FolderNetwork

Privacy policy

Last updated 26 August 2026. This page covers the FolderNetwork service at https://sync.foldernet.work, the desktop sync app, and the FolderNetwork phone app.

The short version. FolderNetwork is a file backup and sync service a company buys for its staff. We hold the files you send us and the small amount of account data needed to sign you in and show your administrator who did what. We do not sell it, we do not advertise against it, we do not profile you, and we do not use it to train anything. There are no third-party analytics or tracking SDKs in any FolderNetwork app.

Who controls your data

A FolderNetwork workspace belongs to the company or organisation that created it — your employer, in most cases. They decide who is in the workspace, what each person can see, and how long deleted files stay recoverable. They can read files you upload into shared folders, and they can see the activity log described below. FolderNetwork operates the service on their behalf.

Your personal folder (<your name> Documents) is hidden from other members of the workspace by the permission system. It is not encrypted in a way that hides it from the service itself.

What we hold

DataWhy
Your email address and display name To sign you in, to address notification email, and to attribute changes in the activity log.
Your password, hashed (scrypt) — never the password itself To check a sign-in.
Your two-factor secret, when you turn 2FA on To check the 6-digit code.
The files and folders you upload, and their previous versions This is the product. Versions are kept for the retention window your workspace administrator chose (30 to 365 days), then deleted.
For each linked computer or phone: the name you gave it, a random device id, a hashed access token, and when it was last seen To keep a device signed in, to show your administrator the fleet, and to let either of you revoke a lost device.
An activity and audit log: who signed in, linked a device, uploaded, deleted, restored, shared or was granted access, and when So an administrator can answer "what happened to this file", and so a deletion can be accounted for afterwards.
Byte counters per workspace and device To bill and to show storage use. Counts of bytes, not their contents.
Diagnostic reports and crash reports, when a device sends one To fix faults. Diagnostic logs are encrypted on the device to a service key before upload, and are read only by an operator investigating a fault.
IP addresses, in memory only To rate-limit failed sign-ins and workspace creation. These counters are not written to the database and do not survive a restart.

The phone app specifically

Where it is stored, and who else touches it

Files are stored as encrypted-in-transit uploads on our storage vendors — a primary object-storage provider and an optional second vendor kept as a mirror, so a single vendor failure does not lose your data. Metadata lives in the service database. Notification email is sent through our mail provider. Those vendors process data on our instructions and for no other purpose. We do not otherwise disclose your data, except where the law requires it.

Deleting your account

You can delete your account yourself, without contacting anyone:

Deleting your account immediately removes your sign-in, your two-factor secret, every linked device and its token, and every folder grant you hold. There is no waiting period and no recovery.

Files you uploaded stay in the workspace. They belong to the organisation that owns it, not to your sign-in, and deleting your account does not take the company's records away from it. If you want particular files removed too, ask a workspace administrator before you delete your account.

If you are the last administrator of a workspace, your account cannot be deleted on its own — that would leave the workspace unadministered. Delete the workspace instead, on the same Security page. That erases every account in it, every file, and every version, from both storage vendors. The audit line recording the deletion is kept.

An audit entry naming the deleted account is retained as the record that the deletion happened.

How long we keep things

Your rights

You can see and correct your own account details in the portal, download your files from it at any time, and delete your account as described above. For anything else — a copy of what we hold, a correction you cannot make yourself, or a complaint — write to us at the address below. Where your workspace's administrator is the party who decides what happens to the data, we will pass your request to them and tell you that we have.

Children

FolderNetwork is a workplace tool sold to organisations. It is not directed at children and we do not knowingly create accounts for them.

Changes

If this policy changes materially we will say so on this page and date it. The date at the top is the version in force.

Contact

Privacy questions and data requests: privacy@foldernet.work