Privacy Policy
- 1. Who we are
- 2. Information we collect
- 3. How we use information
- 4. Your files and server credentials
- 5. The YayFTP connector for Claude (MCP)
- 6. Third-party sharing and service providers
- 7. Data retention
- 8. Security
- 9. Your rights and choices
- 10. Children
- 11. Changes to this policy
- 12. Contact us
1. Who we are
YayFTP (“YayFTP,” “we,” “us”) is a browser-based FTP/SFTP client and file-transfer service operated by Global Transaction Systems, LLC, a Washington limited liability company, located at PO Box 1813, Lynnwood, WA 98046. This policy describes how we collect, use, and protect information when you use yayftp.com, our APIs, and the YayFTP connector for Claude and other MCP-compatible clients (together, the “Service”).
2. Information we collect
Information you provide
- Account information. Your email address and a password. Passwords are stored only as one-way cryptographic hashes; we never store or see your plaintext password.
- Saved site credentials. If you save an FTP or SFTP site in the Site Manager, we store its hostname, port, protocol, username, and password or private key. Passwords and private keys are encrypted at rest with AES-256-GCM. Raw credentials are never returned to your browser or to any API client after they are saved.
- Support communications. Anything you send us when you contact support.
Information created when you use the Service
- API keys. When you create a YayFTP API key, we store only a SHA-256 hash of it. The full key is shown to you once, at creation, and cannot be retrieved afterward.
- Operational logs. We keep standard server logs (timestamps, IP addresses, request paths, response codes) and records of file-transfer operations (for example: which tool was called, the site and path involved, file sizes, and success or failure). These logs help us operate, secure, and debug the Service. Log entries do not include the contents of your files.
- Cookies. We use a session cookie to keep you signed in. We do not use advertising cookies or cross-site tracking. We do not use third-party analytics.
3. How we use information
We use the information above to:
- Provide the Service: authenticate you, connect to the servers you designate, and transfer the files you ask us to transfer;
- Secure the Service: detect abuse, enforce rate limits and transfer caps, and investigate incidents;
- Communicate with you: account verification, password resets, security notices, and replies to support requests;
- Improve the Service: diagnose errors and understand aggregate usage.
We do not sell your personal information. We do not use the contents of your files or your stored credentials for advertising, profiling, or training machine-learning models.
4. Your files and server credentials
YayFTP is a transfer conduit between your browser (or an MCP client acting on your instruction) and servers that you control. When you upload, download, or edit a file:
- File contents pass through our servers transiently for the duration of the transfer. We do not keep persistent copies of your file contents on YayFTP infrastructure.
- Automatic backups created by the Service (for example the
.yayftp-bakfolder written before an overwrite or delete) are stored on your own server, not on ours, and are under your control. - Your saved server credentials are used solely to open the connections you request. Our staff cannot view your saved passwords or private keys in plaintext.
5. The YayFTP connector for Claude (MCP)
YayFTP offers a remote MCP server that lets AI assistants such as Claude perform file operations on your behalf, using your YayFTP account and only the sites you have saved. When you use the connector:
- Every operation is authenticated with your YayFTP credentials and is limited to sites saved in your account.
- We receive only the tool calls the assistant makes for you (for example, “list this directory” or “upload this file”) and the file content involved in those calls. We do not receive, request, or store your conversation history, prompts, or any other content from your AI assistant.
- Requests reach us via the AI platform you use (for example, Anthropic). That platform’s handling of your conversations is governed by its own privacy policy, not this one.
- Write and delete operations create a timestamped backup on your server before changing or removing a file, where technically possible.
6. Third-party sharing and service providers
We share information only with service providers that help us run the Service, and only what they need to perform their function:
| Provider | Purpose | Data involved |
|---|---|---|
| Namecheap, Inc. | Web hosting and infrastructure | All service data resides on infrastructure they operate |
| Twilio SendGrid | Transactional email (verification, password reset) | Your email address and message content. Click and open tracking are disabled. |
We may also disclose information if required by law, to protect the rights, safety, or property of YayFTP or others, or in connection with a merger, acquisition, or sale of assets (in which case this policy will continue to apply to your information or you will be notified of changes).
7. Data retention
- Account data and saved credentials are retained while your account is active and deleted within 30 days after you delete your account.
- Operational logs are retained for 90 days and then deleted or anonymized.
- Transient file content is discarded when the transfer completes.
8. Security
We protect information with measures including: TLS encryption for all connections to the Service; AES-256-GCM encryption at rest for stored server credentials and private keys; one-way hashing for account passwords and API keys; path-traversal protections and per-operation size limits in our APIs; and automatic pre-write backups for destructive operations. No method of transmission or storage is perfectly secure, but we work to protect your information using industry-standard practices. If you believe you have found a security issue, please contact us at support@yayftp.com.
9. Your rights and choices
You can view and update your account information, and add or remove saved sites and API keys, at any time from within the Service. You may request a copy of your personal information or ask us to delete your account and associated data by emailing support@yayftp.com. Depending on where you live (including under laws such as the GDPR or the California Consumer Privacy Act), you may have additional rights of access, correction, deletion, portability, and objection; we honor such requests as required by applicable law. We do not sell or share personal information for cross-context behavioral advertising.
10. Children
The Service is not directed to children under 13 (or the age of digital consent in your jurisdiction), and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. Material changes will be announced on this page and, where appropriate, by email. The “Last updated” date above reflects the current version.
12. Contact us
Global Transaction Systems, LLC
PO Box 1813, Lynnwood, WA 98046
Email: support@yayftp.com