FilePort Pro — Privacy Policy
Effective date: August 13, 2026
What this is
FilePort Pro is a free, ad-supported, web-based FTP and SFTP client. You use it to connect to your own server, browse its files, and upload or download files. This policy explains what data the service handles and what we do — and do not — store.
Credentials and server connections
- When you connect, the host, port, username, and password you enter are used only to establish the connection to the server you chose. They are transmitted from your browser to our server, and from our server to your server, for the sole purpose of making that connection.
- Credentials are held only in memory for the duration of your session (and in your browser while the form is open). They are never written to disk, never stored in a database, never logged, and never shared with any third party.
- Your session ends when you disconnect or after a period of inactivity (approximately 15 minutes).
- We do not use cookies or browser storage to remember your credentials. The only data stored in your browser is a non-secret host-key fingerprint, described under “What we do store”, kept so the app can detect a server that changed its identity.
What we do store
- Nothing that identifies your servers or files. Server logs record connection timestamps and error codes (e.g. “connection failed”), not hosts, usernames, passwords, or file contents. This applies to the account and vault layer too: those logs record only event names and error codes, never the content of a saved connection or account activity. File paths you browse may pass through the platform’s network logs as part of normal HTTPS request handling; they are not used by us for any purpose.
-
After you connect to an SFTP server, your browser stores that server’s host-key
fingerprint — a short identifier that is not a credential and is public
(anyone can read it with
ssh-keyscan). It is stored locally in your browser, keyed by server address and port, and is sent to FilePort Pro at connect time only so the service can verify the server’s identity has not changed. It is never logged, never stored on our servers, and is removed when you clear your browser’s site data. If a server’s key changes, the app refuses to connect until you confirm the change. - We may store aggregate, anonymized usage statistics (e.g. “how many connections per day”) to operate and improve the service.
Pro accounts and the saved-connections vault
FilePort Pro is a separate, optional paid tier. Using it is entirely optional — the free client needs no account and stores no credentials.
- Vault saves are personal data. If you choose to save connections in the Pro vault, those saved entries are personal data under data-protection law. They are stored only when you explicitly save them.
- Encrypted at rest (zero knowledge). Saved connections are encrypted before they reach us, with a key only you hold (derived from your account password). We cannot read the plaintext of a saved connection: a breach of our database or backups would yield only ciphertext. Your account password itself is stored only as a salted, one-way hash, never in plaintext.
- While connected, credentials pass through our server. To relay a connection saved in the vault, your credentials necessarily pass through our server in memory to reach your server — exactly as with any direct connection. They are still never written to disk, never stored at rest, and never logged.
- Irrecoverable by design. Because the vault is zero-knowledge, we cannot recover a lost account password or recovery codes, and support cannot unlock a vault.
Security
- Traffic between your browser and our service is encrypted (HTTPS).
- Plain FTP sends your password unencrypted over the internet by design — the protocol has no encryption. The app warns you before making a plain-FTP connection and recommends SFTP (encrypted).
- We cannot guarantee the security of the servers you connect to; that is your environment.
Advertising
- The service is supported by advertising. When an ad network is active, it may serve ads in designated slots on the page and may use cookies or similar technologies to serve and measure ads. Ad scripts run on the same page as the app, as is standard for ad-supported sites, but only inside dedicated ad slots. Credentials are never shared with ad networks: they exist only in your browser session for the duration of a connection and are never stored or logged.
- We do not allow intrusive pop-under or push-ads.
- Ad networks have their own privacy policies. Google's AdSense privacy policy applies to advertising on this site: policies.google.com/privacy.
Analytics
The site uses Google Analytics 4 to measure anonymous, aggregated page-view statistics so we can understand how the app is used. Analytics data contains no credentials, file names, or server addresses you connect to. You can opt out of analytics cookies through your browser settings.
Your control
- On the free tier, since we store no credentials and no account data, there is nothing to delete or export on your behalf. Closing your browser tab or disconnecting ends the session.
- Pro account holders can permanently delete their account and saved-connections vault at any time. Deleted data is removed from live storage immediately and from encrypted backups within the backup rotation; because the vault is zero-knowledge, deletion permanently erases the encrypted records.
- You may decline advertising cookies through your browser settings.
Changes
We may update this policy as the service evolves. Material changes will be noted on this page.
Contact
Questions: support@fileportpro.com