Your files stayon your side ofthe line.
FilePolish is built as a local file workshop. This policy explains the small amount of account, licence, feedback and website data that can cross the boundary—and the much larger category that never does: the files you work on.
Files and local processing
Images, PDFs, documents, audio and video opened in FilePolish are processed on your device. File contents, filenames, previews and finished outputs are not uploaded to FilePolish, Whop, Neon or our analytics systems.
You choose where finished files are saved. FilePolish protects the source file unless you deliberately choose an action that replaces it.
- Not collected
- File contents, filenames, folder paths, previews, extracted text, metadata read from a file, processing history and finished outputs.
Membership and licence data
FilePolish offers free tools and optional premium access. Whop processes the payment inside the FilePolish checkout; FilePolish receives a signed payment confirmation and manages access separately. To connect a desktop app, it creates a short-lived pairing code. You verify the purchase email on FilePolish and approve that specific computer; no reusable customer licence key is shown or entered.
Each paired desktop installation creates its own cryptographic identity. Its private signing key stays in Windows Credential Manager or macOS Keychain. FilePolish stores the matching public identifier, a user-visible device label, platform, seat number, activation status, last check and offline expiry so you can review and deactivate connected computers. One purchase currently permits up to two active desktop computers.
The desktop app may keep an entitlement record in the operating system credential vault for up to 30 days so premium tools can work offline. That local record can contain the edition, access status, purchase time, account email, device activation identifier and offline expiry date. Deactivating the computer or removing access clears that local credential when the app next checks online; it expires automatically if the app remains offline.
For purchase activation and web membership access, FilePolish uses a six-digit email code and essential session data. Our purchase register can store a buyer email, Whop user, membership and payment identifiers, product identifier, access status, purchase and event times, and a one-way event hash. Internal legacy licence records retain only a keyed one-way fingerprint, a short reference prefix and a derivation version—not a plaintext reusable key. FilePolish does not store the full Whop webhook payload.
Customer Pulse feedback
Customer Pulse is optional. If you send feedback, the record contains the score, product area, selected reason, surface, time received and any comment you choose to write.
The feedback table has no account ID, email, IP address, filename, file format, URL or processing event, and it is not joined to membership or analytics records. Avoid placing personal or confidential information in a free-text comment.
Privacy-preserving aggregate measurement
The public website keeps daily aggregate counters for a small fixed set of events, such as a landing-page view, checkout start or completed job. Attribution is reduced on your device to a broad source such as direct, search, social, email or campaign before the counter is sent.
These records contain no visitor identifier, full referrer, URL, query string, IP field, file fact or person-level history. The installed desktop app does not send these website acquisition counters.
Data kept on your device
FilePolish can use local browser or app storage for your theme choice, saved batch recipes and essential sign-in state. The desktop identity and temporary entitlement described above are kept in the operating system credential vault. This information stays on the device unless access needs an online check.
You can clear website storage in your browser. From Member Access you can deactivate a connected computer, and the desktop app can remove its own secure activation. Uninstalling the application removes its ordinary local app data; your operating system may manage credential-vault entries separately.
Services that help operate FilePolish
We use service providers only for defined jobs:
- Whop securely processes the embedded checkout and sends signed payment-status updates to FilePolish.
- Neon provides email-code authentication and the private database for entitlement, licence, aggregate counter and anonymous feedback records.
- Vercel hosts the public website and server endpoints.
- Microsoft distributes the Windows app and may process Store diagnostics under your Microsoft settings.
- Google Fonts and jsDelivr may deliver public font or language-model resources requested by the web version. The file being processed is not sent with those requests.
These providers can process technical request information under their own terms. Their infrastructure may be located outside your country. Where applicable, we rely on the provider's contractual safeguards and the necessity of delivering the service you requested.
Retention and security
Membership and entitlement records are retained while needed to provide access, handle refunds or disputes, meet accounting obligations and protect the service. Anonymous feedback and daily aggregate counters are retained while useful for improving FilePolish. Local settings remain until you change or clear them, or uninstall the app.
Data sent to FilePolish is encrypted in transit. Access to purchase and feedback records is restricted. No security measure is absolute, so we deliberately limit what the service is able to receive in the first place.
Your choices and rights
You may ask to access, correct or delete personal data connected to your FilePolish membership. Depending on where you live, you may have rights to object, restrict processing, receive a portable copy or complain to a data-protection authority.
To make a privacy request, use the FilePolish support contact shown on your purchase receipt. We may need to verify the purchase email before changing a membership or licence record. You can use the file-processing tools without sending us the files involved in your request.
Children and policy changes
FilePolish is a general-purpose utility and is not directed to children under 13. We do not knowingly collect personal information from a child without the authorization required by local law.
If this policy changes materially, the effective date above will change and the new version will be posted at this address before it applies. FilePolish is published by BorkLma.
