How ShareBolt collects, uses, and protects your data — and your rights under GDPR and CCPA.
Effective Date: June 2026 · Company: ShareBolt · Contact: sharebolt-hello@boreme.in
This Privacy Policy describes how ShareBolt ("we", "us", or "our") collects, uses, discloses, and safeguards information when you visit sharebolt.boreme.in or use our file sharing platform and related services (collectively, the "Service"). Please read this policy carefully. If you disagree with its terms, please discontinue use of the Service.
ShareBolt is a zero-knowledge platform. Files you transfer are encrypted on your device using AES-256-GCM before upload. ShareBolt servers receive and store only ciphertext — we are architecturally incapable of reading the content of your files. Encryption keys are derived locally from your session and never transmitted to our servers. When you use Bring Your Own Storage (BYOS), encrypted ciphertext is written directly to your cloud bucket; ShareBolt never stores it at all.
If you are located in the European Economic Area (EEA) or UK, we process your personal data under the following legal bases:
We use a minimal set of cookies strictly necessary for the Service to function:
We do not use third-party advertising cookies, cross-site tracking pixels, or behavioural analytics tools (e.g. Google Analytics, Meta Pixel). If we add analytics in the future, this policy will be updated and your consent sought where required.
We use Firebase Authentication and Firestore (provided by Google LLC) for user identity management and account data storage. Firebase Auth stores your email address, authentication method, and session tokens. Firestore stores your account profile (plan type, transfer quota usage, preferences). Data is stored in Google's infrastructure under Google's Firebase Data Processing Terms. Google acts as a data processor on our behalf.
Subscription billing is processed by Razorpay Software Private Limited, a PCI-DSS Level 1 certified payment gateway. When you subscribe to a paid plan, you are redirected to Razorpay's secure checkout environment. Razorpay collects and processes your payment details; ShareBolt receives only a subscription status token and masked payment method summary. Razorpay's Privacy Policy governs their processing of your payment data.
For customers paying in USD, subscription billing is processed by Stripe, Inc., a PCI-DSS Level 1 certified global payment processor. Stripe collects and processes your payment details under their Privacy Policy. ShareBolt receives only a subscription status confirmation and masked payment method summary.
If you connect your own storage (AWS S3, Cloudflare R2, Azure Blob Storage, or Google Cloud Storage), ShareBolt acts as a key-exchange coordinator. Encrypted ciphertext is written to your storage bucket directly. ShareBolt does not have access to your cloud provider credentials beyond the scoped presigned URL it generates per transfer. Your cloud provider's data processing terms apply to storage of the ciphertext.
We do not sell your personal data. We do not share your personal data with third parties for their own marketing purposes. We may disclose information:
If you are in the EEA or UK, you have the following rights under the General Data Protection Regulation (GDPR):
To exercise any of these rights, email sharebolt-hello@boreme.in with the subject "GDPR Rights Request". We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority.
If you are a California resident, the California Consumer Privacy Act (CCPA) grants you the following rights:
To submit a CCPA request, email sharebolt-hello@boreme.in with the subject "CCPA Rights Request".
ShareBolt's infrastructure is operated globally, including within the European Union, United States, and India. If we transfer your personal data outside your country of residence, we ensure appropriate safeguards are in place including Standard Contractual Clauses (SCCs) for EEA/UK transfers and Data Processing Agreements with all sub-processors. If you require data residency in a specific geographic region, the Enterprise Citadel plan supports configurable edge routing to restrict data processing to your chosen jurisdiction.
The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without verifiable parental consent, we will take steps to delete that information promptly. If you believe we have inadvertently collected such information, please contact sharebolt-hello@boreme.in.
We implement technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include: client-side AES-256-GCM encryption (zero-knowledge architecture), TLS 1.3 in transit, Firebase Auth industry-standard identity controls, and regular security audits. However, no method of transmission over the Internet or method of electronic storage is 100% secure. We encourage you to use a strong, unique password and enable additional authentication factors.
ShareBolt's zero-knowledge architecture means that files transferred through the Service are encrypted client-side before transmission; ShareBolt servers never receive plaintext file content. Enterprise customers subject to HIPAA may request a Business Associate Agreement (BAA) by contacting sharebolt-hello@boreme.in. Execution of a BAA is required before using ShareBolt to transfer Protected Health Information (PHI).
Enterprise customers and customers subject to the GDPR may request a Data Processing Agreement (DPA) that satisfies Article 28 GDPR requirements. Contact sharebolt-hello@boreme.in to request a DPA. Standard Contractual Clauses (SCCs) are available for international data transfers from the European Economic Area.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting a notice on the Service and, where required by law, by email to your registered address. The "Effective Date" at the top of this page indicates when this policy was last revised. Continued use of the Service after the effective date of a revised policy constitutes your acceptance of the revised terms.
For any privacy-related questions, requests, or concerns, please contact:
We aim to respond to all privacy-related enquiries within 5 business days.