Privacy Policy
Who we are
File Orbit Cloud is operated by Stephen Traiforos, a United States sole proprietor doing business as File Orbit. You own your data. Stephen Traiforos is a steward of personal data described here, never its owner.
As File Orbit grows, we plan to operate through an S corporation. When that happens, we will update this policy with the new entity name.
Contact for privacy questions: privacy@fileorbit.cloud.
What this covers
This policy covers File Orbit Cloud: operated File Orbit login, optional safety-net storage, the app at app.fileorbit.cloud, the marketing site at fileorbit.cloud, support at support.fileorbit.cloud, and related billing and diagnostics.
If you run File Orbit only on hardware you control with your existing login, and you never use File Orbit Cloud products, most Cloud processing below does not apply. Your identity provider (for example Bluesky or Tangled) still has its own privacy rules.
Two sign-in paths
File Orbit login: we operate sign-in and ownership metadata at pds.fileorbit.cloud. We process the account data needed to run that service.
Your existing login: you sign in with Bluesky, Tangled, or another AT Protocol host. We receive the identity data needed to authorize File Orbit features (such as DID and handle), but we do not operate that provider and cannot control its policies, suspensions, or exports.
Information we process
- Account and identity: DID, handle, email when provided for File Orbit login or billing, and session cookies on app.* and related origins.
- Billing: plan and pack purchases, Stripe customer and subscription identifiers, and invoice metadata. Stripe processes card details; we do not store full card numbers.
- Safety-net storage: object bytes and catalog metadata you upload to File Orbit Cloud, plus sync and entitlement records needed to enforce quotas.
- Support: Discourse account linkage for paid File Orbit login customers, and lifecycle email about purchases, cancel, and lapse.
- Browser diagnostics (optional): errors, timing, and session metadata via Grafana Faro through same-origin proxies. File contents are not included. On fileorbit.cloud we ask for Accept before diagnostics start. Do Not Track and Global Privacy Control force opt-out; you can also change the preference in Account or the marketing footer.
Encryption and access
Safety-net file contents on File Orbit Cloud are encrypted at rest on DigitalOcean Spaces.
File Orbit does not end-to-end encrypt library names or paths. Privacy for home copies comes from keeping files on homes you trust and sharing only what you choose. Account, billing, and support records are visible to us as needed to run the service. We do not mine your libraries for advertising, sell access to your files, or train models on customer file contents.
How we use information
We do not mine your libraries for advertising, sell access to your files, or train models on customer file contents.
- Provide and secure File Orbit Cloud, including sign-in, sync, quotas, and support.
- Process payments and prevent fraud.
- Send transactional mail about billing and account events.
- Improve reliability when you allow browser diagnostics.
- Comply with law and respond to valid legal process, including making harmful content inaccessible when required under our Acceptable Use Policy.
Subprocessors
We use service providers to run File Orbit Cloud. They process data only to provide their services to us.
- Stripe: payments and Customer Portal.
- DigitalOcean: hosting, database, and file storage.
- Resend: transactional mail delivery.
- Discourse on support.fileorbit.cloud: community support for paid File Orbit login customers.
- Observability: logging for maintenance and metrics for performance. We do not gather personal information through diagnostics.
Cookies and similar technology
We use session cookies required to keep you signed in and to complete OAuth on app and related origins. Locale preference may be stored in local storage on the marketing site.
Optional browser diagnostics on fileorbit.cloud run only after you Accept the diagnostics banner (or enable the footer control later). Decline, Do Not Track, and Global Privacy Control keep diagnostics off. Diagnostics may set a local preference for that choice. We do not use third-party advertising cookies on File Orbit Cloud.
Retention and deletion
We keep account, billing, and safety-net data while your Cloud relationship is active and as needed for tax, dispute, and security records.
Account Danger can clear File Orbit metadata (`cloud.substratum.*`) from your owner PDS repo and prune this Place's catalog projection. That action does not wipe disks at home, copies on other homes you invited, or your AT Protocol identity. Deletion requests that go beyond those limits may be limited by how peer Places and third-party identity hosts work.
Children
File Orbit Cloud accounts are for adults 18 years or older. Household sharing lets you invite people you trust who also meet that age rule. It is not a product for creating accounts for children under 13, and we do not knowingly collect personal information from children under 13 as account holders.
Adults may store family files in their own accounts, including documents and photos that relate to their children (for example school or medical records). You remain responsible for what you store and for sharing it only with people you trust.
Where data is processed
Safety-net storage operates in North America. Supporting systems (identity, billing, and maintenance logging) also run in the United States unless we publish otherwise. We do not currently appoint an EU or UK representative; if that changes, we will update this page.
Sale of personal information
We do not sell personal information for any reason. We do not share personal information for advertising or marketing. We only share what is needed with the service providers listed above to run File Orbit Cloud, or when the law requires it.
Your choices
- Opt out of browser diagnostics in Account, on the marketing footer, or via DNT / Global Privacy Control.
- Manage billing methods and cancel subscriptions in the Stripe Customer Portal from Account.
- Contact privacy@fileorbit.cloud to ask about access or deletion of Cloud-held personal data.
Changes
We may update this policy as the product changes. The effective date above will change when we publish a revision. Material changes for paying customers will be called out in product or billing communications when practical.