Effective date: 2 September 2026 · Last updated: 2 September 2026
Not a substitute for the full policy below.
We never see the contents of your files. enblob syncs to storage you own and control. Your files travel from your device to your bucket — they never pass through, and are never stored on, our systems.
What we do hold is the small amount of information needed to run an account: your email address, which version of our terms you accepted, and technical check-in data from the client (app version, operating system, processor architecture, and an opaque hash that identifies a bucket without revealing its name).
We don't sell or rent your data, we don't run advertising trackers, and we have no ability to decrypt anything you store. You can ask us for a copy of what we hold, or ask us to delete it, at legal@enblob.com.
This Privacy Policy explains how enblob.com ("enblob", "we", "us") collects and uses personal data when you visit our website, request early access, create an account, or use the enblob client software (together, the "Service").
enblob is the controller of the personal data described in this policy for the purposes of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where it applies to us, the EU GDPR.
This policy forms part of our Terms of Service. Where a term is defined in the Terms (for example "Your Storage"), it has the same meaning here.
Questions, requests, or complaints about privacy: legal@enblob.com. Security issues: security@enblob.com.
enblob is a synchronisation tool, not a storage service. The Service moves files between your own devices and one or more S3-compatible storage backends that you select, configure, and pay for.
We do not collect, receive, store, or have any means of accessing:
This is an architectural property of the product, not a policy promise we could quietly reverse: there is no enblob storage tier for your files to sit in. It also means we cannot recover your data, reset a lost encryption key, or produce your file contents to anyone — including a court. See section 12.
In data-protection terms, where the files you sync contain personal data, you are the controller of that data and your storage provider is your processor. enblob is neither, because it has no access to the contents.
The tables below describe every category of personal data we hold. "Legal basis" refers to Article 6 of the UK/EU GDPR.
When you request early access from our website, you sign in with Google so that we can confirm you control the email address, and you separately opt in to being contacted about the programme.
| What | Why | Legal basis |
|---|---|---|
| Email address | To identify your place on the waitlist and to contact you about early access | Consent |
Referral source (e.g. enblob.com) |
To understand which channel a request came from | Legitimate interests — understanding demand |
| Consent version, and the date you gave or withdrew it | To evidence what wording you agreed to, as the law requires us to be able to do | Legal obligation |
We request only the email address scope from Google. We do not receive your name, profile picture, contacts, calendar, Drive files, or anything else in your Google account.
| What | Why | Legal basis |
|---|---|---|
| Email address | To identify your account, authenticate you, and send service messages | Performance of a contract |
| Role and organisation membership | To apply the right permissions, and to run Team accounts | Performance of a contract |
| Account creation date | Account administration | Performance of a contract |
| Which version of our Terms you accepted, and when | To evidence acceptance, and to know when to ask again after a material change | Legal obligation |
| An opaque internal account identifier | Used in signed bucket-ownership records instead of your email, so your address is not written into your own storage | Legitimate interests — data minimisation |
| Device tokens | To bind an installation to your account; revocable by you | Performance of a contract |
The enblob client periodically contacts our licensing server to confirm your entitlement, check for updates, and retrieve service notices. Each check-in reports:
| What | Why | Legal basis |
|---|---|---|
| A randomly generated installation identifier | To count devices against your plan and let you deactivate one | Performance of a contract |
| Application version, operating system, and processor architecture | To serve the correct update and to know which builds are still in use | Legitimate interests — supporting and maintaining the software |
| First-seen and last-seen timestamps | To identify inactive installations and free up seats | Performance of a contract |
| Workspace identifiers (see below) | To allocate licence seats per bucket and record which account owns a workspace | Performance of a contract |
How a workspace identifier works. A "workspace" is one bucket configuration. Rather than send us your endpoint, bucket name, and prefix, the client combines them locally with a cryptographic hash function and sends only a short fingerprint of the result. The identifier is stable, so we can count it, and we never receive the endpoint, bucket name, or region themselves.
We would rather state the limit of that technique than oversell it. The fingerprint is derived from those values and is not salted, so somebody who already had a specific guess — a particular bucket name at a particular provider — could test that guess against it and see whether it matched. It stops your bucket's identity from being handed to us in the first place. It is not a guarantee that a determined party who already suspected the answer could never confirm it.
The client sends no other usage telemetry. We do not embed analytics SDKs, crash reporters, or advertising identifiers in the software.
We keep records of licence keys issued to your account, the plan and seat count attached to them, their validity period, and a log of lifecycle events (issue, extension, upgrade, revocation) recording who made the change and when. These are held to administer your entitlement and to maintain an auditable record of billing and support actions. Legal basis: performance of a contract and our legitimate interest in keeping accurate business records.
If you email us at hello@, sales@, security@,
legal@, or careers@enblob.com, we hold that correspondence
and any information in it so we can answer you and keep a record of what was agreed.
Legal basis: legitimate interests, or performance of a contract where the exchange
concerns your account. Job applications are handled on the basis of taking steps at
your request prior to a possible contract of employment.
We use Plausible Analytics to understand how many people visit enblob.com and which pages they read. Plausible is a privacy-focused, EU-based analytics service that:
The data it produces — page views, referring site, country, browser and device type — is aggregated and does not identify you. Because no personal data is stored, we do not ask for analytics consent; there is no tracking cookie to consent to. Legal basis, to the extent any processing is personal: legitimate interests in understanding how our website is used.
We use cookies sparingly, and only where they are strictly necessary for the Service to work.
| Cookie | Purpose | Lifetime |
|---|---|---|
| Session cookie | Keeps you signed in after login. Its contents are encrypted with AES-256-GCM, so the cookie is not readable or forgeable outside our server. | 24 hours, or until you log out |
| Sign-in state cookie | Protects the Google sign-in exchange against cross-site request forgery. | 5 minutes, or until sign-in completes |
| Return-path cookie | Remembers which page on our site to return you to once you have signed in. Only ever holds a path within our own site. | 5 minutes, or until sign-in completes |
All three are strictly necessary cookies and are exempt from the consent
requirement under the Privacy and Electronic Communications Regulations. Each is
set HttpOnly and SameSite=Lax, and marked
Secure so it is only ever sent over HTTPS. We set no advertising,
profiling, or cross-site tracking cookies of any kind, and our analytics are
cookieless (section 3.6).
We do not sell, rent, or trade personal data, and we do not share it for anyone else's marketing. We share data only with the service providers below, each acting on our instructions or as an independent controller where noted, and only to the extent needed to run the Service.
| Provider | What they do | What they receive |
|---|---|---|
| Cloud infrastructure provider | Hosts our website, application servers, and database | All data described in section 3, at rest on their infrastructure |
| Provides sign-in | Google authenticates you and tells us your email address. Google's own handling of your Google account is governed by its privacy policy, as an independent controller. | |
| Plausible Analytics | Aggregate website statistics | Cookieless, non-identifying page-view data (section 3.6) |
| Google Fonts and the Tailwind CDN | Serve fonts and a stylesheet used by our website | Your browser requests these files directly, which discloses your IP address and browser details to those providers as a technical necessity of loading them. They are not used to track you on our behalf. |
We have named categories rather than companies for infrastructure we may change over time. If you would like to know which providers we currently use — for a vendor review, a procurement questionnaire, or simple curiosity — ask us at legal@enblob.com and we will tell you.
We may also disclose data to professional advisers (such as lawyers or accountants) where necessary, and to a buyer or successor in the event of a merger, acquisition, or sale of assets — in which case this policy continues to apply to your data until you are told otherwise.
Your storage provider is not our supplier. Your relationship with Amazon S3, or whichever S3-compatible provider you choose, is directly between you and them, under their terms and their privacy policy. We send them nothing and receive nothing from them.
Our website, application servers, and database are hosted in the United Kingdom or the European Economic Area. We will update this policy if that ever changes.
Some of the providers in section 5 are established outside the UK and EEA, or may process data outside it. Where personal data is transferred internationally, we rely on an adequacy decision where one covers the transfer, and otherwise on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, together with any additional safeguards required.
Your files themselves are held wherever you chose to put them. If the region of your bucket matters to you — for data residency, or for a transfer assessment of your own — that choice is entirely yours to make and change, and we are not part of it.
| Data | Retention |
|---|---|
| Account data | For as long as your account is open. Deleted within 90 days of you closing it, except where a longer period is required below. |
| Early-access records | Until you withdraw consent or ask us to delete the record. If you withdraw consent we keep a minimal record of the withdrawal itself, so that we can prove we stopped contacting you and so we do not email you again by mistake. |
| Client check-in data | For as long as the installation is active, and up to 12 months after its last check-in. |
| Terms-acceptance and consent records | Six years from the end of our relationship, as evidence of the agreement. |
| Licensing, billing, and audit records | Six years from the end of the relevant financial year, to meet UK accounting and tax obligations. |
| Correspondence | Two years from the last message, or six years where it concerns a contract or a dispute. |
| Unsuccessful job applications | Six months, unless you ask us to keep your details on file. |
| Website analytics | Retained in aggregate only; no individual-level records exist to delete. |
Deleting your account does not delete your files. They are in Your Storage, under your control, and remain there until you remove them yourself.
Under the UK and EU GDPR you have the right to:
To exercise any of these, email legal@enblob.com. We will respond within one month, and will tell you if we need longer because the request is complex. We do not charge for this, and we may ask you to confirm control of the email address on the account before we act.
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk, helpline 0303 123 1113), or to the supervisory authority in your EU country of residence.
Service emails — about your account, security, billing, or material changes to the Terms — are part of providing the Service and cannot be opted out of while your account is open.
Early-access and marketing emails are sent only if you opted in. You can withdraw that consent at any time from your account settings, using the unsubscribe link in any such email, or by emailing legal@enblob.com. We record the version of the consent wording you agreed to and the date, so that both of us have a clear record of what was asked and answered.
Our Terms of Service provide for Team accounts, under which an organisation administers membership for its own people. Team functionality is still in development. When it is available, this section will set out exactly what a Team administrator can and cannot see, and the "last updated" date above will change accordingly.
Whatever shape it takes, it will not alter what enblob itself can reach: as set out in section 2, we do not hold your file contents or your keys.
No system is perfectly secure, and we give no guarantee that any encryption or obfuscation cannot be broken — see section 7 of the Terms of Service. If we suffer a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours where required, and will tell you without undue delay where the risk to you is high.
To report a vulnerability, contact security@enblob.com.
We comply with valid legal process from law enforcement and other competent authorities. When we receive such a request, we can only provide the data we actually hold — account registration details, licensing and billing records, and the technical check-in metadata described in section 3.3.
We cannot provide the contents of your files, because we do not have them. Requests for stored content must be directed to you or to your storage provider. Where your data is encrypted, we hold no keys and have no ability to decrypt it. Unless we are legally prohibited from doing so, we will notify you of a request concerning your account.
enblob is a file-synchronisation tool for adults and is not directed at children. Under our Terms of Service you must be at least 18, or the age of legal majority where you live, to create an account, install the software, or subscribe.
We do not knowingly collect personal data from children. If you are a parent or guardian and believe a child in your care has given us personal data, contact legal@enblob.com. We will look into it and delete the data where we establish that the account holder is below the age we require. We will not close or delete an account merely because a third party asks us to; requests about your own data are handled under section 8.
We may update this policy to reflect changes in the Service, in our providers, or in the law. The "last updated" date at the top always shows the current version. For material changes we will give at least 30 days' notice by email or in-product notification before they take effect. Continued use of the Service after that date means the updated policy applies.
For any privacy question, request, or complaint: legal@enblob.com.
Our whole approach to your data is on the About page — including the things enblob deliberately cannot do.