fa.to
Home About Hosted Docs Log in
hello@fa.to
Client-side encrypted

PRIVACY NOTICE

Private files.
Clear boundaries.

This notice explains what fa.to can and cannot see, and the limited account information needed to provide managed storage.

Effective 28 August 2026

Who we are

fa.to provides an Android application for encrypted SFTP storage and an optional managed storage service. For privacy questions or requests, email hello@fa.to.

What fa.to cannot see

Your vault passphrase is not sent to fa.to. File contents, filenames, folder information and thumbnails are encrypted on your Android device before upload. We do not hold the key needed to decrypt them and cannot recover a forgotten vault passphrase.

Information we process

For a managed account we process your email address and verification status, password hash, optional encrypted authenticator secret and hashed recovery codes, selected plan and location, subscription and payment status, storage usage, vault deployment identifiers, and security or support records. Our systems and hosting providers may also record ordinary request data such as IP address, time, browser or app version, and error details. We do not receive full card details from Stripe.

For a self-hosted vault, SFTP credentials and vault data go directly between your device and your chosen server. fa.to does not receive those credentials or files. Requests to our website or update service may still create ordinary server logs.

Why we use it

We use account and service information to create and operate your vault, authenticate you, provide support, prevent abuse, secure the service, measure capacity, process subscriptions, and meet legal or accounting duties. Where data protection law applies, these purposes are based on performing our contract, complying with law, and our legitimate interests in operating and protecting the service.

Payments and service providers

Payments and billing management are provided by Stripe. Stripe receives the payment and transaction information needed to provide those services and handles personal data under its own privacy terms. Transactional email is delivered through our configured mail provider, which receives the recipient address and message required to send verification, purchase, cancellation and security notices. We also use infrastructure providers to host the website, control plane and encrypted storage. They are given only the access needed to provide their service.

Locations and international transfers

Managed vaults are stored in the location you select. If that location is outside your country, encrypted vault data will be transferred there. Account and operational data may also be processed by service providers in other countries, using applicable contractual or legal safeguards where required.

Retention

We retain account and operational data only while needed to provide the service, resolve disputes, prevent fraud, and meet tax, accounting or legal requirements. When a hosted subscription ends, access may be suspended and the encrypted vault is normally scheduled for deletion after the period shown in your account. Backups and logs expire through their normal retention cycles. Stripe retains payment records under its own policy and legal duties.

Account deletion

You can request deletion at fa.to/delete-account or from the Android app. Billing and account access are cancelled immediately. The encrypted vault is permanently removed by the storage worker, then the fa.to user, subscription, deployment, credentials and app-login records are deleted. Limited transaction information may remain with Stripe, or be retained where required for tax, fraud prevention, dispute resolution or another legal obligation.

Cookies and analytics

fa.to uses essential session and security cookies required for sign-in and account protection. We use our self-hosted Umami service at stats.pixi.mg for lightweight, aggregate website analytics. It is not used for advertising or cross-site behavioural tracking. When the website starts an APK download, we also increase one aggregate counter for that app version. The download counter does not store an IP address, cookie, user agent or other visitor-level identifier, although analytics requests and ordinary web-server logs may still process technical request information for statistics, security and operations.

Your choices and rights

You can update or delete eligible account information by contacting us. Depending on the law that applies to you, you may have rights to access, correct, erase, restrict, object to, or receive a copy of your personal data. You may also complain to your local data protection authority. In the UK, this is the Information Commissioner's Office.

Legal requests and safety

We may preserve or disclose account, billing, connection, usage, or encrypted storage data when required by a valid legal process. Because we do not hold your vault key, we cannot provide decrypted file contents. We may act on accounts used unlawfully or to harm the service or others.

Changes

We may update this notice when the service or law changes. Material changes will be shown on the website or in your account. Questions can be sent to hello@fa.to.

© 2026 fa.to ยท Vault data is encrypted client-side.

Docs Privacy Terms Delete account hello@fa.to