Terms of Service & Policies

Last updated – 1 October 2026

Important – Please Read Carefully

This Legal Suite (collectively, the “Terms”) governs your access to and use of the ShieldFive website, mobile application and related online services provided by ShieldFive (“ShieldFive”, “we”, “us” or “our”), currently operated by an individual based in Spain, including any other product or service that links to or otherwise incorporates these Terms (collectively, the “Services”).

By creating an account, activating a subscription or otherwise using the Services you acknowledge that you have read, understood and agree to be bound by these Terms. If you do not agree, do not use the Services.

These Terms are drafted to reflect the requirements of:

  • Regulation (EU) 2016/679 (General Data Protection Regulation – “GDPR”);
  • Spanish Organic Law 3/2018 and Law 34/2002 (LSSI-CE);
  • The ePrivacy Directive 2002/58/EC (as implemented in the EU/EEA);
  • Swiss Federal Act on Data Protection (FADP);
  • The United Kingdom GDPR and Data Protection Act 2018;
  • The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA);
  • U.S. CAN-SPAM Act, Children’s Online Privacy Protection Act (COPPA) and other applicable laws.

Nothing in these Terms is intended to circumvent mandatory consumer protections provided by the laws of your habitual residence.

1. Definitions

TermMeaning
AccountThe credentials and profile that permit you (or an entity you represent) to access the Services.
AffiliateAny entity that directly or indirectly controls, is controlled by, or is under common control with ShieldFive.
ContentAll text, data, files, code, images or other materials uploaded, stored, generated or otherwise processed through the Services (excluding Usage Data and Feedback).
Business DayMonday – Friday, excluding Spanish national holidays.
Storage ProviderA third-party cloud service used to store encrypted file blobs.
Applicable LawAll laws, rules and regulations that apply to either party, including those listed in the preamble.

Undefined capitalised terms have the meaning assigned elsewhere in these Terms.

2. Eligibility & Authority

  1. Age Requirement. You must be at least 16 years old to register for any Account, and at least 18 (or the age of majority where you live) to hold a paid plan. We do not knowingly allow Accounts for anyone under 16.
  2. Entity Users. If you create or administer an Account on behalf of a company or other legal entity, you represent that you have authority to bind that entity. “You” and “your” will then refer to both you and the entity.
  3. Prohibited Persons. You may not use the Services if you are located in, or are a national or resident of, any jurisdiction subject to a comprehensive EU, UK, Swiss or U.S. embargo or export restriction, or if you are on any relevant sanctions list.

3. Account Registration & Security

  1. Accurate Information. You agree to provide true, complete and current information when opening or updating your Account.
  2. Credentials. Keep your password, recovery keys and any API secrets confidential. ShieldFive cannot recover encrypted Content if you lose the keys.
  3. Security Notification. Notify us immediately at [email protected] if you suspect unauthorised access or disclosure.
  4. Multiple Accounts. Except where expressly permitted in writing, you may hold only one free Account. Paid Accounts may create sub-users and aliases in accordance with the selected plan.

4. Service Description

ShieldFive provides cloud storage with client-side file encryption and ancillary productivity tools. Data is encrypted locally on your device before upload. Encrypted file blobs are stored in a third-party cloud object storage provider under randomized object keys, and encrypted file/folder names are stored as ciphertext alongside other metadata in our database. The sign-in password is not transmitted to us: the browser derives a separate login value with Argon2id and sends only that value, while the key that opens the vault is derived separately and stays on your device. The delivered client code remains part of the trust model, so client-side encryption is not an unconditional guarantee that the service is technically incapable of deriving file keys. The Security page documents this boundary and the different web and Android encryption formats.

5. Free & Paid Plans

  1. Plan Details. Features, quota, bandwidth, SLA level and pricing are described on the Pricing Page or an executed Order Form. We may reasonably modify free plans at any time.
  2. Trials. Free trials convert to the applicable paid plan at the end of the trial unless you cancel beforehand.
  3. Lifetime Plans. Lifetime plans last for 99 years or until ShieldFive ceases to operate the relevant Service, whichever occurs first, and are non-transferable.

6. Acceptable Use Policy (AUP)

You agree not to, and will not allow others to:

  • Use the Services in violation of Applicable Law, court order or ShieldFive’s Acceptable Use Policy (incorporated by reference), including to store or share: child sexual abuse material, extremist propaganda, malware or content that infringes third-party rights.
  • Perform or facilitate unauthorised penetration tests, vulnerability scans or reverse engineering of the Services except through ShieldFive’s coordinated vulnerability disclosure process ([email protected]).
  • Interfere with or disrupt the integrity or performance of the Services or any data contained therein.
  • Mislead or deceive others, including by phishing or impersonation.

Violation may result in rate-limiting, suspension or immediate termination without refund, and we may report unlawful conduct to competent authorities.

7. User Content & Storage Materials

  1. Ownership. As between you and ShieldFive, you retain all intellectual-property rights to your Content.
  2. Licence to ShieldFive. You grant ShieldFive and its subprocessors a worldwide, non-exclusive, royalty-free licence to host, copy, transmit and otherwise process Content solely for the purpose of providing the Services, resolving support requests, complying with law or enforcing these Terms.
  3. Responsibility. You are solely responsible for the nature, quality and legality of Content and for ensuring that your configuration (redundancy, geographic dispersion, retention, encryption keys) meets your compliance obligations.
  4. Sensitive Data. You shall not store special-category personal data, health records, cardholder data (PCI-DSS), or other data subject to heightened regulatory schemes unless you have first implemented all measures required under Applicable Law and executed the ShieldFive Data Processing Agreement (“DPA”).

8. Intellectual Property; Open Source

The Services, ShieldFive brand, source code (excluding components released under an open-source licence), design and documentation are protected by copyright, trademark and other laws. Nothing in these Terms transfers ownership of any ShieldFive IP to you. Where the Services incorporate open-source software, your use is additionally subject to the relevant open-source licences, which do not govern any hosted portions of the Services.

9. Third-Party Services & Integrations

The Services may contain links to, or integrations with, third-party applications. We do not endorse or assume responsibility for such third parties. Your dealings with them are solely between you and the third party and may be governed by separate terms.

10. Privacy & Data Protection

  1. Privacy Notice. Our Privacy Policy explains how we collect and process personal data, and forms part of these Terms.
  2. Sub-processors. The categories of third-party recipients we share limited personal data with are described in the “Who we share data with” section of the Privacy Policy. Business customers may request the named list as part of an executed Data Processing Agreement.
  3. Controller / Processor Roles. Except for billing information and service telemetry/analytics processed as controller (based on deployment configuration), ShieldFive acts as processor of personal data stored in your Content. A Data Processing Agreement is available for execution on request by writing to [email protected].
  4. Hosting & Transfers. Customer data is hosted in the storage region configured for your deployment (including EU deployments). File blobs and file/folder names are encrypted client-side before upload, subject to the authentication boundary described in section 4. Operational metadata (identifiers, ciphertext sizes, MIME hints, timestamps) is stored in plaintext to operate the service. If ShieldFive enables processors outside the EEA, the applicable transfer arrangements and safeguards are described in our Privacy Policy and Data Processing Agreement.
  5. California. ShieldFive is a “service provider” under the CCPA/CPRA and will not “sell” or “share” personal information as those terms are defined therein.

11. Security Measures

ShieldFive maintains a written information-security programme with technical and organisational controls appropriate to risk, including:

  • Client-side encryption with per-file keys; new uploads use a post-quantum hybrid suite by default (ML-KEM-1024, NIST FIPS 203, combined with XChaCha20-Poly1305 via an HKDF-SHA-256 combiner), and files written under the previous default (AES-256-GCM) remain readable;
  • TLS 1.3 in transit;
  • Authentication and access controls, including multi-factor authentication support;
  • Rate limiting and abuse protections;
  • Monitoring and incident-response procedures.

12. Service Level Agreement (SLA)

  1. Availability Terms. Any availability target or service-level commitment applies only if expressly stated in an Order Form or other written commercial terms.
  2. Credits. Service credits are available only if expressly agreed in writing.

13. Fees, Billing & Taxes

  1. Fees. You will pay the fees described at the time of purchase or in your Order Form. All fees are exclusive of applicable taxes, which you shall pay or self-assess where required.
  2. Billing Cycle. Unless stated otherwise, subscriptions auto-renew for successive terms equivalent to the initial term.
  3. Payment Method. You authorise ShieldFive (or its payment processor) to charge your designated payment method on each renewal date. If payment fails and is not cured within 7 days, we may suspend or downgrade your Account.
  4. Refunds.On your first paid purchase of any plan you may cancel for any reason within 30 days and receive a full refund. This covers one-time purchases, including the Lifetime Vault, as well as subscriptions; for a subscription the refund is of the most recent paid period. After 30 days, refunds are not available except as required by applicable law (including the EU Consumer Rights Directive 14-day withdrawal period for paid digital services, which we honour in full and which runs from the initial purchase date, concurrent with the 30-day guarantee above). The 30-day full-refund guarantee applies once per customer per lifetime; subsequent renewals or upgrades are non-refundable except as required by law. This clause was widened on 4 September 2026 to state plainly that one-time purchases are covered — the previous wording spoke only of “subscribers” and a “paid period”, which did not fit a one-time purchase and left the Lifetime Vault ambiguous while its own product page advertised the guarantee. The change is in the customer’s favour and takes effect on posting rather than after the 30-day notice in section 19.

14. Suspension & Termination

  1. By You. You may delete your Account at any time via the dashboard. Deleting your Account immediately terminates your licence to the Services but does not entitle you to a refund.
  2. By ShieldFive. We may suspend or terminate (i) for material breach upon 14 days’ written notice if the breach remains uncured, (ii) immediately for AUP violations or to comply with legal obligations.
  3. Effect. Upon termination, account records, file rows, share rows, share-event rows and stored ciphertext blobs are deleted on the schedule described in the Privacy Policy — for self-service deletion, within the same request. Residual encrypted copies persist only in disaster-recovery backups and in the object-storage recovery window, for the periods stated there, or as required by law.

15. Disclaimers

Except as expressly stated, the Services are provided “AS IS” and “AS AVAILABLE.” To the maximum extent permitted by law, ShieldFive disclaims all implied warranties (merchantability, fitness for a particular purpose, non-infringement, quiet enjoyment).

16. Limitation of Liability

  1. Indirect Damages. ShieldFive will not be liable for indirect, incidental, special, consequential or punitive damages, or for loss of profits, revenues, data or goodwill, even if advised of the possibility.
  2. Cap. ShieldFive’s aggregate liability arising out of or relating to the Services will not exceed the greater of (a) €100 or (b) the total fees you paid to ShieldFive in the 12 months preceding the event giving rise to the claim.
  3. Exceptions. The above exclusions and cap do not apply to liability that cannot be excluded under Applicable Law or to ShieldFive’s wilful misconduct or gross negligence.

17. Indemnification

You will indemnify and hold harmless ShieldFive, its Affiliates, and their respective directors, officers, employees and agents from and against any third-party claim arising from (a) your Content; (b) your breach of these Terms; or (c) your violation of Applicable Law.

18. Dispute Resolution & Governing Law

  1. Informal Resolution. Before filing a claim, each party agrees to attempt to resolve the dispute by emailing [email protected] with a concise description. If unresolved after 30 days, either party may proceed as set out below.
  2. Jurisdiction. If you are a consumer residing in the EEA, you may bring proceedings in your local courts. In all other cases, these Terms are governed by Spanish law and the courts of Valencia, Spain have exclusive jurisdiction.
  3. Arbitration for U.S. Consumers. If you reside in the United States, any dispute will be resolved by binding individual arbitration under the JAMS Consumer Arbitration Rules, with a waiver of class actions and jury trial. You may opt out by sending written notice within 30 days of first accepting these Terms.

19. Changes to Terms

We may amend these Terms by posting a revised version and updating the “Last Updated” date. Material changes will take effect 30 days after posting and will not be retroactive. Your continued use after that date constitutes acceptance.

20. Severability

If any provision is held unenforceable, it will be limited to the minimum extent necessary and the remainder shall remain in full force.

21. Miscellaneous

  • Entire Agreement. These Terms, the Privacy Notice, AUP, DPA and any Order Form constitute the entire agreement and supersede all prior agreements regarding the Services.
  • Assignment. ShieldFive may assign these Terms to an Affiliate or in connection with a merger or sale of assets. You may not assign without our prior written consent.
  • Force Majeure. Neither party is liable for failure to perform due to causes beyond reasonable control (e.g., natural disaster, war, labour dispute, internet disturbance).