FileDonkey FileDonkey
FileDonkey on Twitter
Privacy Policy
Effective 26 August 2026  ·  Version 1.0
This Policy explains how Ihor Horemykin, a sole proprietor trading as FileDonkey ("FileDonkey", "we", "us"), collects and processes personal data in connection with the FileDonkey application (the "Application") and the website at filedonkey.app (the "Site"). It is written to satisfy the information duties in Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the equivalent provisions of the UK GDPR.

The short version. FileDonkey has no user accounts and no cloud storage. Your files are never transmitted to us and never pass through our servers. We hold personal data in only two circumstances: when you subscribe to our mailing list, and when you choose to send a bug report from inside the Application. Both are optional, and both are initiated by you. We operate no analytics, set no cookies, and sell nothing to anyone.

1. Controller and contact details

The controller responsible for the processing described in this Policy is:

  • Ihor Horemykin, sole proprietor, trading as FileDonkey. FileDonkey is a trade name and not a separate legal entity.
  • Postal address: [registered trading address to be inserted]
  • Email: [email protected]

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. Enquiries relating to this Policy should be addressed to the email address above.

2. Scope

This Policy applies to the Site and to the Application. It does not apply to third-party websites that we link to, which are governed by their own privacy policies.

3. Data the Application does not collect

Because it materially affects the assessment a reader will make of the rest of this Policy, we state the following expressly. The Application creates a virtual disk that reads files from another device over your own local network. In ordinary operation:

  • the contents, names and directory structures of your files are transmitted only between your own devices, and are not sent to us or to any third party;
  • no copy of your files is made on any server operated by or for us;
  • the Application requires no account, no registration and no email address in order to function; and
  • the Application does not incorporate analytics, telemetry, advertising identifiers or usage-tracking of any kind.

The Application transmits data to us only in the single circumstance described in section 5.

4. Mailing list 4.1 Data collected

Where you submit the subscription form on the Site, we collect the email address you enter. No other field is requested. Our server additionally receives the IP address and browser user-agent string from which the request originates, as is inherent in the operation of any internet service.

4.2 Purpose and legal basis

We process this data to send you occasional messages about the development, release and availability of FileDonkey. The legal basis is your consent under Article 6(1)(a) GDPR, given by your submission of the form. You may withdraw that consent at any time, without giving reasons and without detriment, by using the unsubscribe mechanism in any message or by writing to [email protected]. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

We do not use your email address for advertising unrelated products, and we do not disclose, rent, sell or otherwise make it available to third parties for their own marketing purposes.

5. Feedback and bug reports 5.1 When this applies

The Application contains a feedback dialog which transmits a report to us. Nothing is transmitted unless you open that dialog and confirm the send. If you never use it, the Application sends us no data at all.

5.2 Data contained in a report

A report consists of the following. Every field except the first is optional, and the dialog states as much:

  • A device identifier. A value supplied by your operating system which is stable for the device. Its sole purpose is to allow two reports from the same device to be recognised as related. It does not identify you by name, but because it is persistent and unique to a device it is treated in this Policy as personal data.
  • Your email address, if you enter one. It is used only to reply to you about the report. Leaving it blank submits the report anonymously, and the dialog says so.
  • Your description of the problem or suggestion, if you write one. This is free text and its contents are determined entirely by you.
  • A diagnostic log, if and only if you leave the corresponding option enabled. Section 5.3 describes what it contains.

Our server additionally receives the IP address from which the report is sent, and an application user-agent string identifying the FileDonkey version, release stage, operating system name and CPU architecture.

5.3 Contents of the diagnostic log

Where you elect to attach a log, the attachment comprises the current and immediately preceding run of the Application. Each begins with a header recording the FileDonkey version, the operating system name and CPU architecture, the kernel type and version, the Qt framework version, the network name (hostname) of your computer, and the file path at which the log is stored, which on most systems contains your operating-system user name. The remainder consists of diagnostic messages recorded during operation.

Detailed logging. The Application offers an optional "detailed logging" setting, which is disabled by default. While it is enabled, the log additionally records the paths of files accessed through FileDonkey. If you enable that setting and then attach a log to a report, the names and folder paths of the files concerned will be transmitted to us, though never their contents. We recommend that you review an attached log before sending it, and that you leave detailed logging disabled unless you have been asked to enable it in order to diagnose a specific fault.

5.4 Purpose and legal basis

We process reports in order to identify, reproduce and correct faults, to evaluate suggestions, and where you have supplied an address, to correspond with you about your report. The legal basis is our legitimate interest under Article 6(1)(f) GDPR in maintaining and improving the security and correct functioning of software we supply. We consider that interest is not overridden by your interests or fundamental rights, having regard to the voluntary nature of every report, the ability to submit one anonymously, the fact that the diagnostic log is opt-out at the point of sending, and the limited categories of data involved. You may object to this processing on grounds relating to your particular situation under Article 21 GDPR.

6. Purchases and preorders

Where we offer paid licences or preorders, payment is handled by an external payment provider. That provider acts as an independent controller in respect of the card or payment-account data you give it, and processes that data under its own privacy policy. We do not receive or store full payment card numbers. We receive only the information necessary to issue and administer your licence, such as your name, email address and the fact and amount of the transaction, processed on the basis of Article 6(1)(b) GDPR, performance of a contract, and Article 6(1)(c) GDPR in respect of the retention of accounting records.

[The payment provider is to be named here before any payment is accepted, and this section reviewed against that provider's terms.]

7. Cookies and analytics

The Site sets no cookies, uses no local or session storage for tracking purposes, and embeds no third-party analytics, advertising or social-tracking scripts. Fonts and images are served from our own origin rather than a third-party content delivery network, so loading a page of the Site does not disclose your visit to any other party. Because no non-essential terminal storage is used, no consent banner is required under Article 5(3) of Directive 2002/58/EC.

8. Recipients and processors

We do not sell personal data and do not disclose it for the independent purposes of others. Data described in this Policy is disclosed only to:

  • Cloudflare, Inc., which provides the infrastructure and database on which our service endpoints and stored reports are operated, acting as our processor under Article 28 GDPR;
  • our payment provider, in the circumstances described in section 6; and
  • public authorities, where disclosure is required by law, or is necessary to establish, exercise or defend legal claims.

[Any additional hosting or email-delivery provider is to be named here.]

9. International transfers

Our processors may process data outside the European Economic Area, including in the United States. Where that occurs, the transfer is made on the basis of the European Commission's Standard Contractual Clauses adopted under Article 46(2)(c) GDPR, or another lawful transfer mechanism applicable to the recipient. A copy of the relevant safeguards may be requested at the address in section 1.

10. Retention

We retain personal data no longer than is necessary for the purpose for which it was collected:

  • Mailing list: until you unsubscribe or otherwise ask us to erase your address, after which it is deleted without undue delay.
  • Feedback and bug reports: for so long as the underlying issue remains open and for a reasonable period thereafter to detect recurrence, and in any event no longer than [retention period to be confirmed, e.g. 24 months].
  • Transaction and accounting records: for the period required by applicable tax and commercial law.
11. Your rights

Subject to the conditions and exceptions in applicable law, you have the right to request access to your personal data (Article 15 GDPR), its rectification (Article 16), its erasure (Article 17), restriction of its processing (Article 18) and its portability (Article 20); to object to processing carried out on the basis of legitimate interests (Article 21); and to withdraw consent at any time where processing is based on consent (Article 7(3)).

To exercise any of these rights, write to [email protected]. We will respond within one month of receipt, which may be extended by two further months where necessary having regard to the complexity and number of requests, in which case we will inform you of the extension and the reasons for it. We may ask for information reasonably necessary to confirm your identity.

You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement (Article 77 GDPR). In the United Kingdom, the supervisory authority is the Information Commissioner's Office.

12. Automated decision-making

We do not carry out automated decision-making, including profiling, producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 GDPR.

13. Children

The Site and the Application are not directed at children, and we do not knowingly collect personal data from a child. Where we become aware that we have collected personal data from a child without appropriate consent, we will erase it without undue delay.

14. Security

We apply technical and organisational measures appropriate to the risk, in accordance with Article 32 GDPR. Data in transit between the Application, the Site and our endpoints is protected by TLS. Access to stored reports and subscriber addresses is restricted to those who require it for the purposes set out in this Policy. No method of transmission or storage is entirely secure, and we cannot guarantee absolute security.

A note on your local network. Communication between your own devices takes place on your local network and does not pass through our servers. The security of that network, including who is able to join it, is under your control rather than ours. Each device shares only the folder you nominate. We recommend that FileDonkey be used on networks you trust.

15. Changes to this Policy

We may amend this Policy from time to time. The version and effective date at the head of this page will be updated accordingly. Where a change materially affects how we process personal data already collected, we will take reasonable steps to notify you in advance, including by email where we hold an address for you and the change concerns that processing.

16. Contact

Questions about this Policy, or about how your personal data is handled, may be sent to [email protected].