Privacy Policy
Effective Date: September 2026 • Zero-Knowledge Architecture
Zero Key Knowledge
We hold zero master keys. Encryption keys are generated on your device and never leave your hardware.
No Content Scanning
We do not scan, index, parse, or train machine learning models on your documents, photos, or files.
Subpoena Immunity
Because we do not possess decryption keys, we cannot unlock or decrypt files under any third-party request.
1. Non-Possession of Customer Data
Unlike legacy cloud storage providers (such as Google Drive, Dropbox, Box, or Microsoft OneDrive), Foxcolab Drive is designed from the ground up so that our servers receive strictly encrypted data. When you upload any file, folder hierarchy, or metadata, your device executes local encryption using keys created from your password. Foxcolab engineers, system administrators, and infrastructure partners possess neither the keys nor the technical capability to view or unlock your stored files.
2. Data We Collect and Store
To maintain service uptime and prevent abuse, we collect only the minimal data required for technical operation:
- Account Identity: Your registered email address and basic profile settings.
- Encrypted Vault Data: Unreadable encrypted blocks stored in high-availability secure storage.
- Billing Information: Payment processing is managed via PCI-DSS compliant third-party gateways (Stripe/Razorpay). We never store raw credit card numbers.
- Zero Behavioral Tracking: Zero third-party analytics trackers, zero advertising pixels, and zero data brokers.
3. Private Link File Sharing
When you generate a private share link, the key to unlock the file is kept inside the private link on the recipient's device. Web browsers do not send link keys to our web servers, ensuring Foxcolab cannot inspect or access shared documents.
4. Data Retention & Permanent Deletion
When you permanently delete a file or empty your Trash vault, the associated storage pointers are severed immediately and the data blocks are purged during regular storage compaction cycles. Because encryption keys were held only on your device, deletion is permanent and irreversible.
