Last updated: February 10, 2025
5sync OÜ ("we," "us," or "our") is an Estonian limited liability company registered in Tallinn, Estonia. We are deeply committed to protecting your privacy and personal data. This Privacy Policy describes how we collect, process, store, and safeguard your information when you use our cloud storage and file synchronization service ("Service").
As a company incorporated under Estonian law and operating within the European Union, we are fully subject to and compliant with the General Data Protection Regulation (GDPR), the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus), and all other applicable data protection legislation. Privacy is not an afterthought for us — it is the foundation upon which 5sync was built.
This policy applies to everyone who interacts with our Service, including website visitors, free-tier users, and paid subscribers. By using 5sync, you acknowledge that you have read and understood this Privacy Policy.
We follow a strict data minimization principle. We only collect what is absolutely necessary to operate the Service:
Account Data: When you register, we collect your email address and a cryptographically hashed password (using Argon2id). If you choose a paid plan, your payment details are handled entirely by Stripe — we store only a truncated card identifier and billing country for invoice purposes.
Usage Data: We record login timestamps, session durations, storage quota consumption, and feature interactions (e.g., link created, file uploaded). This data is used solely for service operation, capacity planning, and abuse prevention.
Device Data: We collect your IP address (for rate-limiting and security), browser user-agent string, and operating system version. IP addresses are automatically truncated after 14 days and fully purged after 30 days.
We do NOT access your files. Zero-knowledge encryption means we cannot read them. Every file is encrypted on your device before it reaches our servers. Your encryption keys are derived from your password and never transmitted to us. Even under a lawful interception order, we can only provide encrypted ciphertext that is mathematically impossible to decrypt without your key.
We process your personal data for the following clearly defined purposes:
All 5sync data resides exclusively in Tallinn, Estonia, hosted on dedicated infrastructure provided by Hetzner Estonia. Our servers are housed in Tier III certified data centers with redundant power, climate control, and 24/7 physical security. Data never leaves the European Economic Area.
We implement a defense-in-depth security architecture:
We do not sell, rent, license, or trade your personal data. We do not share data with advertisers, data brokers, or any third party for marketing purposes. Period.
We share limited data with the following processors, each bound by a GDPR-compliant Data Processing Agreement:
We use only strictly necessary cookies to operate the Service. We do not use analytics cookies, advertising cookies, or any third-party cookies whatsoever.
| Cookie Name | Purpose | Duration |
|---|---|---|
session_id |
Authenticates your active login session and maintains state across page loads | Session (cleared when browser closes) |
preferences |
Stores your interface preferences such as display theme and sort order | 1 year |
csrf_token |
Prevents cross-site request forgery attacks on form submissions | Session |
Because we use only essential cookies required for the Service to function, no cookie consent banner is necessary under GDPR and the ePrivacy Directive. There are no tracking pixels, fingerprinting scripts, or behavioral analytics on any 5sync page.
Under the General Data Protection Regulation, you have the following rights regarding your personal data:
To exercise any of these rights, send an email to privacy@5sync.com from the email address associated with your account. We will verify your identity and respond within 30 calendar days. There is no fee for exercising your rights. If your request requires additional time due to complexity or volume, we will notify you of an extension of up to 60 additional days.
If you believe we have not adequately addressed your request, you have the right to lodge a complaint with the Estonian supervisory authority: Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate), Tatari 39, 10134 Tallinn, Estonia — aki.ee.
We retain personal data only for the minimum period necessary to fulfill the purposes outlined in this policy:
5sync is not designed for or directed at individuals under the age of 16. We do not knowingly collect personal data from anyone under 16 years of age. If we discover that a minor has created an account without verifiable parental consent, we will promptly delete the account and all associated data.
If you are a parent or legal guardian and believe that your child has registered for 5sync, please contact us immediately at privacy@5sync.com and we will take swift action.
We may revise this Privacy Policy to reflect changes in our practices, new features, or evolving legal requirements. When we make material changes, we will notify you by email at least 30 days before the updated policy takes effect. A summary of changes will be included in the notification.
Non-material changes (such as formatting or clarification of existing terms) may be made without advance notice. The "Last updated" date at the top of this page will always reflect the most recent revision. We encourage you to review this page periodically.
We have appointed a dedicated Data Protection Officer (DPO) who oversees all aspects of our data protection strategy, conducts internal audits, and serves as the point of contact for data subjects and supervisory authorities.
You can reach our DPO at:
Email: dpo@5sync.com
Address: 5sync OÜ, Attn: Data Protection Officer, Pärnu mnt 15, 10141 Tallinn, Estonia
For any questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us:
5sync OÜ
Pärnu mnt 15
10141 Tallinn, Estonia
Email: privacy@5sync.com