Skip to content
UploadWizard
FeaturesHow it worksPricingFAQDocsGet started
FeaturesHow it worksPricingFAQDocsGet started

Privacy Policy

Last updated: May 27, 2026

UploadWizard ("we", "us") provides a white-label file-intake platform that businesses ("customers") use to collect files from their own clients. This policy explains what we collect and how we handle it. It is provided for transparency and is not legal advice.

Our role

For files uploaded through a customer's portal, the customer is the data controller and UploadWizard is a data processor acting on their behalf. Uploaded files are stored in the customer's own object storage (e.g. their S3, Azure, or Google Cloud bucket) — we do not retain copies of customer files on our systems.

Information we collect

  • Account & tenant data: business names, domains, and configuration you provide. Administrator email addresses are stored and are planned for encryption in a future release.
  • Authentication data: email addresses used for passwordless sign-in, and short-lived one-time codes/links (stored hashed).
  • File metadata: file names, sizes, types, and timestamps — used to display and manage uploads. File contents live in the customer's storage, not ours.
  • Aggregate usage counts: daily totals of uploads, sign-ins, and downloads per account. No user identity or file content is included in these counts.
  • Audit events: sign-ins and other security-relevant actions may be recorded in an encrypted audit log under each customer's control (see below).

Zero-knowledge audit log

Each customer's audit log is encrypted with their own encryption key before it is written to our database. UploadWizard stores only the sealed (encrypted) entries and cannot read them. The customer's private key is held solely by the customer — protected by a passphrase they set in their browser — and is never transmitted to our servers in plaintext. This design means UploadWizard cannot produce audit log contents in response to requests, because we genuinely do not hold the key.

Operational secrets

Credentials customers supply to connect their own storage and databases are encrypted via a dedicated secrets management system (HashiCorp Vault transit encryption). No human, including UploadWizard staff, can read raw credential values. The application decrypts them in memory only at the moment of use and discards the plaintext immediately afterward. All decryption operations are audited.

How we use information

To operate the service: authenticating users, routing uploads to the correct storage, enforcing limits and security controls, providing support, and meeting legal obligations. We do not sell personal information.

Website analytics

This marketing site uses self-hosted, cookieless Plausible Analytics — aggregate page counts only, no cross-site tracking, no personal identifiers, and nothing shared with third-party ad networks.

Sub-processors

We use infrastructure and email-delivery providers to run the service. Uploaded file contents are processed only by the customer's chosen storage provider.

Retention

Customers control how long uploaded files are kept via per-business storage settings. Audit log retention is also configurable per customer (1, 7, 30, 90, or 365 days). Account and configuration data are retained while an account is active and for a reasonable period afterward as required for legal and operational purposes.

Your choices

If you are an end user uploading to a business's portal, please direct privacy requests to that business (the data controller). For data we hold as a controller (e.g. customer accounts), contact us below.

Contact

Questions about this policy? Use the contact form or write touploadwizard@all7s.us.

UploadWizard

White-label client file intake — your brand, your domain, your storage. Collect files from clients securely in minutes.

Product

  • Features
  • How it works
  • Pricing
  • FAQ

Resources

  • Documentation
  • Contact

Legal

  • Privacy Policy
  • Terms of Use
  • DMCA

© 2026 | Created with ❤️ byMichal Ferber, akaTechGuyWithABeard.