Skip to content
File Requestsby Firmary Upload only

Data handling

Privacy & retention

File Requests is a limited file handoff service. It does not analyze document contents with AI.

What we collect

We store the requester’s verified account identity and connection details, the selected folder identifier, request text, uploaded file names and sizes, and delivery results. Uploaders need no account. A capability link permits upload but does not prove who supplied a file.

How files move

Files enter private, encrypted temporary staging for structural validation, malware scanning, and reliable delivery. Only the bound Google Drive folder receives accepted originals. Its existing sharing settings apply. Google credentials are never shown to uploaders or ChatGPT.

Google user data

When a requester connects Google Drive, File Requests asks only for their Google account email and the drive.file permission, which covers only the folder they pick and the files File Requests creates in it, not the rest of their Drive. File Requests uses that access only to confirm the chosen folder and deliver accepted uploads into it. Google user data is not sold, not used for advertising, not shown to uploaders or ChatGPT, and not used to train AI models. File Requests’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. A requester can remove File Requests’ access at any time from their Google Account’s third-party connections.

Retention defaults

Temporary copies are deleted after confirmed delivery, within 24 hours. A blocked delivery is purged at 72 hours, after an owner notification is queued. Delivery metadata is retained for 90 days after request closure, unless deleted sooner. Deleted application records can remain in encrypted backups for up to 30 days. These are product defaults, not legal-retention guarantees.

Deletion

The requester can delete a request from its private detail page. This revokes the link, cancels undelivered work, and purges app-held data according to the stated schedule. It does not delete files already delivered to Google Drive.

Operational messages & logs

Receipts and connection or delivery alerts go only to the verified requester. Security logs and minimal delivery events support abuse prevention, reliability, and cost limits. Logs exclude file contents and credentials. These pages contain no advertising pixels, session replay, or third-party analytics.

Permitted material

Do not use this service for raw tax returns, W-9s, government identifiers, payment-card data, medical records, passwords, API keys, or authentication codes.

Contact the operator through Support for privacy or deletion questions.

Made by Firmary, software for accounting firms
Privacy & retentionTermsSupport