Skip to content
Mive
How it works Security Account Your Drive Download
Download How it works Security Account Français

Privacy Policy

Last updated: 9 June 2026

The short version. Your files stay on your PC — we keep no copy of them, never store them, never scan them. We store only the minimum needed to run your account and connect your devices. No ads, no analytics, nothing sold. Delete your account whenever you like and it's gone.

Who we are

Mive is a private file-access service — it lets you reach the files on your own computer from your other devices — operated by an individual based in France. We are the data controller for the limited personal data described below. For any privacy question, or to exercise your rights under the GDPR, write to [email protected].

What we collect

We keep as little as possible. Here is everything:

  • Your account — your email address, your first and last name if you choose to provide them, and an account identifier. Your password is handled by our identity system and is never stored by Mive and never kept in plain text.
  • Your computers — for each PC you enroll, a name you choose and a security identifier derived from its certificate. We collect no system information: no operating system, no IP address, no hardware identifiers, no list of your files.
  • Your shares — when you share a file or folder, we keep a small record so the right people can find it under "Shared with me": which item, on which of your computers, who you shared it with, and whether they can view or edit. We never store the file itself.
  • Connecting your devices — a temporary private network address (valid a few minutes at a time) so your devices can reach your PC. No public IP address of your devices is stored.
  • Your session — a single secure cookie to keep you signed in. The tokens that prove your sign-in stay on our server and are never handed to your browser.
  • Minimal operational logs — to keep the service secure and reliable, our servers may record account or device identifiers and timestamps. We never use these to track you, and we keep no web-analytics access logs.
  • Your abuse reports — if you report content, we keep the reason you picked, any details you added, the reported item or link and its owner, and the date. For a report filed without an account from a public link, we also keep the IP address, solely to limit abusive submissions. This is what lets us act on the report and keep a record of it.

What we never collect

We never collect the contents, names, or metadata of your files. We use no analytics, no trackers, and no advertising identifiers. We do not collect your location, and we build no profile of you.

When you share by email

If you choose to share a file or folder by email, we use Brevo to send the recipient a one-off notification containing your share link. We process the recipient's email address solely to send and deliver that message — we don't use it for anything else, don't add it to any contact or marketing list, and don't keep it beyond what's needed to send the email and handle its delivery. Brevo rewrites the links in these emails for delivery click-tracking.

Your files stay on your machine

This is the whole point of Mive. Your files live on your own PC's disk. They are never uploaded to us, never copied, never scanned, and never stored on our servers. Your devices reach your PC over a private, encrypted connection (a WireGuard tunnel, with TLS at the public edge). Uninstall Mive and every file is exactly where you left it.

Why we process your data

Under the GDPR we rely on two legal bases:

  • Performance of a contract — to create your account and run the service you asked for.
  • Our legitimate interest — to keep the service secure and prevent abuse, and to deliver the share-by-email notifications you ask us to send (which includes handling the recipient's email address for that one purpose).

Cookies

We use exactly one cookie: a strictly-necessary session cookie that keeps you signed in. It is HttpOnly and, in production, marked Secure. We use no analytics cookies, no advertising cookies, and no third-party cookies.

Who else is involved

To run the service we rely on a small number of infrastructure providers:

  • Hetzner — hosting, in the European Union (Germany).
  • Cloudflare — DNS and content delivery.
  • Let's Encrypt — TLS certificates.
  • Brevo — sending our transactional emails (France, European Union): address verification, password resets, and the share-by-email notifications you trigger when you share a file or folder by email. To send a share notification, Brevo processes the recipient's email address and rewrites the links in that email for delivery click-tracking.

Our identity system and our certificate authority run on our own infrastructure. We use no third-party analytics or marketing services, and we never sell your data.

How long we keep your data

We keep your account data only while your account exists. When you delete your account, we remove it in a cascade — your account, your enrolled computers, their certificates, your network leases, and your identity record — within a few minutes. Connection data is ephemeral (network leases last about half an hour; your session ends when you sign out or it expires). A recipient's email address used for a share notification is not kept beyond sending that one message. Operational logs are kept for up to about 90 days, and routine encrypted backups roll over within about 35 days. An abuse report you filed is the one exception: we keep it so we can act on it and hold a record, but your identity is stripped from it when you delete your account.

Your rights

Under the GDPR you can ask to access, correct, delete, restrict, or port your personal data, and to object to its processing. Email [email protected] and we'll act on your request. You also have the right to lodge a complaint with the CNIL, the French data-protection authority.

International transfers

Your data is hosted in the European Union. Cloudflare, which provides our DNS and content delivery, may process limited technical data (such as the domain you connect to) outside the EU; where it does, it relies on the standard safeguards required by the GDPR.

IP addresses

Like any internet service, our servers receive your device's IP address in order to send responses back to it. We do not store your IP address for advertising or profiling.

Children

Mive is not directed at children under 15, the age of digital consent in France. If you believe a child has created an account, contact us and we will remove it.

Changes to this policy

We may update this policy from time to time. When we do, we'll change the "last updated" date above, and for significant changes we'll make a reasonable effort to let you know.

Questions? [email protected]

© Mive
Open your drive Download How it works Security Account Privacy Terms Legal