Privacy Policy
Last updated: August 7, 2026
The Short Version
UploadWizard provides a white-label file-intake platform that businesses ("customers") use to collect files from their own clients. Uploaded data belongs to the client and the customer, not to us — files go straight to the customer's own storage, and the relationship between a business and its clients is governed by that business's own terms and privacy policy, not this one. This policy explains the little we handle to run the platform.
Our Role
For files uploaded through a customer's portal, the customer is the data controller and UploadWizard is a data processor acting on their behalf. Uploaded files are stored in the customer's own object storage (their S3, Wasabi, Azure, or Google Cloud bucket) — we do not retain copies of customer files on our systems. End users with privacy questions or requests about uploaded material should contact the business that operates the portal.
Information We Handle
- Account & tenant data: business names, domains, and configuration customers provide.
- Authentication data: email addresses used for passwordless sign-in, and short-lived one-time codes and links (stored hashed).
- File metadata: file names, sizes, types, and timestamps — used to display and manage uploads. File contents live in the customer's storage, not ours.
- Aggregate usage counts: daily totals of uploads, sign-ins, and downloads per account, with no user identity or file content included.
- Audit events: sign-ins and other security-relevant actions, recorded in an encrypted audit log under each customer's control (below).
Zero-Knowledge Audit Log
Each customer's audit log is encrypted with their own key before it is written to our database. UploadWizard stores only the sealed entries and cannot read them. The customer's private key is protected by a passphrase they set in their browser and is never transmitted to our servers in plaintext — we genuinely cannot produce audit log contents, because we do not hold the key.
Operational Secrets
Credentials customers supply to connect their own storage and databases are encrypted with a dedicated secrets-management system (HashiCorp Vault transit encryption). No human can read raw credential values; the application decrypts them in memory only at the moment of use, and all decryption operations are audited.
Retention
Customers control how long uploaded files are kept via per-business storage settings, and audit-log retention is configurable per customer. Account and configuration data are retained while an account is active and for a reasonable period afterward as required for legal and operational purposes.
This Website
The uploadwizard.app website is served by Cloudflare, which receives standard web request metadata (IP address, user agent, requested URL, timestamp) to deliver pages and protect against abuse. For analytics we use self-hosted, cookieless Plausible Analytics — aggregate page counts only, no cookies, no cross-site tracking, no personal identifiers, and nothing shared with ad networks.
The Contact Form
When you send a message through our contact form, it is verified by Cloudflare Turnstile and delivered to our inbox. We use what you send solely to respond to you; nothing is stored on our servers beyond delivering the message.
Payments
Payments are processed by Stripe. Checkout happens on Stripe's hosted pages: your payment card details go directly to Stripe and are never collected, seen, or retained by us. Stripe's handling of your information is described in its own privacy policy.
Data Sharing
We do not sell, rent, or share your personal information. The only third parties involved are the service providers named on this page, each used solely to operate the service described.
Children's Privacy
UploadWizard does not knowingly collect any personal information from children under 13 years of age.
Changes to This Policy
We may update this policy from time to time; material changes are reflected in the "Last updated" date above.
Contact
Questions about this policy? Reach us through the contact form.