Privacy Policy
Last updated: June 30, 2026
This Privacy Policy explains what data rbox ("rbox", "we", "us") collects when you use the rbox command-line tool, the dashboard at app.rbox.to, and the rbox.to website (together, the "Service"), how we use it, and the rights you have over it.
The short version: we cannot read your files. rbox is end-to-end encrypted and zero-knowledge. Your files are encrypted on your own devices before anything is uploaded, and our servers only ever store ciphertext. We do not hold the keys to your file contents, and we are structurally unable to decrypt, read, scan, or hand over the contents of your synced files — to anyone.
Our security architecture
Because how we are built determines what we can collect, we lead with it:
- End-to-end encryption. Files are encrypted using keys held only on your devices before they leave them. The servers receive and store only encrypted blobs.
- Zero-knowledge. We never receive your encryption keys or a master password. We cannot decrypt your data, and neither can anyone who compromises or compels our infrastructure.
- Your recovery phrase. A 24-word recovery phrase, generated on your device and shown only to you, is what unlocks your data on a new device. We never see it and never store it.
- No key escrow — and what that means. Because we hold no copy of your keys or recovery phrase, if you lose access to all of your devices and your recovery phrase, your data is permanently unrecoverable. This is a deliberate security property, not an oversight. We cannot help you recover it.
Data we collect
- Account email. Authentication is handled by Clerk. We collect the email address (and, if you choose, the name or social login) you use to create your account, so we can identify you and contact you about the Service.
- Device metadata. To coordinate sync we store non-content metadata about each device you link — device names you choose, device public keys, last-seen timestamps, and operating-system type.
- Encrypted file blobs. The actual content you sync is stored as encrypted blobs we cannot read, along with the minimal structural metadata needed to reassemble your files on your devices.
- Billing data. Payments are processed by Stripe. We do not see or store your full card number. We retain a Stripe customer reference, your plan, and billing status so we can provide and bill for the Service.
- Usage and metering counters. We record aggregate counters such as storage consumed, bandwidth used, and sync activity, so we can enforce plan limits and operate the Service. These counters do not reveal file contents.
- Support communications. If you email support@rbox.to, we keep that correspondence to help you and improve the Service.
How we use your data
- To provide, maintain, and secure the sync Service.
- To authenticate you and link your devices.
- To process payments, enforce plan limits, and prevent abuse.
- To send transactional and security messages — for example sync-related notices, device-link alerts, and billing receipts.
- To respond to support requests and comply with legal obligations.
We do not sell your personal data, and we do not use the contents of your files for advertising or profiling — we could not, even if we wanted to.
Sub-processors
We rely on a small set of infrastructure providers to run the Service. Each processes data only as needed to provide their function:
- Cloudflare — infrastructure and encrypted storage. The Service runs on Cloudflare Workers (API), D1 (account and device metadata), and R2 (your encrypted file blobs). Outbound transactional and security email is delivered via Cloudflare's email services, and inbound support email is routed through Cloudflare.
- Stripe — payment processing. Card data is collected and stored by Stripe, not by us.
- Clerk — authentication and account identity.
Data retention
We keep your account data, device metadata, and encrypted blobs for as long as your account is active. If your plan includes version history, prior encrypted versions are retained for the window stated for your plan and then deleted. When you delete your account, we delete your account data and encrypted blobs from active systems within 30 days of your request; residual copies in backups are purged on our normal backup-rotation cycle. Limited billing records may be retained longer where required by tax and accounting law.
Your rights
Depending on where you live, you may have rights under the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended (CCPA/CPRA), and similar laws. These include:
- Access and portability — to know what personal data we hold about you and obtain a copy.
- Correction — to fix inaccurate personal data.
- Deletion / erasure — to have your personal data deleted.
- Objection and restriction — to object to or restrict certain processing.
- Non-discrimination — we will not deny you service or charge you differently for exercising these rights.
You can delete your account and its data directly from the dashboard at app.rbox.to, or exercise any of these rights by emailing support@rbox.to. Note that because of our zero-knowledge design, the contents of your files are already inaccessible to us, so a deletion request removes the encrypted blobs and your account metadata. We do not sell personal data, so there is nothing to opt out of in that regard.
International transfers
rbox is operated using global infrastructure, and your data — encrypted blobs and account metadata — may be processed in countries other than your own, including the United States. Where required, our providers rely on recognized transfer mechanisms such as the EU Standard Contractual Clauses. Because your file contents are end-to-end encrypted, they remain unreadable to us regardless of where they are stored.
Children
The Service is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their personal data.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, provide additional notice where appropriate.
Contact
Questions about this policy or your data? Email support@rbox.to.