The short version
- We identify you by email address, because that is what Cloudflare Access signs you in with. There is no password to store, and we never see one.
- We store what you publish — your files, their versions, and the access list you set — because hosting them is the product.
- We record who opened each artifact, and show that log to the artifact's owner. This is a feature of the product, and it applies to you when you open somebody else's artifact too.
- There is no analytics, no advertising and no third-party tracking on this site. Nothing you publish or view is sold, shared with advertisers, or used to profile you.
Who is responsible
the rtfx.pro operator is responsible for this deployment and is the data controller for everything
described below. Questions, requests and complaints go to privacy@rtfx.pro.
If you reached an artifact through a link somebody sent you, they are the one who decided to share it with you and who sees that you opened it. We host it on their behalf.
What we collect
Everything in this table is stored in this deployment's own database or object storage. There is no data collection on this site beyond it.
| What | Where it comes from | Why |
|---|---|---|
| Email address | Cloudflare Access, when you sign in with a one-time code. | It is your identity here: it decides what you can open and what you own. |
| Account record | Created on first sign-in; an admin may add a display name or note. | Role, status (invited, active, paused) and workspace membership. |
| Artifacts you publish | You, through the dashboard, the CLI, the API or an agent. | The files, plus their title, slug, size, versions and version notes. This is the thing being hosted. |
| Access lists | You, when you share an artifact. | The email addresses you granted access to, per artifact. |
| View log | Recorded when a signed-in person opens an artifact page. | Viewer's email, artifact and version, path, timestamp, referring page, and the approximate country Cloudflare reports. Shown to the artifact's owner. |
| API tokens | You, when you mint one. | Name, scopes, owner, created/last-used timestamps. The token itself is stored only as a hash — we cannot show it to you again after it is created. |
| Access requests | The "Request access" form on the landing page. | Your email address and when you submitted it, so we can send an invitation. |
| Infrastructure logs | Cloudflare, as the network and platform serving every request. | Standard request logging and abuse prevention, under Cloudflare's own terms. |
What we do not collect
- No passwords — sign-in is passwordless, so none exist.
- No payment details. There is no billing in this deployment.
- No analytics, advertising, fingerprinting or session-replay of any kind.
- The product code does not inspect your artifacts' contents for analytics, advertising or profiling. Operators with infrastructure access may still be able to access stored files when required to operate, secure or troubleshoot the service.
Why we are allowed to process it
For readers in the UK/EEA, where a lawful basis has to be named:
- Performance of a contract. Your email address, account record, artifacts and access lists — we cannot host access-controlled pages for you without them.
- Legitimate interests. The view log (an artifact's owner needs to know who opened what they shared), API token metadata, and security/abuse prevention. We keep these to the minimum that serves the purpose.
- Consent. The access-request form: you gave us your address so we would contact you, and you can ask us to delete it at any time.
How long we keep it
- Artifacts and their versions — until you delete them. Deleting an artifact deletes its versions, its files and its access list.
- View log entries — kept with the artifact, and deleted with it.
- Your account record — for as long as you have access. Pausing an account keeps it; deletion removes it.
- API tokens — until revoked or expired.
- Access requests — stored as a waitlist record until the operator acts on it or removes it manually.
Your rights
You can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to a particular use. Much of it you can do yourself: you can delete an artifact, revoke a token, or change who an artifact is shared with, from the dashboard.
For anything else, write to privacy@rtfx.pro. Note that we cannot delete the
view-log entries showing that you opened somebody else's artifact without also removing the
record they rely on; we will explain what applies when you ask. If you are in the UK/EEA you
also have the right to complain to your data protection authority.
Security
- Every artifact is private by default and access-controlled per artifact. An unauthorized request and a request for something that does not exist get the same 404.
- Artifact files are served from a separate origin, so uploaded HTML can never run in the same origin as the dashboard or the API.
- API tokens are stored hashed, scoped, owner-bound and revocable.
- Everything is served over TLS, and sign-in is handled by Cloudflare Access rather than by a password store of our own.
No system is perfect. If you find a security problem, please report it rather than test it further — see the repository's security policy.
Children
rtfx.pro is a tool for professional work and is not directed at children. Access is by invitation, and we do not knowingly create accounts for anyone under 16.
Changes to this policy
If this policy changes materially — new data, a new processor, a new purpose — the date at the top changes and the cookie notice reappears. We will not start doing something new with your data and tell you afterwards.