TeraAirlift

Security & Privacy

What Should a File-Transfer Service's Privacy Policy Say About Your Files?

A reader checklist for finding how uploaded files and related personal data are handled without treating general guidance as legal advice.

Richard Parker9 min read

Three thick document folders stacked on a white surface.

A useful file-transfer privacy policy should explain what the service handles, why it handles it, who can access it, where other providers participate, how long each data category remains, what deletion means, how rights requests work, and which security practices protect the data. If those answers are vague, obtain them in contractual documentation before sending sensitive files.

A privacy policy is a disclosure, not proof that controls operate as described. Use this checklist as educational information, not legal advice or a compliance certification.

1. What data does the service collect?

The policy should distinguish at least:

  • payload content: uploaded files, folders, archives, previews, and derivatives;
  • transfer metadata: names, sizes, hashes, sender, recipient, timestamps, status, and expiration;
  • account data: identity, organization, contact, role, and authentication records;
  • device and network data: IP address, operating system, application version, and diagnostics;
  • operational records: logs, support messages, security events, and audit history; and
  • commercial data: plan, usage, invoice, and payment-related records.

“We collect information you provide” is not enough for a service processing client files. Determine whether the provider inspects content for malware, abuse, indexing, previews, support, analytics, or artificial-intelligence training. Ask whether filenames and hashes are treated differently from payload bytes.

2. Why is each category processed?

Look for a purpose tied to every category: delivering the file, authenticating a recipient, preventing abuse, supporting the customer, meeting a legal obligation, or improving the product. Watch for open-ended wording that permits unrelated reuse.

In an EU/EEA context, GDPR Article 5 includes lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability. Article 28 governs fact-specific controller-processor relationships and contractual requirements. A reference to these articles is a starting point for review—not evidence that the service, customer, or transfer is GDPR compliant.

3. What ownership and secondary uses apply?

Read the privacy policy with the terms it incorporates. It should distinguish customer ownership from the limited license needed to store, process, and deliver files. Ask separately whether payloads or metadata may be sold, shared for cross-context advertising, used to train AI, or reused under a broad “improve our services” purpose. Record the document’s effective date and how material changes are announced.

California’s CCPA page illustrates jurisdiction-specific disclosure and rights questions around collection, use, sale or sharing, deletion, correction, limitation, opt-out, and non-discrimination. Applicability depends on statutory definitions, thresholds, data, and business conduct; it is not a universal checklist or a conclusion that a vendor is covered. The FTC has also warned that surreptitious, retroactive changes allowing more permissive data use, such as AI training, may be unfair or deceptive under U.S. law.

4. Who receives or can access the data?

The policy should describe workforce access, recipients selected by the customer, subprocessors, affiliates, and disclosures required by law. Ask:

  1. Is support access to payloads possible, and under what authorization and logging?
  2. Is access role-based and limited to a documented business need?
  3. Are subprocessor names, functions, and processing locations available?
  4. How are customers notified of subprocessor changes?
  5. Can an administrator access or transfer a departing user’s files?
  6. Can a recipient make a local copy that the service can no longer revoke?

The privacy policy may not contain every contractual answer. Data-processing terms, a subprocessor page, security documentation, and an order form may control different parts of the relationship.

5. Where is data processed?

Ask for the production storage region, metadata region, backup locations, support-access locations, and transfer mechanisms that apply to your account. Development diagrams and a cloud provider’s global footprint do not identify a particular production deployment.

TeraAirlift does not currently publish a final production provider, region, or subprocessor list in repository-supported marketing truth. Azure and other provider controls can illustrate due-diligence questions, but they must not be presented as proof of TeraAirlift’s production architecture.

6. How long is each category retained?

The policy should avoid one undifferentiated retention sentence. Payloads, transfer metadata, logs, backups, recycle bins, legal holds, deleted-user content, and ended-subscription data can follow different clocks.

FTC guidance for U.S. businesses recommends knowing what personal information is held, keeping only what is needed, protecting it, disposing of what is no longer needed, and documenting necessary retention. It does not prescribe one universal retention period for every file-transfer service.

Ask what starts each clock, whether an administrator can shorten it, what happens after expiry, how backups age out, and which records survive for security or legal reasons. TeraAirlift has no published final retention period or deletion SLA, so do not infer one from an interface default or a cloud storage tier.

7. What rights and choices are available?

The policy should identify contact methods and the applicable processes for access, correction, deletion, objection, portability, or complaint. Rights vary by jurisdiction, role, data type, and exception. Confirm whether the business customer or the service handles a recipient’s request and how identity is verified before data is disclosed or deleted.

Account settings are not always legal-rights workflows. Deleting a transfer in a console may not address support records, backups, or information controlled by another organization.

8. How are legal demands handled?

Look for the standard the provider requires before disclosure, whether it narrows or challenges overbroad demands, whether it redirects enterprise requests to the customer, and when notice is given or legally prohibited. Transparency reporting is useful evidence, but another provider’s process does not establish this vendor’s practice.

9. What security statements are specific?

Prefer scoped descriptions over labels such as “military-grade” or “fully secure.” Ask about authentication, authorization, private-by-default sharing, encryption in transit and at rest, short-lived credentials, key responsibility, integrity checks, logging, incident notification, deletion controls, and independent assurance—then request evidence.

CISA’s SCuBA project publishes Microsoft 365 and Google Workspace configuration baselines. Its phishing-resistant MFA requirements are binding in the cited directive for covered U.S. federal civilian agencies; other organizations can use them as risk-based questions. They do not prove that a vendor implements those controls. The U.K. NCSC likewise recommends authenticated access, MFA, private-by-default resources, and carefully managed external sharing. Its guidance is risk-based and configuration-dependent.

TeraAirlift’s supported statements are narrower: the Windows console offers authenticated, linkless recipient delivery, short-lived storage access, SHA-256 upload/completion/download verification, and operational queue/history/logging. Removing emailed download links reduces one phishing surface; it does not remove phishing, endpoint compromise, misaddressed identities, or authorized copying. TeraAirlift does not currently claim phishing-resistant MFA, SOC 2, ISO, HIPAA, publisher verification, or compliance certification.

Use the security page to compare current product boundaries with the policy and contract you receive. Test the Windows client only after your legal, privacy, and security owners accept the documented processing model.

Pair this checklist with the guides to ownership terms, retention, and confidential external delivery.

Sources

Plan your next large-file transfer

Schedule a demo or download the Windows client to explore the TeraAirlift workflow.

End-to-end desktop clients — you send from the app; your recipient opens TeraAirlift and pulls from Available Downloads.