Privacy Policy
Effective August 28, 2026. This Policy applies to the Arkfile service at arkfile.net.
1. Who is responsible for your information
the operator of arkfile.net (the "Operator") operates the Arkfile service at arkfile.net (the "Service") and is responsible for the personal information described in this Policy. This Policy applies only to this deployment. Another Arkfile deployment may have a different operator and privacy policy.
2. Arkfile's privacy model
Arkfile is designed to minimize information available to the server. File contents and owner file metadata, including original filenames, plaintext file digests, custom-password hints, and tags, are encrypted on your device before upload. Account passwords, custom file passwords, share passwords, Account Keys, and unwrapped File Encryption Keys are not sent to or stored by the server. The Operator cannot decrypt these items from stored server data alone. The server does receive operational information needed to provide the Service, as described below.
3. Information the Service processes
Account and service records can include your username, account status, approval status, public key-derivation salt and profile, multi-factor enrollment records, session and revocation records, storage usage and limits, credit and billing records, upload and share timestamps, and administrative actions. If you voluntarily save contact information, it can include a display name, email address, messaging address, telephone number, labels, or notes. Contact information is encrypted at rest with server-held keys but can be decrypted and read by authorized administrators for account-related contact and recovery.
Encrypted storage records can include encrypted file contents, encrypted filenames and other owner metadata, wrapped File Encryption Keys, encrypted share envelopes, ciphertext nonces, ciphertext digests, encrypted-stream and stored-object digests, file and share identifiers, password type, chunk layout, pre-padding encrypted size, padded object size, storage routing information, expiration dates, download limits, and share access counts. The Operator can read the operational fields but cannot read the client-encrypted contents without your client-side secrets.
For security and rate limiting, the Service processes request information. Raw IP addresses are not persisted in Arkfile application logs or security-event records. For unauthenticated requests, the Service temporarily combines IP address, User-Agent, and Accept-Language information and applies a keyed one-way function to create a daily-rotating Entity ID. For authenticated requests, an Entity ID can be derived from the username. Security events may contain an Entity ID, event type, time, and, for authenticated activity, a username. Ordinary server logs can contain operational event details but are designed not to contain raw client IP addresses, passwords, decryption keys, or plaintext file contents.
4. Why information is used
The Operator uses account, encrypted storage, session, and billing information to create and administer accounts, authenticate users, store and transfer encrypted files, operate shares, apply storage limits and charges, process credits, respond to support and recovery requests, maintain backups and replication, and provide requested features. Where UK or EU data-protection law applies, this processing is generally necessary to perform the agreement with you or take requested steps before entering that agreement.
The Operator uses security events, derived Entity IDs, and administrative records to prevent abuse, enforce rate limits, investigate failures, protect users and infrastructure, comply with law, and establish or defend legal claims. Where UK or EU law applies, this processing is based on the Operator's legitimate interests in operating and securing the Service, compliance with legal obligations, or the establishment and defense of legal claims. Optional contact information is used for account-related communication and recovery at your request. The Operator does not use it for advertising.
5. Cookies
The web application uses first-party cookies required for login sessions, token renewal, multi-factor handoff, and cross-site request forgery protection. Authentication cookies are Secure, SameSite=Strict, and inaccessible to browser JavaScript where their function permits. The CSRF cookie must be readable by the web application so it can send the matching request header. The Service does not currently use advertising cookies or third-party analytics cookies. If optional analytics or advertising technologies are introduced, this Policy and any consent mechanism will be updated as required by law.
6. Sharing and public links
A recipient does not need an account to use a share. Anyone who possesses a share identifier can request the encrypted share envelope and related operational fields, including share and file identifiers, the public key-derivation salt, encrypted envelope, and encrypted file size, before entering the share password. The filename, plaintext digest, File Encryption Key, download token, and file contents remain protected inside client-encrypted data until a recipient supplies the correct password to a trusted client. Share access can create security and access-count records. Share owners are responsible for controlling the URL and password and for revoking shares when appropriate.
7. Service providers and disclosures
The Operator may use infrastructure providers to host the application, database, encrypted object storage, backups, domain-name service, TLS certificates, network delivery, support email, and payment processing. Those providers receive only the information needed for their role. An object-storage provider receives encrypted blobs, object identifiers, and padded sizes, but not Arkfile decryption keys. Provider identity and location depend on how this deployment is configured.
The Operator may disclose available account or operational information when reasonably necessary to comply with applicable law, a valid court order, or another binding legal process; protect the rights, safety, and security of users, the Operator, or the public; investigate abuse; or establish or defend legal claims. Because the Operator does not possess your passwords or client-side keys, the Operator generally cannot disclose plaintext file contents or client-encrypted metadata. The Operator does not sell personal information and does not share it for cross-context behavioral advertising.
8. International transfers
The Operator and its infrastructure providers may process information in countries other than the country where you live. Where UK or EU law applies and information is transferred internationally, the Operator will rely on an applicable adequacy decision, approved contractual protections such as standard contractual clauses, or another lawful transfer mechanism where required.
9. Retention and deletion
The Operator keeps account and encrypted storage records while your account is active and as needed to provide the Service. Deleting a file is intended to remove its active metadata and stored encrypted object, subject to temporary copies in backups, replication, provider deletion processes, and legal holds. Session cookies and tokens expire according to their configured lifetimes. Security, administrator, and billing records may be retained after content or account deletion for security, accounting, fraud prevention, dispute resolution, compliance, and legal obligations. Optional contact information is retained until you delete it, your account is closed and it is no longer required, or law requires longer retention. The Operator will not keep personal information longer than reasonably necessary for these purposes.
10. Security and important limits
Arkfile uses client-side encryption, OPAQUE authentication, required multi-factor authentication, encrypted server-held user secrets, access controls, transport encryption, and privacy-preserving rate limiting. No system is completely secure. A compromised device, weak or disclosed password, malicious browser extension, or attacker controlling the live web origin could expose information during future use. Client-side encryption cannot protect information after a malicious client captures it. You should use strong unique passwords, protect your second factor and backup codes, verify the service origin, and keep independent backups where appropriate.
11. Your privacy rights
Depending on where you live, you may have rights to request access to, correction of, deletion of, restriction of, or portability of personal information, to object to certain processing, and to complain to a data-protection authority. You may delete optional contact information and individual files through the Service and may contact the Operator about other requests. The Operator may need to verify that a request concerns your account. These rights can be subject to legal exceptions, including security, accounting, freedom of expression, legal claims, and records the Operator must retain.
The Operator can provide only information actually available to the server. The Operator cannot recover or provide a forgotten password, an Account Key, an unwrapped File Encryption Key, or plaintext from client-encrypted files or metadata. UK residents may complain to the Information Commissioner's Office, EU residents may complain to their local supervisory authority, and residents of California and other US states may exercise applicable access, correction, deletion, and portability rights. The Operator will not discriminate against you for exercising a privacy right protected by law.
12. Children
The Service is not directed to children, and account holders must be at least 18 years old or the age of legal majority where they live. The Operator does not knowingly collect personal information from children under 13. If you believe a child has provided personal information contrary to this Policy, contact the Operator so the account can be reviewed and appropriate action taken.
13. Changes to this Policy
The Operator may update this Policy by publishing a revised version on this page and changing the effective date. If a change materially affects existing users, the Operator will provide reasonable notice through the Service when practical.
14. Contact
Privacy questions, rights requests, account-closure requests, and complaints should be sent to the administrator of arkfile.net.
Administrator contact: arkfile[at]pm.me / arkfile[at]tutanota.com