Privacy Policy

Effective date: July 9, 2026

Overview

Bridglet provides managed SFTP hosting. This policy explains what data we collect when you use the service, where it lives, how long we keep it, and how you can access or delete it. It applies to the Bridglet website, dashboard, and SFTP/API endpoints.

Data we collect

We collect the following categories of data:

  • Account data — your email address and a password hash. We never store your password in plain text.
  • Files — any files you or your SFTP users upload to your directories, transferred over SFTP or the API.
  • Connection and access logs — IP addresses, timestamps, and file operations (upload, download, delete) for each SFTP or API connection, used for security and audit purposes.
  • Payment details — subscription and billing information. Card numbers are handled entirely by Stripe; Bridglet never stores or has access to your full card number.

Where your data lives

  • Uploaded files are stored on Bridglet's servers.
  • Account and directory metadata is stored in our PostgreSQL database.
  • Billing and payment details are held by Stripe, our payment processor.
  • Transactional email (confirmations, receipts, notifications) is sent through Resend.

Retention

Files are retained according to the retention period you configure for each directory. Once that period elapses, files are deleted automatically. Account data is retained for as long as your account remains active.

Deletion and export

Self-service account deletion and data export tools are in progress. Until they ship, you can request full account deletion or a complete export of your data by emailing privacy@bridglet.com . We will confirm and act on these requests promptly.

Your rights under GDPR

If you're located in the European Union, you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request erasure of your data.
  • Receive your data in a portable format.
  • Object to certain processing of your data.

To exercise any of these rights, contact privacy@bridglet.com .

Cookies

Bridglet uses only essential session cookies required to keep you logged in and to protect against cross-site request forgery. We do not use tracking or advertising cookies.

Security

If you discover a security vulnerability, please report it to security@bridglet.com .

Changes to this policy

We may update this policy from time to time. If we make material changes, we'll update the effective date above and, where appropriate, notify you by email.