FlareDrop

FlareDrop Privacy Policy

Last updated: 2026-08-13

FlareDrop is a native macOS client for Cloudflare R2, Backblaze B2, AWS S3, and other S3-compatible storage. This policy describes what the app does and does not do with your data.

What we collect

Nothing. FlareDrop has no analytics, no telemetry, no crash reporting service, and no user accounts of any kind. We do not operate any servers, so there is nowhere for your data, your usage patterns, or your credentials to be sent. Nobody working on FlareDrop can see what you upload, download, or sync, because we never receive any of it.

Where your credentials live

Access keys and secret keys for the storage accounts you configure are stored only in your Mac's Keychain. They are never transmitted anywhere except to the storage endpoint you configured that account to use, as part of signing your own requests. FlareDrop signs every request locally using AWS Signature V4; your secret key never leaves your machine, not even to us, because there is no "us" to send it to.

Network connections

FlareDrop's only network traffic is to the storage endpoints you explicitly configure: your Cloudflare R2 account, your Backblaze B2 bucket, your AWS S3 bucket, or another S3-compatible endpoint you enter yourself. The app does not phone home, check for updates over a tracking channel, or contact any FlareDrop-operated infrastructure, because none exists.

Local data

FlareDrop keeps a local metadata file (metadata.json) in your Mac's Application Support folder. It records things like configured account nicknames and endpoints, bucket/folder favorites, sync job settings, transfer history, and file fingerprints used to detect changes for sync. It does not contain your secret access keys (those are Keychain-only) and it does not contain the contents of your files. This file never leaves your Mac; FlareDrop does not upload it anywhere.

Encryption keys

If you turn on optional client-side encryption for an account, FlareDrop generates a 256-bit AES-256-GCM key on your Mac and stores it in Keychain, the same as your storage credentials. The key is never transmitted to us or to your storage provider. If you export a recovery copy of the key, that export happens only when you initiate it, and the resulting file is yours to store wherever you choose — we have no part in that process and no visibility into it.

Changes to this policy

If this policy changes, the updated text will be published at https://fdpp.deployhighrise.com and the "Last updated" date above will change accordingly.

Contact

FlareDrop does not run a support desk or collect contact information. For questions about this policy or the app, email:

support@deployhighrise.com