You generally do not give up ownership merely by uploading a file, but “you own it” is not the end of the analysis. A file-transfer service normally needs a license to host, copy, process, transmit, display metadata, and deliver content. Your contract may also allocate account control, deletion authority, feedback rights, dispute procedures, and responsibility for third-party material.
Read the actual terms that govern your plan and jurisdiction. This article provides educational questions, not legal advice or an interpretation of any particular contract.
Separate ownership from permission
Ownership answers who holds rights in the content. A license answers what another party may do with those rights. A service can say that users retain ownership while also receiving a license broad enough to operate the product.
Some operational permissions are unavoidable. A transfer service may need to:
- store temporary and redundant copies;
- transmit bytes across networks;
- create previews or technical derivatives;
- scan for malware or prohibited content;
- expose the package to authorized recipients;
- use subprocessors for hosting, support, or communications; and
- retain limited records for security, billing, disputes, or legal obligations.
The useful question is not simply “Is there a license?” Ask whether it is limited by purpose, duration, audience, sublicensing, and termination. Compare “only as needed to provide the service” with language permitting unrelated promotion, model training, or indefinite commercial reuse.
Compare the current document, not a remembered controversy
Major providers’ published terms illustrate the distinction as of their stated dates:
- Dropbox’s terms, effective January 7, 2025, say “Your Stuff is yours” while granting permissions needed to host, back up, share, scan, and provide features.
- Microsoft’s Services Agreement, published July 30 and effective September 30, 2025, says it does not claim ownership of user content.
- Google’s terms, effective July 30, 2026, leave ownership with the user but describe a worldwide, non-exclusive, royalty-free operating license, automated analysis, and limited sublicensing.
- Adobe’s terms, effective October 3, 2025, retain user ownership, separate its operating license from opt-out Content Analytics, and state that user content is not used to train generative AI except under the separate Adobe Stock contributor agreement.
- WeTransfer’s terms, updated August 3, 2026, retain user or licensor ownership and state that content is not used to train AI.
These are neutral snapshots, not rankings. Consumer terms, enterprise agreements, data-processing addenda, and negotiated orders may differ. Recheck the governing document and effective date before relying on any clause. The FTC has separately warned that quietly making terms more permissive for uses such as AI training may be unfair or deceptive under U.S. law; that guidance does not decide a private contract.
Confirm that the sender has the necessary rights
Owning a hard drive or controlling an account does not prove ownership of every file on it. Client footage, commissioned designs, music, talent releases, survey data, building models, and confidential business records may be governed by employment terms, licenses, professional duties, or a statement of work.
Before upload, confirm that the sender is authorized to use the chosen service, storage location, recipients, and processing chain. A vendor’s terms often require the customer to warrant that uploaded content does not violate law or third-party rights. That clause can shift risk even when the customer retains ownership.
Identify who controls the account
Ownership of content and control of the service account can diverge. An employee may upload client property into an individually administered account; a contractor may leave; an administrator may suspend a user; or a subscription may end.
Ask:
- Is the contract held by the individual, employer, agency, or client?
- Can organization administrators access, export, transfer, suspend, or delete user content?
- What happens to files when a user leaves or the subscription ends?
- Can the customer recover content during a grace or recycle-bin period?
- Which party can revoke recipient access and request deletion?
- Are legal holds, disputes, or abuse investigations exceptions?
Microsoft’s documentation illustrates why event scope matters. A deleted user’s OneDrive can be configured for retention from 30 to 3,650 days, with a 30-day default, but Microsoft separately documents recycle-bin, retention-policy, active-deletion, and subscription-termination processes. It would be inaccurate to generalize those mechanisms as “Microsoft keeps every file for 30 days.”
Read sublicensing and subprocessor language together
A service may need to sublicense limited rights to infrastructure and support providers. The privacy notice or data-processing terms should identify the categories or list of subprocessors, the purpose of processing, and how changes are communicated.
For EU/EEA personal data, GDPR Article 28 requires fact-specific controller-processor analysis, sufficient guarantees, and a binding contract with specified processing terms. Article 5 includes purpose limitation, data minimization, storage limitation, and accountability. These provisions do not decide copyright ownership, and citing them does not certify a service as GDPR compliant. Organizations should obtain advice from qualified counsel for their roles, jurisdictions, and data.
Check termination, deletion, and export
Look for separate answers to four events: deleting a transfer, deleting an account, ending a paid plan, and receiving a legal deletion request. Determine whether deletion is immediate or queued, whether recoverable copies remain, when backups age out, what metadata or logs survive, and what can be exported.
Keep product controls distinct from legal rights
Security features can enforce the selected account policy, but they do not rewrite the underlying contract. Authenticated, linkless delivery can reduce reliance on forwardable emailed URLs. Expiration and revocation can narrow future access. Neither mechanism retrieves copies an authorized recipient already downloaded.
TeraAirlift’s current repository-supported behavior includes a Windows desktop console, authenticated recipient delivery without emailed download links as the primary workflow, short-lived storage access, SHA-256 integrity verification, and queue, history, and logging visibility. TeraAirlift’s final public Terms of Service are not present in repository truth, so this article makes no contractual promise about ownership, sale, advertising, AI training, or license scope. The product controls are not statements about copyright ownership, legal compliance, a final retention period, production region/provider, or assurance certification.
Before uploading valuable or regulated material, save the governing terms and privacy notice, record their effective dates, identify any negotiated order form or data-processing agreement, and ask counsel to resolve conflicts. Review the service’s security boundaries and test the current Windows delivery workflow under your organization’s account controls.
Then examine the service’s privacy disclosures, retention lifecycle, and underlying cloud-upload mechanics.
Sources
- EUR-Lex — General Data Protection Regulation, including Articles 5 and 28
- Dropbox — Terms of Service
- Microsoft — Services Agreement
- Google — Terms of Service
- Adobe — General Terms of Use
- WeTransfer — Terms of Service
- FTC — Quietly Changing Your Terms of Service Could Be Unfair or Deceptive
- Microsoft — Set OneDrive retention for deleted users
- Microsoft — Data retention, deletion, and destruction overview
- FTC — Protecting Personal Information: A Guide for Business
- NCSC — Using SaaS securely


