Skip to content

Privacy Policy

Last updated: 11 September 2026.

1. Who we are and what this policy covers

MiniKiwi operates file.kiwi. This policy describes how we process personal information when you visit the Service, create an account, use a Web Folder, purchase paid features, connect supported services, or contact us.

This is our international Privacy Policy, intended for users outside the Republic of Korea, including the United States and the European Economic Area (EEA). The same document is available to all readers of this version. Language, nationality, or a detected country code does not by itself determine which privacy law applies.

Sections 1–9 and 12 describe our general practices and request procedures. Sections 10 and 11 provide additional regional information and rights when the relevant law applies to you or our processing. If an applicable regional provision conflicts with a general provision, the regional provision takes priority. Nothing in this policy limits rights that cannot lawfully be excluded.

MiniKiwi determines the purposes and means of processing account, Service-operation, support, and related business information and is responsible for that processing as its controller. Dodo Payments is separately responsible for its own transaction-related processing, as explained in Section 5.

  • Business name: MiniKiwi
  • Business registration number: 144-32-00617
  • Address: Unit 409-Sa5, 168 Gwanak-ro, Gwanak-gu, Seoul 08788, Republic of Korea
  • Privacy contact: Cho Yoseob
  • Email: [email protected]
  • Telephone: +82-508-2774-8812

EU representative under Article 27 GDPR: Europe Services, SE, Na Cecelicce 425/4, Smichov, 150 00 Praha 5, Czech Republic. Data subjects may contact the representative at [email protected] regarding the processing of their personal data.

UK representative under Article 27 of the UK GDPR: REP27 LTD (company number 17385889), Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom. Data subjects in the United Kingdom may contact the representative at [email protected].

Anyone, authorities included, can verify the designations here:

Product definitions and purchase conditions are in our Terms of Use.

2. Information we process and its sources

Analytics-Excluded Countries

We exclude the following countries from our first-party audience measurement through the script-delivery rule described below (the Analytics-Excluded Countries): Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, Iceland, Liechtenstein, Norway, and the United Kingdom.

When a browser requests our analytics script, our hosting provider uses the request’s IP address to identify the country. For an Analytics-Excluded Country, it returns a short notice that analytics is disabled instead of the measurement script. That response does not perform audience measurement. The rule uses the detected location of the request, not your nationality, account language, or place of residence.

This is a script-delivery restriction, not a block on every analytics endpoint. A previously cached copy of the measurement script may continue to run until its cache expires. References below to excluding Analytics-Excluded Countries are subject to this limitation. The exclusion does not automatically delete previously collected records; Section 7 explains their retention.

This exclusion applies only to our first-party audience measurement. It does not exclude information needed for Service operation, security, purchases, support, or connected third-party services.

Information and sources

We receive information from you, your device and interactions with the Service, the account provider you choose, Dodo Payments in connection with your purchase, and Google when you authorize the Connector described in Section 6. Other users may provide information when they share files or collect submissions through a Web Folder.

ActivityInformation involved
Essential Service operation and securityService-use and access records, IP address, access times, browser/device information, country information, and a user identifier when you are signed in. Necessary cookies or browser storage may be used for sign-in, security, language, display, and settings you request.
First-party audience measurementExcluding Analytics-Excluded Countries under the rule above: a random persistent visitor identifier; visit, session, and event identifiers; page path, title, and hostname; referrer URL; visit times, duration, and visibility state; destination URL and domain for outbound-link events; language, time zone, screen dimensions, Web-performance metrics; country, region, city, continent, postal code, approximate latitude and longitude, network organization; browser identification details sent with the request and the browser, operating-system, and device information derived from them. Page query strings and URL fragments are currently excluded. The connection IP address is processed by our hosting provider for location, security, bot detection, and visitor distinction, but is not stored in our analytics visit records in its original form.
Account and Service operationEmail, account, and authentication information; uploaded files and related file-management information; and purchased access, balances, and usage records. We use this information to create and manage accounts, sign you in, store and share files, and provide paid features. Email/password authentication is handled through Google/Firebase.
Payments and refundsOrder/payment identifiers, product and quantity, amount, currency, time, status, customer identifiers, relevant contact details, the express request and acknowledgement relating to immediate Service provision, the applicable policy version and confirmation time, and refund/dispute records. We also use a hash of the purchaser’s email address to help identify duplicate purchases.
Support and privacy requestsYour reply address, message, information needed to identify the account or purchase, relevant technical details, and our correspondence and handling records.
Reliability and diagnosticsLimited error and diagnostic information.

When you use the public refund-request form, the name, purchase email address, product, purchase reference, optional details, request content, and receipt time are sent by email to [email protected], with a confirmation copy to the purchase email address you entered. The form does not require an account and does not save a separate copy of the submission in a file.kiwi application database. The messages and delivery records remain subject to the retention and security practices of our support mailbox and email delivery provider. The form also uses a security check to prevent automated abuse. Our security provider processes the verification, network, and device information needed for that check. See the Cloudflare Turnstile Privacy Notice.

We handle linkable email hashes and other pseudonymous identifiers as personal information.

To process account deletion requests and check their completion, we use the account identifier, a hashed browser-session identifier where available, processing stages, the request time, and the account deletion result. Where needed, these records are sent to our responsible staff by email. These messages exclude passwords, access tokens, file contents, and raw error messages. We retain the records only as needed to handle the request and confirm deletion, unless a legal retention obligation applies.

Payment details entered into Dodo Payments checkout are handled by Dodo Payments and its payment providers.

Uploaded files may contain personal information about you or other people.

Our support chat stores conversations and associated contact information so that our support team can respond and review the conversation. Support notifications and replies may also be delivered by email where an email address is available.

For error diagnosis, file.kiwi filters reports before sending technical error information to an external diagnostic service. The filtered reports contain error categories, recognized diagnostic message templates, application versions and environments, severity, and code locations and function names in public application files and recognized server modules. Server bundle names are normalized to remove private build directories and random suffixes. Reports also include the affected page or route with dynamic identifiers removed, browser type and major version, and operating-system family. The filter removes unrecognized free-text error messages, user identifiers, original client IP addresses, URL query strings and fragments, full User-Agent strings, and arbitrary metadata.

3. Purposes and grounds for processing

We process personal information for the purposes below. References to contract, legitimate interests, and legal obligations explain the grounds used where the applicable privacy law requires a lawful basis; they do not mean that every jurisdiction uses the same framework. Section 10 further explains the EEA grounds. Agreeing to this policy is not blanket consent to every activity listed here.

PurposeGrounds for processing
Set up an account, authenticate users, provide requested file features, and manage Upload-GB purchases, allocations, and usagePerformance of our contract with you, or steps you request before entering it.
Verify purchases, activate paid features, communicate about an order, and process cancellations or refundsPerformance of the purchase or Service arrangement and compliance with applicable legal obligations.
Respond to support requests and resolve Service problemsContract performance where connected to your Service; otherwise our legitimate interest in providing effective support.
Keep required transaction, accounting, complaint, and compliance recordsCompliance with the particular legal obligation requiring the record.
Protect accounts and infrastructure, detect abuse and duplicate payments, diagnose errors, handle payment disputes, and establish or defend legal claimsOur legitimate interests in operating a secure and reliable Service, preventing loss, and resolving disputes, subject to your rights and reasonable expectations.
Measure Service use, visits, acquisition sources, performance, and country-level trends without advertising or cross-site trackingOur legitimate interest in understanding and improving the Service through first-party measurement excluding Analytics-Excluded Countries under the rule in Section 2.

Information needed for account authentication, payment identification, or a requested feature is necessary to perform that activity. Without it, we may be unable to provide the relevant feature or resolve your request. Non-essential tracking is not a condition of purchasing the Service.

Where you are not a party to our contract, such as a respondent to another user’s form, we do not treat that user’s contract or OAuth authorization as your consent. The purpose and the parties’ roles determine the appropriate processing ground. The form or Web Folder organizer is responsible for explaining its own collection and use; this policy explains file.kiwi’s handling.

Before using information for a materially different purpose, we will provide the necessary information and establish the appropriate processing ground, including obtaining new consent where required.

4. Cookies, similar technologies, and analytics

The Service may use cookies or browser storage where necessary for sign-in, security, language, display, and settings you request. Blocking or deleting this necessary storage may prevent a sign-in state or selected setting from being retained. We do not use this storage for advertising or audience measurement.

Language suggestion display setting: We may check your browser’s language preferences to suggest an available language. When you click the language-change button or the language suggestion tooltip, we store only a flag in your browser’s local storage (localStorage) to prevent the suggestion from appearing again. This flag is not sent to our servers or used for advertising, audience measurement, or user tracking. It has no automatic expiry. Clearing file.kiwi’s site data in your browser settings removes the flag, and the language suggestion may appear again.

We operate our own audience-measurement service. Excluding Analytics-Excluded Countries under the rule in Section 2, it does not set an analytics cookie, but it stores a random visitor identifier in your browser’s local storage so that repeat visits can be distinguished. If you block or delete that storage, a later visit may be counted as a new visitor.

Excluding Analytics-Excluded Countries under the rule in Section 2, the script sends the page path and title; referrer URL; visit, duration, and visibility events; language, time zone, screen dimensions, device and browser information; and Web-performance measurements. Page query strings and URL fragments are currently excluded. Pages displayed in an iframe and outbound-link clicks may be counted as separate events.

Analytics-Excluded Countries are excluded through the IP-based script-delivery rule described in Section 2, subject to the cached-copy limitation explained there.

This measurement, excluding Analytics-Excluded Countries under the rule in Section 2, is not used for advertising or to combine a visitor’s activity across unrelated websites. The information and retention criteria are described in Sections 2 and 7.

Google services embedded in the Service may receive device and activity information when they load or you interact with them. Depending on the service and your account settings, Google may associate that information with activity on other services. Google’s Privacy Policy and account controls describe its own processing. Our first-party measurement practices do not determine Google’s separate practices.

5. Sharing information and Dodo Payments

Service providers and recipients

We share information to provide the Service, respond to your instructions, meet legal obligations, and protect legitimate interests as described above. Access must be limited to what the recipient needs for its role.

  • Google/Firebase: Account authentication and infrastructure used for the Service. Google also provides the connected Forms functionality described in Section 6.
  • IDrive Inc. (IDrive e2): Provides file storage alongside Cloudflare R2. It processes encrypted file data and the storage identifiers and metadata needed to store and retrieve it on our behalf. Files transferred to this storage remain subject to the expiration and deletion rules in Section 7. Storage location and provider information are explained in Section 8.
  • Cloudflare: Hosts and delivers the Service, stores Service and support information, delivers emails, provides security and automated-abuse checks, and hosts our first-party audience measurement, excluding Analytics-Excluded Countries under the rule in Section 2. It processes the relevant Service records, messages, and network and device information for these purposes. Storage locations and international processing are explained in Section 8.
  • Recipients you authorize: People who receive access or submit information through your Web Folder settings, sharing links, or connected workflows. A recipient may handle information independently after receiving it.
  • Other necessary recipients: Professional advisers or authorities where necessary for a legal obligation or claim, and a successor operator if the business changes hands, subject to appropriate safeguards and any required notice.

Dodo Payments

For purchases where Dodo Payments is the Merchant of Record, Dodo Payments is the legal seller for the transaction. It processes purchase and payment information for purposes including transaction processing, tax, fraud prevention, risk and compliance checks, receipts, refunds, and payment disputes.

Dodo Payments acts as an independent controller for those activities, not merely as a processor acting on MiniKiwi’s instructions. Its Privacy Policy explains its own handling of information and how to exercise rights with it. Where Dodo Payments performs a separate activity solely on our documented instructions, the applicable data-processing arrangement governs that activity.

We send Dodo Payments the product, amount, currency, billing country, and customer information needed for checkout. Depending on the purchase, this includes your email address, user identifier, relevant Web Folder or file identifiers, a hash of the purchaser’s email address, and a record of your immediate-Service request and acknowledgement, including the wording, policy version, and confirmation time, in payment metadata. We receive transaction information through its systems to verify payment, provide access, detect duplicate purchases, and handle support and refunds.

Where needed to resolve a payment dispute, we may share relevant order, delivery or activation records and related support correspondence with Dodo Payments. Any disclosure is limited to what is necessary for that purpose. Our handling of this information is covered by this policy. Dodo Payments’ own processing and retention are covered by its notice and obligations.

6. Google API User Data — file.kiwi Google Forms Connector

file.kiwi Google Forms Connector is optional and accesses Google user data only after you choose to connect a selected form and authorize access. We process the form’s information, upload-reference answers, authorization credentials, and connection records to connect the form to your Collection Web Folder. Other answers may reach our server in Google’s response but are not used, logged, or retained.

You can disconnect or revoke Google authorization to stop new processing. When you use Disconnect, file.kiwi restores the original submission-confirmation message and deletes the Apps Script recovery settings before deleting the D1 connection records. The FileID and UploadURL fields remain, and the original Google Form and its responses are not deleted. We retain connection records while the Connector is provided for the associated Collection Web Folder, and delete them when you disconnect or the Web Folder is deleted, subject to the detailed deletion rules.

The Google Forms Connector Privacy Notice forms part of this policy and explains permissions, data use, providers, international processing, retention, deletion, and privacy requests. file.kiwi’s use and transfer of Google API data follows the Google API Services User Data Policy, including the Limited Use requirements.

7. Retention and deletion

We retain information for its identified purpose, rather than indefinitely simply because it was collected. Different records have different retention periods.

Our scheduled cleanup runs daily. The periods below use calendar months. Eligible records are processed in batches; if a run fails or a backlog remains, cleanup continues on subsequent runs until the outstanding records are removed.

RecordRetention period or criteria
Account and authentication informationWhile needed for the account and Service relationship. Account closure and the treatment of shared resources and retained records are described below.
Service operational informationWhile needed to provide the Service and manage access, balances, and usage. Files follow the applicable expiration and deletion rules. Legal transaction records are retained separately.
Contracts, cancellations, payments, and supply recordsFor the period required by the recordkeeping obligation applicable to the particular record. We retain only the necessary fields; records with no such obligation are kept only as needed to administer the transaction and resolve outstanding claims.
Consumer complaints and dispute-handling recordsUntil the complaint or dispute is resolved and any justified claim-handling or legally required retention period ends. These records are handled separately from routine support-chat history.
Routine support-chat historyConversations and their associated messages, contact information, and handling records are scheduled for deletion six months after the latest recorded customer access or conversation activity. Relevant activity includes new messages, recorded reads, and handling updates. This cleanup covers the chat database; email correspondence and any separately retained complaint or dispute records follow their own retention criteria.
Google Connector dataConnection and related processing records are retained while the Connector is provided for the associated Collection Web Folder. They are deleted when the user disconnects or the Web Folder is deleted; a daily cleanup removes orphaned connection records where no valid Web Folder remains. The Google Forms Connector Privacy Notice explains credential and acceptance-record deletion, shared authorizations, incomplete connection attempts, and information that remains on Google’s systems.
Audience-measurement recordsExcluding Analytics-Excluded Countries under the rule in Section 2, raw visit and event records, including associated event details, are scheduled for deletion six months after collection by our server. A visit linked to a more recent event is retained until that event also expires. Visitor and session identifier lists in hourly summaries are cleared once the entire hour is older than six months. Summary counts, durations, and performance totals remain while needed for Service statistics. The browser visitor identifier remains until you clear the relevant browser local storage; limited provider-managed recovery copies follow Cloudflare’s database recovery period.
Security, error, ordinary support, and backup recordsFor as long as needed for the relevant security investigation, support matter, or legal claim. Provider-managed backup copies follow the applicable recovery cycle.

When you close your account, we delete personal account records that are no longer needed without undue delay. Closing your account does not automatically delete shared Web Folders or uploaded files. To remove them, delete the relevant Web Folders or files before closing your account, or contact [email protected]. Transaction records and unused Upload-GB refund evidence are handled separately from account closure.

If a specific record must be retained for a legal obligation or an actual dispute, we restrict its use to that purpose and delete or anonymize it when retention is no longer justified. Dodo Payments may independently retain transaction information under its own obligations even when you delete your file.kiwi account.

For authentication information held by Google/Firebase, Google states that logged IP addresses are retained for a few weeks. Other authentication information is retained until we initiate deletion of the associated user, after which Google removes it from its live and backup systems within 180 days. This provider-specific period does not apply to all file.kiwi records or to Google Forms. See Firebase’s privacy information.

Cloudflare’s standard database recovery history covers 7 or 30 days, depending on the service plan. Deleted database records may remain recoverable within that window. This recovery window is not a retention period for active records or a statement that all other logs, exports, and backups have the same lifecycle. See Cloudflare’s recovery information.

8. International processing

MiniKiwi operates in the Republic of Korea. Our providers may process information in other countries, whose privacy rules can differ from those where you live.

We use IDrive e2 storage in Oregon, United States. File data and the associated storage identifiers and metadata are transferred over encrypted connections when moved to or retrieved from this storage to provide the Service. IDrive describes its processing and transfer safeguards in its Privacy Policy and Data Processing Addendum, within their applicable scope. See its storage-location information. Its privacy contact is [email protected].

Google/Firebase processes authentication information in the United States. Google Forms and the central integration script use Google’s global infrastructure; the authentication service’s U.S.-only location does not describe those separate services. Google’s FormApp functionality is not covered by the data-region restrictions described for certain other Google services.

Google describes its international processing and transfer mechanisms, including the coverage of Google LLC’s Data Privacy Framework certification, in its data-transfer information. Cloudflare describes the contractual safeguards for covered customer processing in its Data Processing Addendum. These provider arrangements apply within their respective scope; they do not mean that every transfer by file.kiwi or every third-party service is covered by the same arrangement.

Where required, a transfer must have an applicable lawful basis, such as a recognized adequacy decision or approved contractual safeguards with any necessary supplementary protections. You may contact us to ask about the safeguards applicable to your information and how to obtain a copy, subject to necessary redactions.

9. Privacy requests and common protections

Subject to the conditions of applicable law, you may request access to your personal information and a copy of it, correction, deletion, restriction of processing, or a portable copy of information you have provided. You may also object to processing based on legitimate interests and object to direct marketing. For direct marketing, we will stop the processing to which you object.

Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing already carried out before withdrawal. Stopping optional processing does not by itself require you to stop using unrelated Service features.

Send requests to [email protected] or use the postal contact in Section 1. Describe the request and provide enough information to locate the relevant records. You do not have to create an account or cite a law. If needed to determine the rights that apply, we may ask where you reside. We may request proportionate information to verify identity or an agent’s authority where needed and permitted; verification information is used for that purpose. An opt-out request is not subject to identity verification where the applicable law prohibits that requirement.

We will respond without undue delay and normally within one month of receipt. We meet the deadlines applicable to the particular request. Any extension must be permitted by the law that applies, and we will notify you within the required time and explain the reason. The regional deadlines below, including shorter deadlines for certain requests, take priority.

Requests are normally free. If we cannot comply, or a lawful exception permits a reasonable fee or refusal for a manifestly unfounded or excessive request, we will explain the reason and your options to challenge the decision.

You may complain directly to the competent data protection authority, including in the place where you live or work or where an alleged violation occurred, as applicable. You do not have to complain to us first. Your right to seek a judicial remedy is unaffected.

For Dodo Payments’ independent processing, you may use the contact route in its Privacy Policy. We can help direct your request, but cannot erase records that Dodo Payments independently has a lawful reason to retain. Where another user or organization controls information collected through its Web Folder or Google Form, we will explain the appropriate contact and assist within our role.

10. Additional information where EEA privacy law applies

This section applies when our processing falls within the scope of the General Data Protection Regulation (GDPR), including qualifying offers of services to people in the EEA or monitoring of their behaviour there. It is not limited to people with EEA nationality. The EEA comprises the EU member states, Iceland, Liechtenstein, and Norway.

Processing grounds

The contract ground in Section 3 covers processing necessary for our contract with you or steps you request before a contract. Our stated legitimate interests are subject to a necessity and balancing assessment; your interests and fundamental rights can override them. A legal-obligation ground under EEA law must be supported by an applicable EU or EEA member-state obligation. A Korean or other non-EEA obligation does not, by itself, establish that ground. For our own records kept to administer transactions or resolve claims without such an obligation, the relevant ground is contractual necessity or the legitimate interests specifically described in Section 3, subject to their conditions.

Where consent is required, including for non-essential device storage or access, we must obtain it before the relevant activity. Legitimate interests do not replace a required device-storage consent. Our audience measurement excludes Analytics-Excluded Countries under the rule in Section 2; Section 4 describes the measurement arrangements. Processing permission and the safeguards required for international transfers are separate requirements; authorizing a Google connection does not dispense with either requirement.

Rights and timing

In addition to Section 9, where the relevant conditions are met:

  • You may obtain access, correction, erasure, or restriction of processing. Erasure may be limited, for example, where retention is necessary for a valid legal obligation or legal claim.
  • Portability applies to information you provided that is processed automatically on consent or contract grounds. You may request transmission to another controller where technically feasible.
  • You may object to legitimate-interest processing for reasons relating to your situation. We must stop unless we demonstrate overriding compelling grounds or the processing is needed for legal claims. An objection to direct marketing does not require that balancing exercise.
  • You may withdraw consent without affecting processing lawfully carried out before withdrawal. You also have protections concerning decisions based solely on automated processing that produce legal or similarly significant effects, subject to the applicable exceptions and safeguards.

We respond within one month. Complexity or the number of requests may justify up to two additional months; we will notify you and explain the extension within the first month. You can complain to your competent supervisory authority or seek a judicial remedy without contacting us first. Contact details for supervisory authorities are available from the European Data Protection Board.

11. Additional information for U.S. residents

Scope and information categories

U.S. state privacy rights apply when you are an eligible resident and the relevant law covers MiniKiwi and the processing involved. Coverage can depend on the kind of information, our activities, statutory thresholds, and exemptions. This section does not assume that every state law applies to every visitor or every record. It does not restrict any other applicable federal or state protection.

The categories described in Section 2 include identifiers and contact details, account information, commercial and transaction records, internet or device activity, approximate location information, and information in files, forms, or communications you choose to provide. Those files or communications may contain sensitive information; we do not ask you to include unnecessary sensitive information in a support request. Section 2 identifies sources, Section 3 explains purposes, Section 5 identifies recipients and disclosure purposes, and Section 7 explains retention criteria.

Our own audience measurement, excluding Analytics-Excluded Countries under the rule in Section 2, is not used for advertising or combining activity across unrelated websites, as explained in Section 4. This does not mean that no information is disclosed to other organizations: the provider, payment, and user-directed disclosures in Sections 5 and 6 still take place. A connected Google Form or Dodo Payments checkout is also governed by its provider’s own privacy practices.

Rights and requests

Depending on the state law that applies, you may be entitled to:

  • Confirm processing, access personal information, and receive a portable copy, including information about collection and disclosures.
  • Correct inaccurate information or request deletion, subject to permitted exceptions.
  • Opt out of sales of personal information, sharing for cross-context behavioural advertising, targeted advertising, or certain profiling that produces legal or similarly significant effects, where those activities and rights apply.
  • Limit certain uses or disclosures of sensitive personal information, or withhold or withdraw consent to its processing, where required by the applicable law.
  • Use an authorized agent where permitted, and exercise rights without unlawful discrimination or retaliation.

Use the contact methods in Section 9. We will not require an account solely to make a request. For California requests to know, correct, or delete under the California Consumer Privacy Act (CCPA), we respond within 45 calendar days, with up to 45 additional days only where permitted and with timely notice explaining the reason. Other state deadlines apply to requests governed by those laws; the 45-day period is not a blanket waiting period for opt-outs or other requests with a shorter deadline.

If we deny a request, we will explain why. Where your state provides an appeal right, reply to our decision or email [email protected] asking for a privacy-request appeal. We will review it and provide a written outcome and reasons within the applicable state deadline. If the appeal is denied, we will explain how to contact the relevant state authority where required. You may also contact your state Attorney General or other competent privacy regulator directly.

12. Security and policy changes

We use measures appropriate to the information and processing risks, including secure communications, access controls, and the protections described for the Google Connector. If an incident triggers an obligation to notify affected people, we will provide the required notice without undue delay.

We will identify the effective date of changes to this policy and give advance notice of material changes through the Service and, where appropriate, directly to affected users. Where a new use requires consent, updating this policy alone will not replace that consent.

Contact [email protected] with questions about this policy or your personal information.