Privacy Policy
Last updated on October 2nd, 2026
Effective October 2nd, 2026
Our Commitment
Fast prioritizes your privacy. We collect minimal information necessary to enable our services, monitor stability and performance, and improve our offerings. We do not sell user data, show ads in our Services, or collaborate with third-party traffic monetization services or platforms. Our marketing website uses advertising cookies only as described below. Limited analysis of activity is done to prevent abuse, ensure a high level of service performance, and detect bugs. If you have questions, please contact us at privacy@fast.io.
Fine Print
This Privacy Policy of VividEngine, LLC (doing business as Fast Technologies) ("Fast"), in conjunction with the Terms of Service, any Data Processing Agreement (DPA) executed between you and Fast, and other terms and conditions of use which are incorporated herein by reference and may be posted and applicable to specific services, collectively referred to as the "Agreement", governs your use of this website, content, apps, software, products and services provided to you on, from, or through the Fast website or platform (collectively, the "Services"). Fast may modify this Privacy Policy. Significant changes take effect on the effective date stated at the top of this policy, after notice by email or a prominent notice on our website. Your continued use of the Services after a change takes effect indicates your acceptance of the modified Privacy Policy. This modification and continued-use mechanism applies to this Privacy Policy only; an executed DPA is amended only as its Section 13 provides.
Personally Identifiable Information (PII) includes, but is not limited to, names, addresses, email addresses, IP addresses, or any other identifier used to identify or track an individual. We store PII to enable upload and download services, prevent abuse, ensure high service levels (performance and error monitoring), and provide customer support. Under the EU General Data Protection Regulation (GDPR), UK GDPR, California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), and other applicable privacy laws, you have the right to access, rectify, delete, restrict processing of, and object to the processing of your PII. To exercise these rights, please contact us at privacy@fast.io. You may request a portable copy of your data by emailing privacy@fast.io, and you may use an authorized agent. We respond within one month (GDPR) or 45 days (CCPA). When Fast processes personal data contained in a business customer's Content, it acts as that customer's service provider or processor under the Service Provider and Processor Terms in our Terms of Service and, where one has been executed, the DPA.
This Privacy Policy governs your use of the Fast Services, regardless of how you access it, and by using our Services you consent to the limited collection, processing, and storage as described in this Privacy Policy. We automatically receive limited types of information when you interact with our website, apps, services, and platform. This information includes your computer, tablet, mobile, or other digital device's IP address, access times, your browser type and language. We may also collect information about the type of operating system you use, your account activity, and accessed pages. We also collect your phone number (if you enable two-factor verification by phone), approximate country derived from your IP address, device and browser identifiers for each sign-in, and, when you sign documents, your signature image, IP address and user agent. This data is collected in compliance with GDPR and CCPA, ensuring minimal collection and processing. Personal and non-personally identifiable information may be shared with third parties who assist us in providing services. These third parties are contractually obligated to protect your data and use it only for the purposes we specify. In general, Fastio collects data for the purpose of customer services, general business analytics, and platform debugging. Our services are not intended for individuals under the age of 16. We do not knowingly collect personally identifiable information from children under 16. If we become aware that a child under 16 has provided us with personal information, we will suspend and delete the account. For assistance, contact us at help@fast.io.
Your personal information may be used to correspond with you regarding the services, provide customer support, and communicate important updates. We retain data only as long as necessary to provide requested services, comply with legal obligations, and enforce our agreements. When you choose to make Content available, Fast will collect information from other parties for the purpose of preventing abuse, billing, and, in some cases, reporting to you. Some information is retained only as long as necessary to provide requested Services; other information may be retained longer to comply with our legal obligations and enforce our Agreements. Under GDPR and CCPA, you have the right to request the deletion of your personal data when it is no longer necessary for these purposes.
Fast will display your avatar, full name, and email address on various pages of the service to facilitate the services and user identification. Fast is not responsible for any personal information published online through your directed use of the Services. You may receive unsolicited messages from other parties or it may be used in a manner that violates the law, your personal privacy or your safety. By using the Services and publishing Content, you assume the risks and sole liability arising as a result of such information being displayed.
If you are not a resident of the United States, please note that Fast stores your data in the United States; some service providers listed below may process it in other countries. AI processing through Google Cloud Vertex AI's global endpoint may occur outside the United States. By providing any data to Fast, you consent to the transfer of such information to the United States and other jurisdictions. Where you have executed a DPA with Fast, the Standard Contractual Clauses it incorporates apply to transfers of the personal data it covers.
We will not rent or sell your personally identifiable information to third parties. However, we may disclose your personal information or any of its log file information when we have a good faith belief that disclosure is reasonably necessary to (a) comply with a law, regulation, or compulsory legal request; (b) co-operate with investigations of purported unlawful activities; (c) identify persons who may be violating the law or legal notice; (d) protect and defend the rights or property of Fast or third parties; (e) protect the safety of an individual or group; (f) prevent fraud or abuse of Fast or its users. Any such disclosures will comply with GDPR and CCPA requirements, and where possible, we will notify you before disclosing your personal information.
The services use essential cookies to function properly. These essential cookies are first-party, are not used for cross-site tracking, and are not shared with third parties. If you consent to analytics cookies, our marketing website also sets two first-party cookies, "fastio_attribution" and "fastio_touchpoints", which record the referring page, the landing page, campaign (UTM) parameters, and visit times for up to one year, so that signups can be attributed to the campaign that brought them. We delete them if you withdraw that consent. These cookies are not shared with advertising networks. Analytics cookies are described below. On our marketing website (not the web application), with your consent where required, we use Google Ads advertising cookies to measure our ads and to show our ads to visitors on other sites (remarketing). In the United States you can opt out at any time with the "Do Not Sell or Share My Personal Information" link or the cookie banner, and we honor Global Privacy Control signals. Cookies help us save your preferences and session information to enhance your user experience. A cookie is a small data file that we transfer to your digital device. We may use "persistent cookies" to save your ID and related information. We may use "session cookies" and "local storage" to enable certain features of the Service. You are solely responsible for the privacy and security of your digital devices receiving this technology.
Our web application uses PostHog product analytics and session replay as part of operating and improving the Service; they cannot be turned off within the application. PostHog session replay in the web application masks on-screen text and text-bearing attributes and blocks images and media, and autocaptured clicks omit element text and attributes. PostHog may still receive limited customer content in page titles and page addresses (for example a file, folder, or share name) and in error reports. On our marketing website, analytics cookies are optional: PostHog does not record events or sessions there until you consent, and you can change your choice at any time in the cookie banner. This data collection helps us understand how users interact with our Services, improve user experience, and diagnose technical issues. For more information about how PostHog processes your data, please review the PostHog Privacy Policy.
Additionally, third parties may collect Personal Data from individuals using Fast Services. These third parties are bound by their own privacy policies and terms of service. We require our third-party service providers to maintain appropriate security standards for protecting your personal information and to use the data only for specified purposes.
The security of your information is important to us. Fast owns and operates its own servers and network, in leased space at a third-party data center in the United States whose provider maintains its own SOC 2 Type II, ISO/IEC 27001, and PCI DSS certifications (those certifications belong to the data center provider, not to Fast), and employs comprehensive measures to protect information collected from loss, destruction, disclosure, unauthorized access, misuse, and alteration. These measures include encryption of data at rest and in transit, access controls, regular security audits, and employee security training. Although we strive to protect your personal information, Fast cannot ensure or warrant the security of any information you transmit to us, and you do so at your own risk. Sensitive data is stored in an encrypted form. Fast does not receive or store your full card number or security code; Stripe handles them. We do keep billing details such as your billing address and records of your subscription and charges. Under GDPR and CCPA, you have the right to be informed about data breaches that may affect your personal data.
In the event that Fast is acquired, sold or merged with a third party entity, we reserve the right to transfer or assign the information we have collected from you as part of any change of control. In the unlikely event of our bankruptcy, insolvency, reorganization, receivership, or assignment for the benefit of creditors, or the application of laws or equitable principles affecting creditors' rights generally, Fast may not be able to control how your personal information is treated, transferred or used.
Fast utilizes third-party services to provide and improve the Services. By using our services, you agree that data, including PII, may be shared with these third parties as necessary:
- Google LLC (Google Cloud): AI processing with Gemini and Anthropic Claude models on Vertex AI, and temporary storage of files while AI features process them. Content processed by AI services is used only to provide the features you request. Under our enterprise agreements, Google does not use your content to train its AI models.
- Voyage AI Innovations, Inc. (Voyage AI): Search embeddings for AI-powered search. Content processed by Voyage AI is used only to provide the features you request, and Voyage AI does not use your content to train its AI models.
- LangChain, Inc. (LangSmith): Monitoring and debugging of AI features; records AI requests and responses, which may include prompts, AI answers, and file excerpts
- Brave Software, Inc. (Brave Search): Web search for AI features; receives search queries generated from your request
- Lunaweb GmbH (CloudConvert): File conversion and previews for formats Fast cannot render itself
- Cloudflare, Inc.: Edge network, content delivery, DNS, web application firewall, real-time collaboration, and temporary staging of files uploaded through the Fast MCP server
- Stripe, Inc.: Payments and billing, including Stripe-hosted invoice and payment pages
- Twilio Inc.: Two-factor authentication (SMS, voice call, WhatsApp, and authenticator-app factors) and SMS messaging
- Twilio Inc. (SendGrid): Email, including notification emails that may contain comment excerpts, file names, and thumbnails
- PostHog, Inc.: Product analytics and session replay. PostHog session replay in the web application masks on-screen text and text-bearing attributes and blocks images and media, and autocaptured clicks omit element text and attributes. PostHog may still receive limited customer content in page titles and page addresses (for example a file, folder, or share name) and in error reports
- SmartBear Software Inc. (Bugsnag): Error monitoring
- Intercom, Inc.: Customer support
- MaxMind, Inc.: IP address geolocation (country), United States
- Google LLC (Google Fonts): Font delivery on our websites; Google receives your IP address
- Google LLC (Google Ads): Advertising on our marketing website (remarketing and ad measurement); Google receives cookie identifiers, your IP address, and the pages you visit on our marketing website. Set only with your consent where required
- CookieYes: Cookie consent management on our marketing website
- Google Drive, Dropbox, OneDrive, and Box: File import and sync, when you connect one of these services
For the complete, current list of sub-processors and their purposes, please refer to our Sub-processor registry. You may also connect, or direct Fast to connect to, third-party services you choose (such as MCP servers and integrations); when you do, you direct us to share the relevant data with that service to perform what you requested, and you control those connections. If you sign in with a Google or Microsoft account, Fast receives your name, email address, and account identifier from that provider.
Desktop Applications
When you use our desktop applications for macOS and Windows ("Desktop Client"), we may collect additional information to provide synchronization services and improve performance. This includes: file metadata (names, sizes, modification dates, and folder structure) for files you choose to synchronize; application logs and crash reports; device information including operating system version, hardware identifiers, and application version; and synchronization status and performance metrics. The Desktop Client stores authentication tokens locally on your device to maintain your session. We do not access or analyze the contents of your synchronized files except as necessary to provide the Services or as described in our Terms of Service. You can uninstall the Desktop Client at any time, which will remove locally stored application data but will not automatically delete your data from our servers.
Programmatic Access and Agent Accounts
When you access our Services through APIs, MCP (Model Context Protocol) servers, SDKs, or other programmatic methods, or when you register and operate Agent Accounts, we collect and process additional data to ensure platform security and prevent abuse. This includes: API keys and authentication tokens; request logs including timestamps, endpoints accessed, IP addresses, and request parameters; usage patterns and rate limit metrics; and information about the application, agent, or system making requests (such as user-agent strings and client identifiers). We actively monitor programmatic access for anomalous patterns, potential abuse, and security threats. This monitoring may involve automated analysis of access patterns, request frequencies, and behavioral signals. Data from programmatic access may be retained longer than standard user data for security analysis, abuse prevention, and legal compliance purposes. If you operate Agent Accounts, you acknowledge that all actions taken by those agents are attributable to you, and associated data will be processed accordingly.
Legal Basis for Processing
Under GDPR and UK GDPR, we process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to provide you with the Services you requested, including account creation, file storage, synchronization, and customer support.
- Legitimate Interests: Processing for platform security, fraud prevention, abuse detection, service improvement, and analytics, where our interests do not override your fundamental rights.
- Legal Obligation: Processing required to comply with applicable laws, regulations, or legal processes.
- Consent: Where required, we obtain your consent for specific processing activities such as marketing communications, advertising cookies on our marketing website, or optional AI features.
Data Retention
We retain your personal data only as long as necessary for the purposes described in this Privacy Policy. Our general retention practices include:
- Account Data: Retained while your account is active. After a share, workspace, organization, or user account is closed or deleted, its data is kept for a recovery period before it is permanently purged: 15 days for shares, 30 days for workspaces, 60 days for organizations, and 90 days for user accounts. An organization with a billing subscription history (including a trial) is kept for 180 days, and so are its shares and workspaces. An organization that Fast closes because a subscription was never started is purged after 7 days, along with its shares and workspaces. A user account that owns an organization still awaiting deletion is not purged until that organization is. Some data is kept longer: data under a legal hold, until the hold is released; e-signature envelopes and their records, for up to seven years; billing and tax records, as the law requires; usage records, for up to 120 days; activity history and audit records, as needed for security, audit, and legal purposes; backups, which contain account and file metadata but not file contents, for no longer than one year and restored only for disaster recovery; and copies held by Sub-processors, which are deleted on their own schedules.
- Content and Files: Deleted according to your instructions or upon account termination, subject to the recovery periods above.
- Usage Records: Detailed usage records are summarized into daily totals after 45 days and into monthly totals after one year. These records support billing, and after an account is deleted they are kept for up to 120 days to resolve billing disputes.
- Organization Audit Log: 30 to 365 days depending on plan while the organization exists; deleted when the organization, workspace, or share is purged, except activity history and audit records kept as described above.
- Deletion Audit Records: Kept for up to three years.
- Server and Application Logs: Generally retained for a short period (days to weeks) for debugging and security purposes.
- E-signature Records: E-signature envelopes and their records are kept for up to seven years.
- Backups: Contain account and file metadata but not file contents, are kept for no longer than one year, and are restored only for disaster recovery.
- Billing Records: Kept as tax and financial law requires.
- Legal Holds: Data under a legal hold is kept until the hold is released.
We periodically review our retention practices and update this table when they change. For specific retention inquiries, contact us at privacy@fast.io.
California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). We collect the following categories of personal information, as described in this Privacy Policy:
- Identifiers (such as name, email address, phone number, IP address, and account and device identifiers)
- Internet or other electronic network activity (such as access logs, account activity, and product analytics)
- Geolocation data (approximate country only)
- Commercial information (such as your plan and billing history)
- Professional information (if you provide it)
- Sensitive personal information (only e-signature data and account credentials)
You have the following rights:
- Right to Know: You may request information about the categories and specific pieces of personal information we have collected.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt Out of Sale/Sharing: You may opt out of the sharing of your personal information for cross-context behavioral advertising. Use the "Do Not Sell or Share My Personal Information" link in our website footer, the opt-out button below, the cookie banner, or a Global Privacy Control signal, or email privacy@fast.io.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
We do not sell your personal information. On our marketing website we "share" limited browsing data (cookie identifiers, IP address, and pages visited) with Google for cross-context behavioral advertising, as defined under CCPA/CPRA. You can opt out with the "Do Not Sell or Share My Personal Information" link in our website footer, in the cookie banner, or with a Global Privacy Control signal. The footer link and the button below work even when the cookie banner does not load: they set a first-party cookie, "fastio_ads_optout", that turns off advertising cookies in this browser for one year. We do not share data from the Fastio web application or customer content for advertising.
You have opted out of sale/sharing in this browser. Advertising cookies are off on our website.
Residents of Texas and other states with consumer privacy laws can opt out of targeted advertising the same way.
To exercise your California privacy rights, contact us at privacy@fast.io or use the contact information below. For requests to know, delete, or correct personal information, we will verify your identity before processing your request. Requests to opt out of sale/sharing do not require identity verification.
Cookie Consent
When you first visit our website from a jurisdiction that requires cookie consent (such as the European Union or United Kingdom), we display a cookie consent banner allowing you to accept or manage your cookie preferences. Essential cookies required for the functioning of the Services are set automatically. The attribution cookies described above are set only with analytics consent and deleted if you withdraw it. On our marketing website, analytics cookies are optional: PostHog does not record events or sessions there until you consent, and you can change your choice at any time in the cookie banner. Advertising cookies on our marketing website are also optional: the Google Ads tag does not load until you consent, never loads when your browser sends a Global Privacy Control signal, and you can turn it off at any time in the cookie banner or with the "Do Not Sell or Share My Personal Information" link. Our web application does not use advertising cookies. Our web application uses PostHog product analytics and session replay as part of operating and improving the Service; they cannot be turned off within the application. PostHog session replay in the web application masks on-screen text and text-bearing attributes and blocks images and media, and autocaptured clicks omit element text and attributes. PostHog may still receive limited customer content in page titles and page addresses (for example a file, folder, or share name) and in error reports. You can also manage cookies through your browser settings.
Your Right to Complain
If you are located in the European Union or United Kingdom and believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local data protection supervisory authority. We encourage you to contact us first at privacy@fast.io so we can attempt to resolve your concerns directly.
Contact Us
If you have any questions about this Privacy Policy or wish to exercise your rights under GDPR, UK GDPR, CCPA, or other applicable privacy laws, contact us by mail at VividEngine, LLC (doing business as Fast Technologies), Attn: Privacy Policy, 4747 Research Forest Dr., Ste 180-265, The Woodlands, TX 77381-4902 or by email at privacy@fast.io.