Name, business email, recovery email, optional phone number, firm or organization, role, and account identifiers.
Effective August 22, 2026
File It! Privacy Notice
This notice explains how Blu Software LLC handles information for the File It website, accounts, licensing, support, demos, and optional cloud services.- We do not sell personal information or share it for cross-context behavioral advertising.
- Stripe processes payment-card information; File It does not store complete card numbers.
- The demo email address is sent to Resend for delivery but is not stored in the File It demo-session record or added to marketing.
- The website, account, and licensing systems are not designed to receive the documents in your local cabinet.
- You may request access, correction, deletion, or another applicable privacy right at support@file-it.com.
1. Scope and responsible company
This Privacy Notice applies to personal information processed by Blu Software LLC (“Blu,” “File It,” “we,” “us,” or “our”) through file-it.com, My File It, purchasing, license activation and entitlement services, downloads, support and sales communications, security reporting, demonstrations, and any File It Cloud enrollment. It does not govern a customer's independent handling of documents inside its own File It installation or third-party sites that publish their own notices.
Blu Software LLC is a New Mexico limited liability company operating in Florida and provides File It throughout the United States. For privacy questions or requests, contact support@file-it.com.
2. Information we collect
Orders, plan, amount, promotion, payment status and processor references, license and tenant IDs, activation state, server fingerprint, eligible release channel, coverage, and support history.
Sales and support requests, subject lines, sanitized details you provide, security reports, replies, product-update preference, and delivery status.
IP address or connection data used for security and rate limiting, browser and device information, request timestamps, error and audit logs, product version, download authorization, and service health events.
The email submitted to deliver a private link, a hashed session token, claim and expiration times, and abuse-prevention events. Sample cabinet activity is not associated with the submitted email in the File It demo-session record.
If Cloud launches and you enroll: plan, protected-storage measurements, retention configuration, backup and restore status, checksums, encrypted-object identifiers, and operational events. Encrypted customer content is treated separately from account metadata.
3. Information we intentionally avoid
File It's marketing website, customer portal, licensing service, and ordinary support intake are not designed to receive client tax documents, social security numbers, financial account credentials, complete payment-card data, medical data, passwords, private encryption keys, or cabinet contents. Do not place that information in a support form, email, demo, or security report. If sensitive information is sent unnecessarily, we may delete or redact it and ask for a sanitized replacement.
4. Where information comes from
We collect information directly from you or your organization, automatically from your browser or File It installation, from Stripe and payment-method providers regarding payment status, from Resend regarding email delivery, from Google Workspace when you correspond with us, and from hosting, security, or infrastructure providers that generate operational records. We may also receive information from a person your organization authorizes to purchase or administer File It.
5. Why we use information
- create, authenticate, recover, and protect accounts;
- process purchases, promotions, taxes, refunds, disputes, and renewals;
- issue and validate licenses, activations, entitlements, signed downloads, and updates;
- deliver requested demo links and expire demo sessions;
- respond to sales, support, account-transfer, and security requests;
- operate, debug, secure, monitor, back up, and improve the Services;
- detect fraud, spam, credential abuse, malicious traffic, and unauthorized access;
- send transactional messages and, only when selected, product or account updates;
- establish, exercise, or defend legal rights and comply with tax, accounting, court, and regulatory obligations; and
- perform another purpose disclosed when information is collected or with consent.
6. Demo email handling
When you request a self-guided demo, the licensing service holds the submitted address only long enough to ask Resend to deliver the single-use link. The File It demo-session record contains a one-way token hash and timing metadata, not the email address. To prevent repeated delivery abuse, we retain for up to 48 hours a keyed, non-reversible HMAC fingerprint derived from the normalized address. The dedicated key is stored separately from the database; the fingerprint is used only for request limits and is not used to contact, profile, or identify the visitor. We do not add the address to a File It marketing list or use it for sales follow-up based solely on a demo request. Resend processes the recipient address and ordinary delivery, security, suppression, and abuse-prevention information under its own retention controls. The demo expires after 30 minutes, although de-identified security and audit events may remain.
7. Customer documents and Cloud encryption
Local File It cabinets remain under the Customer's control. The website, account, purchase, and licensing databases do not need cabinet contents. If Customer separately enables File It Cloud, encrypted backup objects may be stored with a cloud infrastructure provider. The intended design encrypts content before upload so Company personnel do not receive ordinary plaintext access. Operational metadata—such as object size, timestamps, tenant identifiers, checksums, backup result, and restore request—may still be processed to provide and secure the service. Exact Cloud architecture, regions, subprocessors, retention, and key-recovery boundaries will be published before enrollment opens.
8. Service providers and disclosures
We disclose information only as reasonably necessary for the following business purposes or as directed by the Customer:
We may also disclose information to professional advisers, insurers, auditors, acquirers in a corporate transaction, law enforcement, courts, or regulators when reasonably necessary and legally permitted. We may disclose information to protect users, the public, Company, or the Services from fraud, abuse, security threats, or legal claims. We require service providers to process information for contracted purposes and appropriate safeguards where applicable.
9. No sale or behavioral advertising
We do not sell personal information for money and do not share it for cross-context behavioral advertising. We do not currently use third-party advertising cookies. If those practices change, we will update this notice and provide legally required controls before beginning them. Because no sale or targeted advertising occurs, Global Privacy Control and “Do Not Track” signals do not presently change the website's behavior; we will honor legally binding browser signals if a covered practice is introduced.
10. Cookies and local storage
We use essential cookies or similar storage for authenticated account, admin, and demo sessions; request integrity; security; and limited interface state. Authentication cookies are HTTP-only where technically appropriate and expire or are cleared according to the session's purpose. Blocking essential storage may prevent sign-in or demo access. We do not currently use advertising cookies.
11. Email choices
We send transactional messages necessary for purchases, security, account access, recovery, licensing, support, demos, and material service notices. These are not marketing subscriptions. Product news or promotional email is sent only when selected or otherwise legally permitted, identifies Blu Software LLC/File It, and provides an unsubscribe method. Opt-out requests are honored within the period required by law. Unsubscribing from marketing does not stop transactional messages.
12. Retention
We keep information only while reasonably needed for the described purpose, legitimate security and business operations, dispute resolution, and legal obligations. Account, license, entitlement, and ownership records generally remain for the account and license lifecycle. Order, tax, refund, and accounting records may be retained for at least seven years. Support, sales, and security correspondence may be retained while the issue is active and for a reasonable period afterward. Short-lived authentication secrets are stored as one-way hashes and expire according to their stated lifetime. Rate-limit data is temporary. Backup objects, versions, and operational metadata follow the enrolled Cloud retention and deletion settings, subject to technical deletion windows, legal holds, and disaster-recovery copies.
Deletion from active systems may not immediately remove encrypted or access-restricted backup copies. We may retain information where necessary to complete a transaction, maintain a perpetual license record, detect fraud, comply with law, enforce agreements, or establish and defend claims. When practical, we delete, aggregate, or de-identify information that is no longer needed.
13. Security
We use safeguards intended to be reasonable for the nature of the information, including access controls, limited retention, encryption in transit, hashing of one-time secrets, signed licensing and release mechanisms, audit logging, and provider review. No online service or storage system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. Customers should use unique protected email accounts, secure endpoints, current software, verified recovery information, and independent tested backups.
If a security incident triggers notification duties, we will investigate and notify affected individuals and government authorities as required by applicable law. Report suspected vulnerabilities to security@file-it.com.
14. Your choices and privacy rights
Depending on where you live and whether a law applies to Company, you may have rights to know or access personal information; correct inaccuracies; request deletion; obtain a portable copy; opt out of sale, sharing, targeted advertising, or certain profiling; limit use of sensitive information; withdraw consent; and appeal a denied request. We provide reasonable access, correction, and deletion consideration to U.S. users even where a particular state law threshold may not apply, subject to identity verification and lawful exceptions.
Submit a request to support@file-it.com with the account email and requested action. We may verify control of the primary or recovery email and request additional information proportionate to the request. Authorized agents must provide authority and may still require verification of the individual. We will not discriminate against anyone for exercising an applicable privacy right. If we deny a request, you may reply with “Privacy appeal” for review.
15. State-specific information
California residents may request the categories and specific pieces of personal information collected, sources, purposes, categories of disclosures, correction, and deletion, and may exercise applicable non-discrimination rights. In the preceding 12 months, the categories described in Section 2 were collected and disclosed for the business purposes described in Sections 5 and 8; none were sold or shared for cross-context behavioral advertising. Residents of Colorado, Connecticut, Delaware, Iowa, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, Virginia, and other states with applicable privacy laws may exercise the rights their laws provide through the same request process.
16. Children
The Services are for organizations and adults and are not directed to children under 18. We do not knowingly collect personal information from children through the Services. If you believe a child submitted information, contact us so we can investigate and delete it where appropriate.
17. United States processing
The Services are presently offered in the United States. Information may be processed in the United States and in other locations where our providers operate, subject to their contractual and legal safeguards. We do not currently market the Services to individuals outside the United States. Contact us before submitting information if you require a jurisdiction-specific data-processing agreement.
18. Changes to this notice
We will post updates here and revise the effective date. If a change materially reduces existing privacy protections or materially expands how account information is used, we will provide a prominent website or account notice and, where appropriate or legally required, email active account owners before the change takes effect. Changes needed for law, security, fraud prevention, or clarification may take effect sooner. Prior versions may be requested by email.
19. Contact
Privacy requests and questions: support@file-it.com
Security reports: security@file-it.com
Company: Blu Software LLC, a New Mexico limited liability company operating the File It product.
Use the support form for ordinary product issues. Do not include client documents, passwords, payment-card data, or private keys.