:
- Account data — email address, display name, chosen language, plan, and authentication identifiers.
- Encrypted content — encrypted file contents, names, application metadata, versions, and encrypted key records. InfiniDrive does not receive the secrets needed to decrypt E2E-encrypted files. Object counts, ciphertext sizes, folder relationships, sharing records, and service timestamps remain visible.
- Operational data — IP addresses, device and browser details, timestamps, request identifiers, and security event logs.
- Billing data — subscription state and limited payment metadata received from Stripe. InfiniDrive never stores full card numbers.
- Support data — messages and diagnostic details you choose to send us.
3. Why we process it
Processing serves a small set of purposes: providing and securing the storage service you signed up for, handling subscriptions and taxes, preventing abuse, answering support requests, meeting legal obligations, and keeping the platform reliable. Depending on the context, the legal basis is performance of a contract, a legitimate interest in security and operations, your consent, or a legal obligation.
InfiniDrive does not sell personal data. We cannot read E2E-encrypted file contents: encryption and decryption happen on your device, and the service does not hold your decryption secrets.
4. Cookies and local storage
This marketing site sets no advertising or analytics cookies. The product uses necessary session data and browser storage for sign-in, secure transfers, and public verification records. Unlocked encryption keys stay in a browser worker’s memory; locking or signing out ends that worker and clears decrypted previews.
5. Your rights
Subject to applicable law, you can request access to your data, correction, deletion, restriction of processing, or a portable copy, and you can object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it at any time. You may also lodge a complaint with your data-protection authority.
- Send requests from your account email to privacy@infinidrive.app.
- We may verify your identity before releasing or deleting data.
- We respond within the timeframes required by applicable law.
6. Delete your InfiniDrive account
InfiniDrive is provided by InfiniDrive OÜ, registry code 17572344, Tallinn, Estonia. Account deletion is available directly in InfiniDrive Mobile and in the authenticated customer panel. A support-assisted route remains available if you cannot sign in.
Self-service deletion: in the mobile app open Settings → Delete account, or sign in at panel.infinidrive.app/account and choose Delete my account. Review the consequences, type the exact username and DELETE, acknowledge permanent data loss, and submit. If you cannot sign in, email support@infinidrive.app from the registered address with the subject “Delete my InfiniDrive account” and complete the identity-verification step sent by support.
- After verification, access is disabled and any active paid subscription is cancelled so that no further recurring charges are created.
- The account profile, authentication identity, uploaded files and folders, file versions, shares, deleted items, storage allocations, and associated application metadata are permanently deleted.
- Permanent deletion from active systems is completed within 30 days after successful identity verification. Uploaded content cannot be restored after deletion completes.
Limitation: RAID redundancy is an availability control, not a backup. After a confirmed permanent deletion completes, content cannot be restored.
7. Retention after account deletion
InfiniDrive does not retain uploaded files after permanent deletion completes. Limited records are retained only where they are necessary for security or required by law:
- Technical and security logs are retained for no more than 30 days and are then automatically deleted or anonymized.
- Invoices, payment transaction records, and accounting documents are retained for 7 years where required by Estonian accounting and tax law. Access is restricted and these records cannot be used to restore the deleted account or its files.
- The deletion request and minimal evidence that it was fulfilled may be retained for up to 3 years to demonstrate compliance and resolve legal claims; it does not include uploaded file content.
8. Providers and international transfers
InfiniDrive relies on a deliberately short list of providers for infrastructure, network delivery, and payments; each provider and its role is published on the Subprocessors page. Primary storage stays in Europe. Where a provider may process limited data outside the EEA, a recognized transfer mechanism is used where required.
9. Contact
For any privacy question or request, write to privacy@infinidrive.app. General support is available at support@infinidrive.app.
