Legal
Privacy Policy
Last updated: September 18, 2026
APULODI (“we”, “us”) operates the file infrastructure service at apulodi.dev. This policy explains what we collect and why — in plain language.
What we collect
- Account data — your name, email address and organization membership, collected when you sign in with a magic link.
- Your files — the objects you upload, stored in a private cloud bucket. Only you (and the teammates you invite, and anyone you explicitly share a public link with) can access them.
- Usage data — aggregated counts of uploads, downloads, storage and bandwidth per project, used for metering, quotas and billing.
- Operational logs — request logs kept briefly for security and reliability.
What we do NOT do
- We do not sell your data. Ever.
- We do not read, index or analyze the contents of your files, except to execute transformations you explicitly request (e.g. thumbnails, transcodes).
- We do not run third-party advertising or tracking scripts.
How data is protected
- Files are stored in a private bucket; delivery is via short-lived signed URLs or opt-in public CDN URLs built from unguessable identifiers.
- API access is via scoped project keys; only a SHA-256 hash of each key is stored.
- Traffic is encrypted in transit (TLS) everywhere.
Data retention & deletion
Deleting a file removes it from listings immediately and purges the stored object after a short grace window. Deleting your account deletes your metadata; you can delete all stored files beforehand from the dashboard.
Contact
Questions about this policy: hello@apulodi.dev