Privacy Policy
How Swarmfile collects, uses, and protects personal data when you use our website, software, and hosted service.
Last updated: 5 October 2026
This Privacy Policy explains how Mirrexa US LLC, a Wyoming limited liability company (“Swarmfile,” “we,” “us,” or “our”), with its principal office at 30 N Gould St Ste R, Sheridan, WY 82801, United States, handles personal data in connection with our websites, desktop and command-line applications, and hosted control-plane and storage services (together, the “Service”). It should be read alongside our Terms & Conditions.
For Customer Content and other personal data submitted to the Service by an organization, that organization generally decides why and how the data is processed and acts as controller; we process it on the organization’s instructions. We act as controller for data we use for our own purposes, such as account administration, billing, security, legal compliance, and direct communications. Your organization’s own privacy notice may also apply.
1. Data we collect and where it comes from
- Account and identity data - name, email address, organization, hashed credentials, membership and role information, sign-in records, and records of accepting our legal terms. If you use an identity provider, we receive the attributes it releases, such as an email address and subject identifier.
- Commercial and billing data - plan, seat count, usage, subscription status, billing contact details, and transaction identifiers. Stripe handles payment-card details; we do not store full card numbers.
- Customer Content and collaboration data - files you store or stream and associated names, sizes, versions, permissions, comments, share recipients, activity events, and project configuration.
- Device, usage, and security data - IP address, network and approximate location attributes supplied by our infrastructure provider, user agent, device and platform information, session and audit records, feature usage, connectivity diagnostics, error reports, and fraud or abuse signals.
- Support and contact data - information you provide in sales, support, privacy, or other communications.
We receive this data from you; your organization, its administrators, and other collaborators; your browser, device, and Swarmfile software; identity providers and integrations you choose; and operationalproviders such as Stripe and Cloudflare. Customer Content may contain personal or sensitive data chosen by you or your organization. Please do not submit data unless you are authorized to do so.
2. How we use data
- to provide, maintain, secure, and improve the Service;
- to authenticate users, enforce permissions, and coordinate the distribution of data between your machines and our infrastructure;
- to process payments and manage your subscription;
- to detect, prevent, and respond to fraud, abuse, security incidents, and violations of our Terms (including automated controls such as ransomware quarantine and rate limiting);
- to communicate with you about your account, service changes, security notices, and support requests; and
- to comply with legal obligations and enforce our agreements.
3. Legal bases for processing
Where the GDPR, UK GDPR, or similar laws apply, we rely on performance of a contract to provide and administer the Service; our legitimate interests in operating, securing, supporting, and improving the Service, preventing abuse, and protecting legal rights; compliance with legal obligations; and consent where the law requires it for a particular activity. You may withdraw consent at any time, without affecting earlier processing. When we act as a processor, the relevant organization determines the legal basis.
4. How we disclose data
We do not sell personal data, share it for cross-context behavioral advertising, or use it for targeted advertising. We disclose data as needed:
- to service providers, currently including Cloudflare for hosting, storage, network security, and optional Turnstile bot detection; Stripe for payments and subscription management; Postmark for transactional email; n0 (the iroh relay network) for NAT traversal and peer discovery when two machines can't connect directly, which sees connection metadata; Google Analytics for aggregate analytics on our marketing and documentation pages (never on public project pages, Explore, the signed-in dashboard, or the desktop app); Google Fonts for web fonts, which load sitewide and carry the page URL as referrer; and GitHub for distribution of the git-LFS agent and release artifacts, which sees download metadata;
- to your organization and people you choose, including administrators, collaborators, peers, share-link visitors, and email-share recipients, according to your settings;
- to customer-configured providers, such as identity providers, storage providers, and webhook or other integrations, when an organization enables them;
- where required by law or to protect our rights, users, or the public; and
- in connection with a corporate transaction, such as a financing, merger, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections.
5. Content visibility and encryption
How Swarmfile can access file content depends on the product mode you choose. In managed-encryption modes, the Service may decrypt content in memory to provide authorized features such as transfer or preview. In end-to-end encrypted modes, we are not intended to have the key needed to read file contents. Free-plan public projects, public links, and content you deliberately share are designed to be accessible to their intended recipients and should not be treated as private. Encryption does not prevent recipients from copying data they are authorized to view.
6. International transfers and residency
We are a US company and we and our providers may process data in the United States and other countries. Where required, we rely on an adequacy decision, standard contractual clauses, or another lawful transfer mechanism. You may contact us for information about the safeguards relevant to your data.
A region or residency selection applies only to the project data and metadata identified by the Service as resident in that region. It does not necessarily cover account, billing, support, communications, fraud-prevention, or security data, or processing by a provider or integration you choose. See our security page for deployment options.
7. Retention and deletion
We retain account data while an account or organization is active and Customer Content according to the organization’s lifecycle, trash, version, and deletion settings. After deletion, copies may remain for a limited period in processing queues, caches, replicas, and security logs before being overwritten or de-identified. We may retain billing, legal-acceptance, audit, security, and support records for longer when reasonably needed to comply with law, prevent fraud, enforce agreements, or resolve disputes. Retention periods depend on the type of data, why it was collected, sensitivity, legal requirements, and operational need.
8. Security
We take reasonable technical and organizational measures to protect personal data, including encryption in transit, access controls, tenant isolation, integrity verification, and encryption appropriate to the selected storage mode. Details are on our security page. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Keep independent backups of important data as described in our Terms.
9. Cookies and device storage
We use cookies and similar browser storage needed to operate and secure the Service. These include an HTTP-only sign-in cookie; a share-recipient session cookie that may last up to 30 days; and local or session storage used for sign-in flows, invitations, user preferences, trial state, and locally cached end-to-end encryption material. Clearing this storage may sign you out, reset preferences, or require you to restore encryption access.
If configured, Cloudflare Turnstile processes device and network signals to distinguish people from abusive automated traffic. On our marketing pages (never in the signed-in dashboard), Google Analytics sets first-party cookies such as _ga to measure aggregate page usage; it is not used for advertising. We do not use third-party behavioral advertising or advertising cookies. If we introduce further non-essential cookies, we will request consent where required.
10. Automated processing
Automated security systems may quarantine suspected ransomware, apply rate limits, or flag or restrict activity that appears abusive. We do not use personal data to make solely automated decisions that produce legal or similarly significant effects. Contact us if you believe an automated security control affected you incorrectly.
11. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal data, to object to or restrict certain processing, withdraw consent, or appeal our response. To exercise a right for data we control, use our contact form and write “Privacy request” in your message, or mail the address above. We may need to verify your identity and authority, but will use that information only to handle the request. Where permitted, an authorized agent may submit a request for you. We will not discriminate against you for exercising a privacy right.
If we process the relevant data for your organization, please direct the request to that organization first; we will assist it as required. You may also complain to your local data-protection authority.
12. Additional US state disclosures
The categories of personal data we have collected, their sources, purposes, and recipients are described in Sections 1, 2, and 4. We may collect identifiers; commercial information; internet, device, and network activity; approximate geolocation derived from an IP address; professional or employment information supplied in account or support records; and the contents of communications and Customer Content. Some Customer Content or account-security data may qualify as sensitive personal information. We use sensitive data only as reasonably necessary to provide and secure the Service or as otherwise permitted by law.
Residents of certain states may have rights to know, access, correct, delete, or obtain a portable copy of personal data; opt out of its sale, sharing for cross-context behavioral advertising, targeted advertising, or certain profiling; limit certain uses of sensitive data; and appeal a denied request. In the preceding 12 months, we have not sold personal data or shared it for cross-context behavioral advertising. We do not use personal data for targeted advertising or offer financial incentives for it. We honor legally recognized opt-out preference signals, including Global Privacy Control, when they apply. Because we do not engage in sale, sharing, or targeted advertising, there is currently no such processing to opt out of. We do not otherwise respond to legacy “Do Not Track” signals.
13. Children
The Service is not directed to children and is intended for use by individuals aged 18 or older. We do not knowingly collect personal data from children.
14. Changes to this Policy
We may update this Policy from time to time. When we do, we will revise the “Last updated” date above, and material changes will be notified by reasonable means where required. The effective version is identified by the date above; this Policy is a notice about our data practices, not a request for consent where another legal basis applies.
15. Contact
Questions, complaints, or privacy requests can be submitted through our contact form or mailed to Mirrexa US LLC, 30 N Gould St Ste R, Sheridan, WY 82801, United States.