Faway / 2026.10.08

Privacy policy

Faway provides HTML hosting, project management and authorized sharing for individual creators. Register with email and a password, or create and sign in to an account with Google. Email codes verify registration, email linking and password resets.

Data we store

We store author accounts, password hashes, uploaded projects, grants, access sessions, MCP credential hashes and necessary service records. Active visitor codes have an encrypted copy so their authors can view them. Full MCP credentials are provided only at creation.

How data is used

Data is used for file storage, project display, authorization, quota accounting and service operation. Faway pages do not load third-party analytics or ads. Projects with CDN assets enabled may connect visitors to those third-party services.

Operational records

Operational metrics retain hourly totals of request categories, status codes, response times and successful actions for 90 days. They store no visitor IP addresses, raw URLs, query parameters, user agents or visitor identifiers, and use no analytics cookies. The admin console can view basic author details, linked sign-in email addresses, storage usage and login times recorded since monitoring began for account support and service operation.

Access and retention

Projects are private by default and require a valid visitor code. Authors can replace, export or delete projects, and revoke grants or MCP connections. Deletion removes online files; backups rotate on a seven-day retention period. The server and backups are in Seoul. Same-server backups do not protect against loss of the entire server.

Google identity verification

Google sign-in requests basic identity information only, with no access to Gmail, Drive or contacts. Faway stores your stable Google identifier, verified email and sign-in times to create or access your personal workspace. Sign-in methods sharing an email are not merged automatically: sign in to your original account, then explicitly link Google in Space settings. Google access tokens are not stored persistently.

Email accounts and verification codes

Email registration, linking and password resets require email verification. Faway stores verified addresses, password hashes, sign-in times and temporary verification state. Passwords and codes are never stored as plain text. Google users with a linked email can also set an email sign-in password through password reset.

Verification emails are sent through Resend. The email service receives only the recipient address and verification email, never project content. Each code can be used once and expires after 10 minutes.

Limits of sharing

Authorized visitors can save loaded content or forward codes. Revocation blocks future access but cannot reclaim saved copies.