Your Privacy Matters
At Tarlo, we believe in transparency. This policy explains what data we collect, how we use it, and your rights regarding your information.
1. Information We Collect
Account Information
- Email address: Used for account creation and important service notifications
- Full name: Optional, for personalizing your experience
- Password: Securely hashed and stored, never accessible in plain text
- Two-Factor Authentication: Optional TOTP secrets and backup codes (encrypted)
File Data
- Uploaded files: Stored on the IPFS network and our infrastructure
- File metadata: Filenames, upload dates, file sizes
- IPFS CIDs: Content identifiers for files you upload or import
Usage Analytics
- Google Analytics: Only with your consent via cookie banner
- Basic usage statistics: Storage used, upload counts (anonymized)
2. How We Use Your Information
Service Operation
- Provide IPFS storage services
- Process payments via Stripe
- Send important service updates
Improvement
- Analyze usage patterns (anonymized)
- Improve our services
- Troubleshoot technical issues
3. Cookies and Tracking
Essential Cookies
Required for the service to function:
- Authentication cookies: Keep you logged in securely
- Session cookies: Remember your preferences during your visit
Analytics Cookies (Optional)
Only used with your explicit consent:
- Google Analytics: Helps us understand how our service is used
- Performance monitoring: Identifies areas for improvement
Cookie Control
You can withdraw cookie consent at any time by clearing your browser data or contacting us. Essential cookies cannot be disabled as they're required for the service to function.
4. Data Sharing and Storage
We Never Sell Your Data
Your personal information is never sold, rented, or shared with third parties for marketing purposes.
Service Providers
We only share data with trusted partners who help us provide our services:
- Stripe: Payment processing (they never see your files)
- IPFS Network: Public files are distributed across the network
- Google Analytics: Only with your consent, for usage statistics
Data Location
- Account data: Stored securely in European data centers
- Public files: Distributed globally via IPFS network
- Private files: Stored on our secure infrastructure
5. Your Rights (GDPR)
Access
Request a copy of all data we have about you
Rectification
Correct any inaccurate personal information
Erasure
Request deletion of your account and data
Portability
Export your data in a machine-readable format
Important Note
Files uploaded to public IPFS may be permanently distributed across the network and cannot be completely removed. Consider this before uploading sensitive content publicly.
6. Security
- Encryption: All data transmitted using HTTPS
- Password security: Hashed using industry-standard bcrypt
- Two-Factor Authentication: Optional TOTP-based 2FA for enhanced account security
- Access controls: Strict authentication for all account operations
- Backup codes: Encrypted recovery codes for 2FA-enabled accounts
- Regular updates: Security patches applied promptly
7. Data Retention
- Account data: Kept while your account is active
- Uploaded files: Stored as long as you maintain your subscription
- Analytics data: Anonymized and retained for up to 26 months
- Deleted accounts: All associated data removed within 30 days
8. Contact Us
If you have questions about this privacy policy or want to exercise your rights:
9. Changes to This Policy
We may update this privacy policy from time to time. When we do:
- We'll update the "Last updated" date at the top
- For significant changes, we'll notify you via email
- Continued use of our service constitutes acceptance of changes
This policy is effective as of July 31, 2025
Return to Tarlo.app