Privacy policy
Last updated October 5, 2026
flockfs is run by 0sec, a Delaware C corporation ("we", "us"). This policy explains what we collect when you use flockfs.com, app.flockfs.com and the flockfs apps, CLI and MCP server we host, and what we do with it. Questions go to doruk@0.security.
What we collect
- Your account. Your email address and name. If you sign in with Google or GitHub, we receive the basic profile those services share (name, email, account id).
- What you put in flockfs. The files and folders in your drives, every version of them, and who made each change. This includes changes made by agents you connect.
- Agent activity. When an agent uses flockfs through MCP or the API, we record a timeline of its actions: the tool, the file path, a cleaned-up copy of the arguments (secrets and tokens are removed), whether it worked and how long it took.
- Access tokens. Tokens and OAuth connections you create for agents and apps, with their names, scopes and expiry.
- Billing. If you pay for Team, Stripe handles your payment details; we never see your card number. We keep your Stripe customer and subscription ids, your plan, billing period and number of seats.
- Technical data. IP addresses, browser type and request logs, which our servers record to run the service and protect it from abuse.
- Website analytics. flockfs.com uses Google Analytics to count visits and see which pages people use, with Google signals and ad personalization turned off. The app at app.flockfs.com does not use it.
- The live demo. Edits you make in the demo on flockfs.com go into a temporary sandbox that is deleted a few minutes after you leave.
How we use it
- To run flockfs: store and sync your files, keep their history, show live edits, and let the people and agents you choose work with them.
- To bill you and answer support requests.
- To keep flockfs secure, enforce limits and investigate abuse.
- To understand how the website is used, so we can improve it.
We do not sell your data, and we do not use the contents of your drives to train AI models.
Agents and apps you connect
When you connect an agent or app (for example Claude, ChatGPT, Codex or Cursor), it reads and writes the files you give it access to. What that service does with the data is covered by its own terms and privacy policy. You can see and revoke every connection under Access in the app.
Who processes your data
- Hetzner (Germany): hosts app.flockfs.com, its database and our encrypted backups.
- Cloudflare: serves flockfs.com and its DNS.
- Stripe: payments.
- Google: website analytics on flockfs.com, and sign-in if you choose Google.
- GitHub: sign-in if you choose GitHub.
Your drives are stored in Germany. Some of these providers may process data in the United States.
How long we keep it
- Files stay until you delete them. Older versions are kept for your plan's history window: 30 days on Free, one year on Team, and as agreed on Enterprise.
- A deleted drive is removed for good after 30 days; until then, a drive deleted by mistake can still be restored.
- We back up the database daily, encrypted. Data you delete can remain in older backups until those backups are removed.
- Account and billing records are kept while your account is open and as long as the law requires afterwards.
Your choices and rights
You can export any drive at any time (flockfs export, as plain files or a Git repository), correct your account details, delete drives, and ask us to delete your account. Depending on where you live, you may also have the right to access, correct, delete or move your personal data, or object to how we use it. Email doruk@0.security and we will help.
Security
Connections are encrypted with TLS, agents use scoped tokens that you can limit to a folder and revoke, and backups are encrypted. No system is perfectly secure, so tell us right away if you find a problem.
Children
flockfs is not meant for anyone under 16, and we do not knowingly collect their data.
Changes
If we change this policy, we will update the date above. For changes that matter, we will also tell account owners by email or in the app.