Kushner Management Company LLC operates FolderBloom. This Privacy Policy explains how we handle information when you visit our website, create an account, connect cloud storage, or use file libraries and galleries powered by FolderBloom.
For account, billing, and service administration, we determine how information is used. For content a customer selects for publication, we generally process it to provide the service according to that customer's instructions. If you are visiting someone else's website, that website owner's privacy notice also applies.
1. Information we collect
Account and workspace information. We collect your name, email address, authentication records, workspace membership and role, invitations, website domains, and service settings. Passwords are stored in hashed form. Authentication sessions may include IP addresses and browser or device information for security.
Connected storage information. When you authorize Dropbox or OneDrive, we receive provider account identifiers, account labels, permissions, and access credentials needed to maintain the connection. Provider access and refresh tokens are stored encrypted. We do not ask for your Dropbox or Microsoft account password.
File metadata and published content. We process information about selected files and folders, including names, paths, provider identifiers, file sizes, types, modification dates, and version information. We also store presentation settings such as captions, titles, alt text, scheduling, and access rules. This information can contain personal data if you include it in your files or labels.
Documents are generally streamed from your storage when requested rather than retained as permanent original-file copies in FolderBloom. Photo processing accesses source images and stores optimized gallery copies. Original photo downloads, where enabled, also require access to source content. File content may pass through service-provider systems and temporary buffers during processing or delivery.
Billing information. Stripe processes payments and may collect payment details, billing addresses, tax information, and fraud-prevention information. FolderBloom stores subscription and customer identifiers, plan information, payment status, and billing records needed to administer your account. We do not store full payment card numbers or card security codes in the FolderBloom application database.
Usage and technical information. We record download starts, associated file and site identifiers, timestamps, delivery source, byte counts, and sometimes the referring website's domain. Our gallery download analytics do not store visitor IP addresses in download-event records. However, requests to our servers, hosting providers, storage services, or content delivery networks may involve IP addresses, browser information, and operational or security logs. Security controls may use request information to prevent abuse.
Support and communications. We keep support requests, messages, internal support notes, and records needed to resolve issues and administer the service.
2. How we use information
We use information to create and secure accounts; connect authorized storage; synchronize selected folders; publish libraries; process and deliver images; enforce access settings; administer subscriptions and taxes; provide usage reports; troubleshoot problems; prevent abuse; respond to requests; and meet legal obligations.
We send transactional communications such as verification messages, password resets, invitations, invoices, payment notices, renewal reminders, and material service or policy updates. Workspace owners also receive usage summary emails by default, which any member can change or turn off under Account. Any optional marketing communications are separate from required service communications and include an appropriate way to unsubscribe.
We do not use customer files or photos to train AI models.
3. What website visitors can see
The customer chooses which folders and files to publish and whether to apply supported access restrictions. Content published publicly can be viewed, downloaded, shared, and potentially indexed by search engines. Gallery plans may allow downloads of originals when the customer enables that feature.
A privacy or deletion request cannot retrieve copies already downloaded by visitors or immediately clear independent browser and search-engine caches. If you have a concern about personal information in a customer's published folder, contact that website owner and, if needed, [email protected].
4. Cookies and similar technologies
FolderBloom uses necessary cookies or comparable session tokens for account sign-in, workspace selection, secure storage connections, and password-protected folder access. Blocking them may prevent those features from working.
The file-download analytics described above do not require advertising tracking cookies. We do not use customer file content for behavioral advertising. The website hosting an embed may use its own cookies, analytics, or advertising tools, which are controlled by that website owner.
If we introduce optional analytics or advertising technologies, we will update this notice and provide consent or opt-out controls where required before enabling them.
5. When information is shared
We do not sell personal information or share it for cross-context behavioral advertising.
Information is shared as needed with:
- Cloud storage providers, including Dropbox and Microsoft OneDrive, to use the connection you authorize.
- Stripe, for payment processing, billing, tax handling, and payment security.
- Hosting, database, email, object-storage, image-processing, and content-delivery providers, to operate, secure, and deliver the service. If we use an outside image-processing provider, it may receive source photos and metadata needed to create optimized versions.
- Authorized workspace members, according to their roles and access permissions.
- Visitors, when a customer publishes content and permits access to it.
- Authorities or other parties, where reasonably necessary to comply with law, protect rights or safety, or investigate fraud and abuse.
- A successor business, in a merger, acquisition, or transfer of the service, subject to appropriate protections and notice where required.
Service providers are engaged to perform work for FolderBloom, not to receive customer content for their independent advertising. Dropbox, Microsoft, and Stripe also maintain their own privacy notices for their services.
6. Retention and deletion
We retain account information, service settings, connected-storage metadata, and optimized image copies while needed to provide your service. Disconnecting a provider stops future access through that connection; it does not necessarily erase existing metadata, gallery copies, billing records, or backups immediately. Cancellation stops renewal and is separate from an account-deletion request.
Download-event records are ordinarily subject to an approximately 13-month retention period. Other records may be retained for different periods based on their purpose, including accounting, tax, security, legal obligations, and dispute resolution.
Workspace owners can request deletion of a workspace from the Team page; it must be confirmed from the account email and is carried out after a 14-day holding period unless an owner or admin cancels it. You can also request deletion by emailing [email protected]. We will verify your identity and authority, explain any effect on shared workspaces and subscriptions, and remove information we no longer need, subject to applicable retention requirements. Residual copies in backups may remain until those backups expire and will not be used for ordinary service delivery. We do not modify or delete your original Dropbox or OneDrive files.
7. Your choices and privacy requests
You can update supported account settings, manage workspace access, change published content and permissions, cancel subscription renewals, and disconnect cloud storage using the dashboard. You may also revoke FolderBloom's access through your storage provider's connected-app settings.
Contact [email protected] to request access to, correction of, deletion of, or a copy of your personal information. Depending on your location and applicable law, you may have additional rights to restrict or object to processing, withdraw consent, opt out of certain processing, or appeal a denied request. We will verify requests, respond within applicable legal timeframes, and explain any lawful limits. You may ask us to reconsider a denied request by replying to our decision with "Privacy request appeal." Where applicable, you may also complain to your local privacy regulator.
We do not discriminate against customers for exercising applicable privacy rights. Deleting information necessary to provide the service can prevent continued use of the affected features.
8. Security
We use safeguards intended to protect information, including hashed account passwords, encrypted stored provider tokens, access controls, and secure connections in production. No system can guarantee complete security. Customers are responsible for keeping credentials secure and reviewing what they publish.
9. International processing
FolderBloom is operated from the United States. Our providers may process information in the United States or other countries where they operate. Where applicable law requires safeguards for international transfers, we will use appropriate safeguards. Contact us with questions about where your information is processed.
10. Children
FolderBloom accounts are intended for adults, and the service is not directed to children under 13. We do not knowingly collect account information directly from children under 13. Contact us if you believe a child has provided such information.
Customers who publish photos or information involving children are responsible for obtaining required permissions and selecting appropriate access settings. Public publication is not private storage.
11. Policy changes and contact
We may update this policy as our service changes. We will revise the effective date and notify customers of material changes by email or through the dashboard where appropriate. If a change requires new consent, we will obtain it before that processing begins.
Privacy questions and requests: [email protected].