Legal
Privacy
Plain-language draft, last updated Sep 7, 2026. Written honestly by the team and not reviewed by a lawyer yet; if something here is unclear, ask before relying on it.
What we store
Account: email, a salted password hash (never the password), your handle and display name, an optional profile picture, and, if you connect X, your X id, username, and verification status. Sellers add a payout email and country; Stripe holds the identity and bank details, we only store your Stripe account id and payout status.
Activity: receipts for what you buy or sell (with the buyer email masked in seller views), library items, seats, store-credit ledger, Agentic Pay ledger, reviews, tickets and any evidence images you attach, follow lists, saved searches, notifications, agent activity (with tokens and emails scrubbed), download history (no links), sign-in sessions (coarse device label, masked IP), and private notes only you can see.
Where it lives
Everything is stored in a private Cloudflare R2 bucket in Cloudflare's infrastructure; nothing is stored in a browser-accessible location except the cookies below. Uploaded pack files are private objects served only through short-lived signed links. Screenshots and avatars are public because they appear on public pages; we strip metadata from images before storing them.
Cookies
A signed session cookie (14 days) to keep you signed in, a CSRF token, and small preference cookies for theme, display currency, referral attribution (30 days), and compare selections. No advertising cookies and no third-party analytics scripts. Stripe sets its own cookies on Stripe-hosted pages.
Who else sees data
Stripe processes payments and payouts. Sellers see masked buyer emails and the contents of tickets you open with them. Anyone can verify an entitlement key, which reveals a listing and a date but not who bought it. If you connect X, we call X's API once at sign-in. If you follow a link to YouTube or an external site from a listing, that site sees the visit. We do not sell data.
Agents
Tokens you create let software act for you within their stated scope. Anything an agent does with your token is logged on your dashboard. Revoke tokens any time from Account or Sell.
Deletion and export
Export your library and, as a seller, your sales as CSV from the site. To delete your account or specific data, open a support ticket from the email on the account; we remove profile data and revoke tokens and sessions, and keep receipts only as long as needed for tax and dispute handling. Buyers keep downloads of packs they paid for even if the seller deletes the listing.
Children and contact
File Market is for adults; do not use it if you are under 18. Questions go through Support on this site.