Cloud Storage & Software Tools

The industry files

Your files are the small half. The account records, the logs and the metadata are the rest, and backups keep copies for a while after you delete. On a workplace or family plan the account may not be yours to close, and an administrator can read what is in it.

The read at a glance

Tracking priority Recommended

Years of documents, photos and messages accumulate in one account.

If it leaks Moderate

A leak exposes whatever you stored: your files, messages, and photos.

Expect it kept Indefinitely

Backups and "anonymised" derived data can persist with no clear end date, and purge lags deletion.

Identity demanded Optional

An account needs an email; ID is rare.

Industry profile reviewed 23 August 2026. Also machine-readable via the free API.

If it leaks

What leaks here is the content itself: the files, the messages, the drafts you never finished. On a work account the breach reaches everyone whose documents sat in it, none of whom picked the vendor.

What repeats in the policies

What's on file

The files are the small half

Policies separate your content from what they call service data, and only your content gets the strong promises. Service data is every file you opened, when, from where, on what device and for how long, kept as a record of you using the product.

When the terms move

The deal can change after you have stored everything

This is the trade where terms have visibly changed under people: model-training rights added by default, then walked back after the backlash, more than once. Switching it off is per workspace and often per admin, so the choice is not always yours to make, and a model already trained does not unlearn.

Who you can ask

The account may not be yours to close

Pay for it yourself and you are the customer. If an employer or a school pays, they are, and the vendor answers to them: an administrator can read, export and hand over what is in your account, and a deletion request goes to that organisation rather than to the vendor.

When you delete

Deletion here comes with a number, and a catch

Unusually, most policies say how long: a trash window, then backups and replicas until the rotation catches up, commonly a month to six. The catch is what deletion does not reach. Anything you shared into someone else's workspace stays theirs, and aggregated usage data sits outside the promise entirely.

What a company here typically holds

Worked out from the industry, not from any one company. What you actually handed over is yours to record.

Contact InfoAccount ProfileBrowsing & Activity Messages · maybePurchases · maybeLocation · maybe

What this can reveal about you

Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.

Who matters to you Possible

Shared files and contacts map your network.

What lawfully stays after you leave

Two kinds of hold. Law sets it: a statute makes them keep it. They set it: a ground the company grants itself.

Anonymised, aggregated, or AI-trained data They set it often kept indefinitely

They treat it as no longer being about you, though such data can sometimes be re-identified.

Copies still in backups They set it about 30 to 180 days

Deleted data sits in backups and replicas until the backup rotation reaches it.

Fraud-prevention markers They set it about 2 to 6 years

To flag suspected fraud, often on a shared industry database you cannot reach through the company.

Tax and accounting records Law sets it about 6 years

Tax and company law makes them keep billing and payment records.

Records tied to a live or potential dispute They set it the limitation period of the claim

They can keep records to defend a live or possible legal claim.

Who wants this data

Years of your documents and conversations in one place is the most valuable training material a company can get without buying any, which is why the terms keep moving towards it. Underneath sits the ordinary commercial appetite for usage analytics, kept in aggregate with no end date on it.

Sold or shared Possible

Usage data feeds product analytics; content is generally not sold.

AI training Moderate

Content may train models unless you opt out, which works only going forward.

Even anonymised, this can still be you

Stored content is full of identifiers, and language models attribute writing to its author at scale (Staab et al., ICLR 2024).

Name, date of birth, postcode Typical

Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).

Payment patterns Sometimes

Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).

How you write Sometimes

Language models infer where a person lives, their income, and their sex from their writing alone, at near-human accuracy and at scale (Staab et al., ICLR 2024).

Browsing fingerprint Typical

Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and sparse histories of what people viewed re-identified them against public reviews (Narayanan and Shmatikov, 2008).

The studies Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)·Beyond Memorization: Violating Privacy via Inference with Large Language Models (ICLR 2024, 2024)·How Unique Is Your Web Browser? (Privacy Enhancing Technologies Symposium (PETS 2010), 2010)·Robust De-anonymization of Large Sparse Datasets (IEEE Symposium on Security and Privacy, 2008)

The wording that does the work

Clauses that recur across this industry, and what each one actually permits.

“to provide and improve our services”

“to provide and improve our services”

The catch-all purpose. Analytics, profiling, personalisation and AI training all fit under it. When they want to do something new with your data, this sentence usually already allows it.

The move An objection tells them to use your data to run the service and nothing more.

“we do not sell your personal information”

“we do not sell your personal information”

Usually this means no cash changes hands. Your data can still go to ad networks, analytics firms and partners, because they count that as sharing rather than selling.

The move Use the do-not-sell switch where there is one, and put an objection in writing as well.

“service providers, partners, and affiliates”

“service providers, partners, and affiliates”

This is how your data leaves with no name attached. Recipients are described by what they do rather than named, and you cannot send a request to a company you cannot name.

The move An access request can ask for recipients by name rather than by category, and UK and EU law put that choice with you.

“aggregated or de-identified information”

“aggregated or de-identified information”

Taking your name off does not take away the pattern, and the pattern often still points at you. Policies give themselves free use of this data with no end date, on the basis that it is no longer about you.

The move If a deletion comes back as 'anonymised', keep the reply. It usually means de-identified, and it is their claim, not a fact you can check.

“retained as long as necessary, or as required by law”

“retained as long as necessary, or as required by law”

They can keep it for legal duties, tax rules, fraud prevention, possible lawsuits and their own business reasons. None of those has a firm end date, so deletion turns into something you have to argue for.

The move Which reasons apply to you, and how long each runs, is a request of its own.

“you grant us a licence to use your content”

“you grant us a licence to use your content”

This is a contract term rather than a data setting, so a privacy request cannot undo it. A careful version ends when your account does. A broad one can be passed on, never expires and survives deletion.

The move Their terms say whether the licence ends when the account does. Close the account and log the date here.

“your administrator may access, retain, monitor, disclose or remove information in your account”

“your administrator may access, retain, monitor, disclose or remove information in your account”

On an account provided through work or school, someone in that organisation can open what is in it, keep a copy, hand it to a third party, or delete it, without asking you. The vendor treats this as the customer exercising their own rights over their own data.

The move The request goes to the organisation that bought the account, not to the vendor. What the vendor holds separately is still worth asking for.

“you retain ownership of your content”

“you retain ownership of your content”

Ownership and permission are different things. The same paragraph grants a broad licence to host, copy, transmit, scan and adapt what you upload, because a service cannot run without one. The licence is the part that decides what they can do with your files.

The move What the licence covers beyond running the service is theirs to state.

“deleted content is removed from our active systems immediately and from backups within a set period”

“deleted content is removed from our active systems immediately and from backups within a set period”

The copy you can see goes at once, and the copies in backups and replicas stay until the rotation reaches them. It is the one number this trade does put in writing, and it is the honest reason deletion is never instant.

The move A deletion request can ask when the backup copies actually clear. The date they give is the one to keep.

Their own policy is the one that binds them. Pin it down with a request, and keep the reply.