Privacy
Account data includes your email, verification time, preferences, password hash if enabled, and server-managed sessions. We store file names, sizes, deadlines, share configuration, upload metadata, and API key hashes. File contents are stored in a private R2 bucket.
Cloudflare provides Workers, D1, R2, transactional email delivery, and Turnstile bot checks. Requests are processed to authenticate, enforce quotas and sharing rules, deliver requested email, and prevent abuse. Turnstile may process device/network signals as part of its checks.
Files are temporary: access ends at expiry or deletion and queued jobs remove the objects. Account and operational metadata can remain after object deletion. Email-link payloads are encrypted at rest and cleared after delivery or permanent delivery failure; expired verification and download grants are purged.
Share URLs and passwords are access credentials. Do not publish them unless you intend recipients to access the file. API keys are shown once, stored as hashes, scoped, expiring, and revocable. Reminder emails are optional and disabled initially.
AlphaBox is operated by AlphaBlue Thailand. These policies remain drafts pending confirmation of public support, abuse and privacy contacts, jurisdiction and metadata retention schedules before public launch.
AlphaBlue Thailand determines account and operational data processing. Data is used for requested sharing and authentication, allowance enforcement, abuse prevention and applicable legal obligations. Optional expiry reminders can be disabled; authentication and security messages are transactional, not marketing.
Recipients can access shared files and relevant download information, and link holders may forward links. Authorized providers including Cloudflare process infrastructure and security data, potentially outside your country. We do not promise Thailand-only storage or end-to-end encryption. A private bucket restricts public access but does not prevent authorized infrastructure or operator access.
Authorized operators may review reports, relevant metadata and reported content when necessary and proportionate for abuse investigations, security incidents or lawful requests. We do not claim continuous scanning of every upload. Disclosures to authorities require an applicable lawful basis; evidence retention is limited to its purpose.
Subject to identity verification and lawful limitations, you may request access, correction, deletion and other rights under applicable data protection law through the privacy contact to be published before launch. There is currently no self-service account erasure. File deletion does not automatically erase account, audit, abuse or provider backup records. Metadata and backup retention, request handling and international-transfer safeguards must be confirmed before launch.
Authentication and download grants use cookies; theme and language preferences may use browser storage. Turnstile processes security signals under provider policies. Protect credentials and report suspected compromise. The operator will assess incidents and provide notifications where required by applicable law; this draft does not promise an unconfirmed response deadline.