Privacy Policy
Effective June 25, 2026 · v1.0 · Beta
This policy explains how Genmod Pty Ltd (ABN 43 690 110 617) (“Filebot”, “we”, “us”) collects, uses, stores, and shares information when you use the Filebot platform. As an Australian entity, we handle personal information in line with the Australian Privacy Principles (APPs) and, where applicable, the EU/UK GDPR and US state privacy laws. Because of how Filebot is built, your file content is handled differently from typical SaaS data — please read “How file content is handled” below.
1. Controller vs. processor
We act as a controller for account, billing, and usage data (your name, email, organization, API-key metadata, usage events, and support correspondence). We act as a processor on your behalf for the file content and end-user data inside the files you upload and process — you are the controller of that content.
2. Information we collect
You provide: account data (name, email, organization, authentication credentials — we use magic-link and OAuth sign-in and do not store passwords for those), plan and subscription state (card data is handled by our payment provider; we do not store full card numbers), and anything you send us via support.
Generated by your use: pipeline and run metadata; file object metadata (storage key, size, content type, a content hash, retention policy, owning organization); metered usage events; API-key metadata (we store hashed key material, not the raw secret); and any storage credentials you connect, which are encrypted at rest with AES-256-GCM using a key held outside the database.
Collected automatically: technical logs (IP, user-agent, request paths, timestamps) for security and debugging; strictly-necessary session cookies; and product analytics via PostHog (see our Cookie Policy).
3. How file content is handled
Filebot is architected to minimize our exposure to your file content. Files upload directly to Cloudflare R2 object storage via short-lived presigned URLs — file bytes do not pass through our API layer. During a run, content is read from storage into worker memory transiently to perform the transformation you requested, and results are written back to storage. Managed stored artifacts are retained for a default of 30 days (configurable per pipeline), and intermediate and uploaded files are deleted approximately 24 hours after a run completes, by an hourly garbage-collection sweep.
If you run the Enterprise Agent in your own infrastructure, the relevant processing happens on your compute and we receive only run and step metadata. Filebot is a proprietary, hosted service; there is no open-source or self-hostable distribution.
4. How we use information
To provide, operate, secure, and maintain the service and run your pipelines; to authenticate users and manage organizations, API keys, and sessions; to meter usage and process billing; to send transactional emails (via Resend); to detect and investigate fraud, abuse, and security incidents; to provide support; and to comply with legal obligations. We do not sell personal information. For EEA/UK users we rely on contract, legitimate interests, consent (where required, e.g. non-essential cookies), and legal obligation.
5. AI processing
Some pipeline steps can invoke AI models. All processing compute runs on Cloudflare (Workers and Containers) — Cloudflare is the compute tier, not an AI provider. When you use a cloud AI step, content is routed to OpenAI (OCR, image description, and Whisper transcription) or Deepgram (speech-to-text) — the only third-party AI providers wired into the platform — solely to perform the requested operation. When you run the Enterprise Agent, local models can be used and no third-party AI provider is involved.
6. Subprocessors
We use the following subprocessors to provide the cloud service:
- Cloudflare — edge/worker compute and R2 object storage (file content, metadata, logs).
- Neon — managed Postgres for application metadata and encrypted credentials (not file content).
- Polar — billing and Merchant of Record (billing identifiers; no file content).
- Resend — transactional email (recipient address and email content).
- PostHog — product analytics, EU-hosted, consent-gated (usage telemetry and IP; no file content).
- OpenAI and Deepgram — cloud AI steps, only when you enable one.
7. International transfers
Our infrastructure is located primarily in Australia (database in Sydney; object storage region-hinted to Oceania), with certain subprocessors operating globally. Where we transfer personal data out of the EEA/UK/Switzerland, we rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
8. Data retention
File content is retained per the run’s retention policy (see “How file content is handled”), then deleted. Account data is retained for the life of your account and a period afterward as required for legal, tax, and accounting purposes. Provider-level backups may retain residual copies for a limited window after deletion from the live system.
9. Security
We use measures appropriate to the risk, including TLS in transit; AES-256-GCM encryption at rest for stored credentials with the key held outside the database; presigned, short- lived upload URLs so file bytes bypass the API; scoped API keys with hashed secret storage; organization-scoped access control; and virus scanning of uploaded files. No method of transmission or storage is completely secure.
10. Cookies & analytics
We use strictly-necessary session and authentication cookies, and product analytics from PostHog (EU-hosted). Because analytics is non-essential, it is gated behind consent: a cookie banner lets you accept or reject non-essential analytics before it loads. We do not run third-party advertising trackers.
11. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to complain to a supervisory authority (Australian users may complain to the Office of the Australian Information Commissioner). Where we act as a processor of file content, requests from data subjects within those files should be directed to the organization that controls them. To exercise rights regarding data we control, contact privacy@filebot.dev.
12. Children & changes
The service is not directed to children under 16, and we do not knowingly collect their personal data. We may update this policy; material changes will be communicated via the service or email and the effective date will change. Questions: privacy@filebot.dev (see also our Terms of Service).