Privacy
Privacy Policy
This notice explains how personal data is processed when you use FlakaCloud accounts, private cloud storage, sharing, referrals, Family storage, security features, and paid subscriptions.
Effective July 22, 20261. Controller and contact
FlakaCloud is the controller responsible for FlakaCloud within the meaning of the EU General Data Protection Regulation (GDPR).
Privacy requests and questions can be sent to support@flakacloud.com. We may request information reasonably necessary to verify your identity before fulfilling a request.
2. Data we process
Account and profile data
Username, email address, email-verification state, password hash, account status, role, account creation time, plan, storage allowance, bonus storage, and profile settings. FlakaCloud does not store your plain-text password.
Files and cloud content
Photos, videos, original filenames, stored filenames, file type, size, upload time, technical media metadata, thumbnails, album covers, albums, shared folders, favorites, trash state, and storage usage. Content may incidentally contain personal data or special-category data chosen by the uploader.
Sharing and social features
Friend requests, friendships, album and shared-folder memberships, invitations, access states, Family membership and storage allocations, referral invitations and rewards, and the usernames or email addresses required to deliver those features.
Subscription and payment records
Plan, price identifier, Stripe customer and subscription identifiers, subscription status, renewal and cancellation dates, invoice identifiers, amount, currency, payment status, refunds, and limited payment-method descriptors returned by Stripe. Full card numbers and card security codes are entered with and handled by Stripe, not stored by FlakaCloud.
Device, security, and communications data
Session identifiers, device labels, hashed IP addresses, hashed user-agent details, login timestamps, authentication attempts, security and administrative audit events, upload validation results, malware-scan results when enabled, support correspondence, and transactional email delivery status.
3. Purposes and legal bases
- Contract and pre-contract steps (Article 6(1)(b) GDPR): registering and verifying accounts; storing, organizing, displaying, downloading, and sharing files; providing friends, referrals, Family storage, subscriptions, account recovery, support, and service communications.
- Legal obligations (Article 6(1)(c) GDPR): accounting, tax, payment, consumer-protection, regulatory, law-enforcement, and data-protection duties.
- Legitimate interests (Article 6(1)(f) GDPR): securing accounts and infrastructure; preventing fraud, referral abuse, malware, unauthorized access, and payment abuse; diagnosing faults; enforcing the AGB; establishing or defending legal claims; and improving reliability. We balance these interests against user rights and expectations.
- Consent (Article 6(1)(a) GDPR): only where FlakaCloud specifically asks for optional consent. Consent may be withdrawn prospectively at any time without affecting earlier lawful processing.
Data required for registration, storage, sharing, security, or billing must be provided to use the relevant feature. Without it, FlakaCloud may be unable to create the account, deliver files, complete a payment, or provide support.
4. Your content and sharing
Original media is kept in private server storage and is delivered through permission-checked routes. FlakaCloud creates thumbnails or previews to display content efficiently and may inspect file structure or scan uploads for malicious content.
When you share an album or folder, add a friend or Family member, or accept an invitation, the relevant username, membership information, and selected content become available to the people involved. Those recipients may view or download content according to the access granted. Avoid sharing content with anyone who should not receive it.
5. Recipients and processors
- Hetzner Online GmbH: production server, database, network, and file-storage infrastructure.
- Stripe group companies: checkout, subscriptions, payments, fraud prevention, billing portal, invoices, refunds, and payment records.
- Microsoft: delivery of verification, password, security, Family, support, and billing emails through the configured Microsoft email service.
- Other users: only where sharing, friendship, Family, referral, or invitation features require it.
- Authorities and professional advisers: where legally required or necessary to protect rights and pursue or defend claims.
Processors receive only the data needed for their task and are bound by applicable data-protection obligations. FlakaCloud does not sell personal data and does not use cloud content for third-party advertising.
6. International transfers
Primary hosting is configured with a European provider. Stripe and Microsoft operate internationally, so limited data may be processed outside the European Economic Area. Where required, transfers rely on an adequacy decision, the EU Standard Contractual Clauses, the EU-US Data Privacy Framework for certified recipients, or another lawful safeguard under Articles 44 to 49 GDPR.
Provider information is available in the Stripe Privacy Policy, the Microsoft Privacy Statement, and the Hetzner Privacy Policy.
7. Cookies and local storage
FlakaCloud uses strictly necessary session and security cookies to keep users signed in, protect forms, remember trusted-device choices, and preserve essential upload state. These technologies are required to provide the service and are not used for behavioral advertising.
The application does not currently operate its own advertising or cross-site analytics profile. Browser or provider technologies used on an external Stripe or Microsoft page are governed by that provider's notice.
8. Retention and deletion
- Active account and content: kept while the account exists and the data is needed to provide the requested service.
- Trash: deleted media remains recoverable for up to 3 days unless permanently deleted sooner, then the application removes the database record, original, thumbnail, and related cover references.
- Verification and reset credentials: verification codes expire after 15 minutes and password-reset links after 30 minutes. Expired or replaced credentials are no longer valid.
- Referral invitations: pending invitations normally expire after 30 days. Records needed to prevent duplicate rewards or fraud may remain while the referral program or a related account remains active and as necessary to protect the service.
- Sessions and security logs: retained for the life of the account or as long as reasonably needed for authentication, fraud prevention, incident investigation, abuse control, and legal claims. Revoked sessions no longer authorize access.
- Billing and tax records: retained for the statutory period, generally 7 years from the end of the relevant calendar year under Austrian tax-record rules, and longer where a pending proceeding requires it.
- Account deletion: account content and active service records are deleted or anonymized unless retention is required by law, necessary for payment records, security evidence, unresolved disputes, or legal claims. When a user permanently closes an account, FlakaCloud retains an irreversible hash of the normalized email address to enforce the disclosed permanent re-registration block; the hash is not used to contact the former user. Copies may remain temporarily in protected rotating backups until overwritten.
Retention may be extended where litigation, a security incident, a legal hold, or a binding authority request requires it. When continued identification is unnecessary, data is deleted or irreversibly anonymized.
9. Security
Measures include password hashing, email verification, secure session cookies, CSRF protection, rate limits, role and ownership checks, private file storage, permission-checked media delivery, restricted MIME handling, upload validation, audit logging, and security updates. Media processing and malware controls may reject or quarantine unsafe files.
No internet service can guarantee absolute security. Use a unique password, protect your email account and devices, review active sessions, and keep an independent copy of irreplaceable files. Report suspected unauthorized access immediately.
10. Automated controls
Automated rules may temporarily rate-limit login or registration attempts, reject invalid or suspicious uploads, enforce storage limits, identify potential referral abuse, or block access after a security event. These controls protect the service but are not used to make decisions producing legal or similarly significant effects solely through automated profiling. Contact support if you believe a control acted incorrectly.
11. Your GDPR rights
Subject to the legal conditions, you may request access, correction, deletion, restriction, data portability, or object to processing based on legitimate interests. Where processing is based on consent, you may withdraw that consent. You also have the right not to be subject to certain solely automated decisions.
Send requests to support@flakacloud.com. FlakaCloud normally responds within one month; complex or numerous requests may lawfully take up to two additional months. Some rights are limited where retention or processing is required by law or necessary to protect another person's rights.
You may lodge a complaint with the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, Austria, or with the supervisory authority of your habitual residence or workplace.
12. Changes to this notice
This notice may be updated when features, providers, security measures, or legal requirements change. The effective date above identifies the current version. Material changes will be communicated in the application or by email where legally required. Earlier processing remains governed by the notice and law applicable at that time.