Server-Side Encryption Architecture
BackupBox operates on strict Server-Side Encryption protocols. All files uploaded to BackupBox are encrypted at rest on secure cloud storage buckets using AES-256 and protected in transit via TLS 1.3 encryption.
Because stored payloads are protected with bucket-level encryption and token authentication:
- We cannot inspect, read, index, or decrypt your personal files.
- We have no password reset mechanism for custom folder passcode locks.
- No BackupBox employee, partner, or cloud server administrator can ever access your files.
Information We Collect
To register, authenticate, and manage your account and subscription, we collect limited personal information:
- Account Details: Your email address and basic profile info (e.g., name) when you register or sign in via Google, Apple, or Facebook.
- Transaction Records: Billing identifiers, subscription tier status, and basic invoice histories processed through our secure partner Stripe. We do not store or process raw credit card numbers.
- Analytical Logs: Device type, browser characteristics, and page response logs. This is strictly used to improve upload speeds and prevent server downtime.
What We Never Collect
Our commitment to user privacy means we explicitly do not collect or monitor:
- File Content: The raw, decrypted bits of your photos, documents, databases, or videos.
- Decryption Keys: Passcodes or cryptographic keys used to unlock your link sharing packages.
- Activity Tracking: Who you share links with, what files they download, or any details about your network traffic.
Data Expiry & Purging
Any files shared using our link-sharing tool are subject to automatic expiration. Based on your plan settings, links can be configured to expire in 1, 3, 7, 30, or 60 days.
Once a link sharing package expires:
- The associated download URLs become invalid immediately.
- The encrypted files are permanently deleted from Cloudflare R2 bucket networks.
- This purge is absolute and cannot be undone; no backups or cached copies remain on our systems.
Third-Party Processors
We use select third-party service providers to run our backend application safely. Each vendor is GDPR and CCPA compliant:
- Cloudflare R2: Secures and stores your encrypted data packages on global edge networks.
- Stripe: Handles our secure checkout sessions, subscription renewals, and upgrades.
- Firebase Auth: Provides secure authentication options (Google/Apple login protocols).
How to Delete Your Data
We believe you should have complete control over your data. You can delete your account and all associated records permanently at any time:
- Go to your **Dashboard Settings**.
- Select **Delete Account** from the account settings card.
- Confirm the deletion. This will immediately purge your user profile, billing connections, and delete every file in your cloud vault permanently.
Contact Our DPO
If you have questions about this policy, GDPR data rights, or zero-knowledge security, you can contact our Data Protection Officer directly:
privacy@backupbox.app