Privacy Policy
Last updated: September 22, 2026
Who we are
FilePreserve is made and operated by Georgina Hawley ("we," "us," "FilePreserve"), an independent software maker. You can reach us at hello@filepreserve.com.
What FilePreserve is, and why this matters for data handling
FilePreserve is a Salesforce managed package for regulated teams (FDA CAPA/complaint documentation, CMS RADV audit response) that archives files off active Salesforce storage, enforces retention and legal-hold rules, and merges/exports files across a record's related lists on demand. Because it's built for compliance-sensitive data, the core design decision behind everything below is simple: your Salesforce record data and your archived files never leave infrastructure you already own and control.
Salesforce record data
FilePreserve runs entirely inside your own Salesforce organization as a managed package. It reads the object/record data you configure an archive job to act on, using the permissions and sharing rules of whichever user is running it — FilePreserve never sees or accesses more than that user already has access to inside your org. There is no external API call, and no third-party service, involved in reading or evaluating your Salesforce records. Your record data is never sent to FilePreserve's own infrastructure — it stays inside your Salesforce org. (Archived files are handled separately — see the next section.)
Archived files — your own AWS S3 bucket, not ours
When an archive job runs, files are moved to an AWS S3 bucket that you create and control in your own AWS account. FilePreserve connects to it using Salesforce's native AWS Signature Version 4 authentication (a built-in Named Credential/External Credential pattern) — there is no FilePreserve-operated storage layer in between. We never host, proxy, or retain a copy of your archived files ourselves. This is a deliberate design choice, not just a technical detail: hosting regulated compliance data ourselves would make us a data processor/custodian for FDA- and CMS-adjacent records, which is a compliance-certification burden we've chosen not to take on. Your files stay in an AWS account you already audit and control.
This is documented in more operational detail in the setup guide's storage section (see Setup Guide) and in the product's own buyer-facing data-handling material if you've requested a copy as part of an evaluation.
Retention, legal hold, and disposal data
Retention periods, legal-hold flags, and disposal-mode settings (Preserve forever, Ask me first, or Delete automatically after a notice period) are configuration you set and that lives in your own Salesforce org as custom object records — not data we see or store. When a disposal job actually deletes a file, it deletes it from your S3 bucket and your Salesforce org directly; we don't retain a separate copy or log of deleted file content anywhere.
Usage data we do collect
We do not collect telemetry about your archive jobs, record content, or file contents. If you contact us for support, we keep that email correspondence to respond to you and for our own support records — nothing more.
Billing information
Billing is handled directly by Stripe, a PCI-compliant third-party payment processor. We do not see or store your full payment card details — Stripe handles that directly and processes it under its own privacy policy. We receive confirmation that a subscription is active, tied to your org's identity, so we can manage your account, plus standard billing information (email, subscription status) needed to administer that subscription.
Website data
filepreserve.com uses Cloudflare Web Analytics to understand aggregate traffic (pages visited, referral source, general location by country/region). It's privacy-first by design: no cookies, no cross-site tracking, and no personal data collected or stored about individual visitors — which is why this site doesn't show a cookie-consent banner. We don't use this data for anything beyond understanding how people find and use the site.
Data retention and deletion
Because FilePreserve never stores your Salesforce record data or archived files outside your own infrastructure, there is nothing on our end to delete when you uninstall the package — uninstalling removes FilePreserve's own objects and configuration from your org per Salesforce's standard managed-package uninstall process. What happens to files already archived in your S3 bucket at that point is entirely under your own control, since that bucket is yours. Billing records are retained by Stripe per their own retention policy.
Changes to this policy
If this policy changes in a way that affects what data FilePreserve touches or how it's used, we'll update the date at the top of this page and, for material changes, notify active subscribers by email.
Contact
Questions about this policy: hello@filepreserve.com.