PRIVACY POLICY

FileOne Privacy Policy

Effective date: July 11, 2026 · Last updated: August 12, 2026

FileOne (the “App”) is provided by Phoenix Studio (“we”, “us”, or “our”). This policy explains how the App accesses, uses, stores, transfers, and deletes data related to you.

1. Data We Process

Files and media on your device

After you grant permission, FileOne accesses files, file names, folder structure, and media metadata on your device to provide file browsing, search, preview, copy, move, compression, extraction, and deletion features. Previewing, playing, exporting, or transferring files between locations may create necessary temporary files and caches on your device; we do not upload them to our servers.

SMB and WebDAV connection information

When you choose to connect to your own SMB or WebDAV server, the App processes the server address, user name, domain (when applicable), and password to establish the connection and read or write the network files you select. If you choose to save a password, the credential is stored on your device using encrypted storage protected by Android Keystore. You can remove saved network locations in the App.

Google Drive, OneDrive, and Dropbox

When you choose to add cloud storage, FileOne completes authorization through the provider’s OAuth page or official authentication component. Your Google, Microsoft, or Dropbox password is handled by the provider and is never read by FileOne. To provide full file-management features, the App processes account display information, authorization tokens, file and folder identifiers, names, sizes, dates, MIME types, and other metadata, together with the contents of files you choose to browse, search, preview, play, upload, download, copy, move, rename, or delete.

Google Drive uses the drive scope, which permits viewing, modifying, creating, and deleting all files in your Drive. OneDrive uses the delegated User.Read and Files.ReadWrite permissions. Dropbox uses Full Dropbox access. Google and Microsoft token caches are managed by their official components; Dropbox long-lived authorization tokens are stored using encrypted storage protected by Android Keystore. FileOne may also store encrypted information required to resume interrupted uploads. When you remove a cloud location, the App clears its local access data and attempts to revoke provider authorization when supported.

Local-network file transfer

When you choose to turn on Browser Transfer, the App provides a file-transfer service on your current local network. Browsers you authorize with the pairing code can view, upload, download, or delete files in the selected transfer folder. Transferred files and file names move only between your device and the local-network devices you select; they do not pass through our servers.

App settings

The App stores necessary settings locally on your device, such as display preferences, recently used locations, and transfer-service state, to provide and restore App features.

2. What We Do Not Do

FileOne does not provide a user-account system or integrate third-party analytics, behavioral-tracking, or crash-reporting services. We do not sell or rent your personal or sensitive data. If a future version adds a service that processes user data, we will update this policy and the related Google Play disclosures before that version is released.

3. Data Transfers and Security

FileOne communicates directly with your device, the server you select, or the cloud-storage provider. Phoenix Studio does not receive your files, passwords, or authorization tokens. Cloud OAuth and file APIs, and supported WebDAV connections, use HTTPS. The encryption and signing capabilities of SMB depend on the server configuration. Browser Transfer uses HTTP, so enable it only on a trusted local network and keep your pairing code secure. When you copy or move data between backends, file content streams through your device from the source to the destination and does not pass through our servers.

4. Permissions

File-access permissions support core file-management functions. Network and Wi-Fi-state permissions support SMB, WebDAV, cloud-storage connections, local-network discovery, and Browser Transfer. Cloud account permissions are requested only when you choose to add the corresponding provider. Notification permission displays status for transfers, background tasks, and media streaming. The install-unknown-apps permission is used only when you open an APK and choose to install it. The set-wallpaper permission is used only when you choose to set an image as wallpaper.

5. Retention and Deletion

You control your files, which remain on your device or on the server, cloud storage, or destination device you select. You can delete files in the App, remove network locations and cloud accounts, or clear FileOne’s app data in Android system settings to delete data stored locally by the App. You can also revoke FileOne’s access in the account security settings provided by Google, Microsoft, or Dropbox. Temporary files and caches are removed when no longer needed and can also be deleted by clearing app data. We do not operate developer servers that store these files or credentials, so we have no remote user records to delete.

6. Third Parties and Children

When you connect Google Drive, Microsoft OneDrive, Dropbox, SMB, or WebDAV, the corresponding provider or server processes data under its own terms and privacy policy. Except to perform a file operation you request, or to open or share a file with an external app you select, FileOne does not disclose this data to third parties. We do not sell, rent, or provide user data to data brokers. The App does not provide accounts or behavioral tracking for children.

FileOne’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7. Updates and Contact

When the App’s data-processing practices change materially, we will update this policy and its effective date on this page. For privacy questions, deletion assistance, or questions about this policy, contact [email protected].