Privacy Policy
Effective: 2026-06-10. Last updated: 2026-06-10.
UFA Connect (the "App") is operated by MFT Labs ("we", "us"). This
policy explains what data we collect, how we use it, and how you can
control it. We try to keep it short and free of marketing-speak.
What we collect
The only personal information we collect is what you give us during
registration and use:
- Account details: name, email address, and (optionally) phone number.
- Authentication credentials: a salted+hashed password (we never store the plain text).
- Files you upload: stored encrypted at rest on AWS S3 and served only to you and recipients you explicitly share them with.
- Sharing metadata: who shared what with whom and the permission level you granted (view, download, share).
- Subscription state: the App Store transaction ID and current plan tier, used to enforce storage quotas. We do not see your card details — Apple handles payments.
- Device push tokens: an opaque Apple-provided token per device, used to deliver share notifications. You can disable notifications in iOS Settings at any time; the token is then evicted automatically.
- Email delivery logs: Resend webhook events for messages we send you (verification, password reset, magic-link sign-in) — used solely to detect bounces and stop emailing addresses that don't accept mail.
- Operational logs: request method, path, timestamp, and IP address. Retained for 30 days for abuse investigation; never sold, never shared.
What we do not collect
- No third-party analytics SDKs, no ad networks, no fingerprinting.
- No cross-app tracking. The App's
IDFA use is "none".
- No location data.
- No contact list, calendar, or microphone access.
How your files are protected
- All connections to the server use TLS 1.2+.
- Files are stored in AWS S3 (region
ap-south-1) with server-side encryption enabled by default.
- Access to a file requires a valid signed JWT belonging to either the owner or a current recipient.
- Deleting a file removes both the database row and the underlying S3 object.
Subprocessors
We use a small number of third-party services to run the App. None of them
receive your file contents:
- Apple — App Store payments, push notifications, account-system integration.
- AWS — S3 object storage, server hosting.
- Resend — transactional email delivery (verification, reset, sign-in links).
Your rights
- Sign out of all devices via the account menu in the App.
- Delete your account by emailing info@mftlabs.io; we'll erase your row and all associated files within 7 days.
- Export your data: contact support and we'll prepare an archive of your file metadata and the files themselves.
Children
UFA Connect is not directed at children under 13 and we do not knowingly
collect personal data from anyone under 13. The App Store age rating is
4+ because the App contains no objectionable content, not because we are
marketing to children.
Changes
If we update this policy materially, we'll notify you via the App and
via the email address on file at least 7 days before changes take
effect. Minor clarifications may be made without notice; the "Last
updated" date above always reflects the current revision.
Contact
Questions or requests: info@mftlabs.io.