Privacy policy
FlyingFiles is a file manager that runs only on your computer. We don't collect data about you or about how you use the app.
Last updated: 2026-09-14
In one sentence: the app doesn't send us any data — there are no accounts, telemetry, analytics or ads, and the only network connections it makes are to servers you configure yourself and an update check when you ask for one.
1. Who is responsible for the app
The publisher of FlyingFiles is NCI, ul. Bławatkowa 10, 84-100 Puck, Poland, VAT ID PL586-103-86-56. Contact for privacy matters: kontakt@nci.pl.
2. What the app stores on your computer
All of the data below stays on your device and is never sent anywhere. You can view and delete it at any time — these are ordinary files and entries in the system password store.
| What | Where |
|---|---|
| Settings: the paths of both panels, window size, appearance, language, favorite paths, saved FTP/SFTP connections (address, port, username, initial folder, key path — no passwords) and SSH/Telnet terminal entries | macOS: ~/Library/Application Support/FlyingFiles/settings.tomlWindows: %APPDATA%\FlyingFiles\settings.toml |
| Backups of the settings file | the same folder, settings.toml.bak.* files |
| Transfer log: what was copied, when and where to, and the conversation with servers (addresses, usernames, paths, errors; passwords masked) | the same folder, logs/transfers.log |
| macOS: addresses of network shares you have used, for reconnecting them | the same folder, network-mounts.toml |
| FTP/SFTP server passwords | the system password store — the macOS Keychain or Windows Credential Manager — under the name FlyingFiles FTP |
.ffignore rules, if you create them | the .flyingfiles folder inside the folder you choose |
| Contents of open archives | the system's private temporary folder, deleted when the archive is closed |
| macOS: update mechanism files (Velopack), including a random installation identifier | helper files of the Velopack library in your user account |
Passwords are never saved in the settings file. They go to the operating system's password store, which protects them with its own mechanisms. The app reads them only when you connect to a server or edit a saved connection.
3. Network connections
The app connects to the network only in these situations:
FTP, FTPS and SFTP servers that you add yourself. Login details and transferred files go only to that server. We can't see them, and we don't act as an intermediary in the connection.
Network shares mounted in your system — as in any file manager.
Update check (macOS and the old Windows beta from
Setup.exe). Only when you choose Help → Check for Updates... does the app download the list of releases from thenci.plserver and, with your consent, the package with the new version. The request contains no data about you or your files. The update mechanism (the Velopack library) attaches to it the installed version number, the CPU architecture and a random installation identifier, which it stores on your computer and uses for staged rollouts of updates. As with every visit to a website, the server records the IP address, the date and the request address in its logs. The logs are used solely for server diagnostics and security.
The Microsoft Store version updates through the Store, not through our server — Microsoft's privacy policy applies to that part.
Features that use other programs work locally: opening files in system applications, SSH/Telnet terminals in the Terminal app or Windows Terminal, and video frames from the system's Quick Look.
4. What we don't do
We don't collect telemetry or usage statistics.
There are no user accounts and no logging in.
There are no ads, no tracking and no profiling.
We don't read, upload or index your files. The app works on them locally, just like Finder or File Explorer.
We don't pass on any data to anyone.
5. Contact by e-mail
We accept support requests and reports only by e-mail at kontakt@nci.pl. This is the only situation in which you give us any data at all — and you do so knowingly.
What we receive: your e-mail address and whatever you write or attach (a description of the problem, your system version, an excerpt of the log, a screenshot).
Why: solely to reply and to resolve the matter you reported. The legal basis is our legitimate interest in replying to you (Article 6(1)(f) GDPR).
How long: we keep the correspondence in our mailbox until the matter is closed; you can ask us to delete it at any time.
We don't add you to any mailing list, and we don't pass your correspondence on to anyone.
Please don't send passwords or private keys — they are never needed to reproduce a problem.
6. The website
The nci.pl/flyingfiles website:
doesn't use cookies or analytics tools, and doesn't load scripts, fonts or any other resources from external servers;
counts downloads in aggregate in a database: clicking a download button increases a counter for the given day, version and type of download (macOS, or going to Microsoft Store). The counter doesn't record your IP address, your browser, the page you came from, the exact time or any identifier;
like every web server, keeps access logs (including the IP address, the date, the page address and information about the browser). The logs are kept by the hosting provider for security and diagnostic purposes, and how long they are retained depends on the hosting settings. The legal basis is the legitimate interest in maintaining a secure website (Article 6(1)(f) GDPR).
The Get it from Microsoft Store button leads to Microsoft's website, where Microsoft's privacy policy applies.
7. Your rights
The GDPR gives you the right of access to your data and the rights to rectification, erasure, restriction of processing, objection and data portability.
The app's data consists of files on your disk and entries in the system password store — you exercise these rights yourself, immediately. Deleting the settings folder and the FlyingFiles FTP entries from the password store erases everything the app “knows” about you.
For matters concerning correspondence and data related to the website, write to kontakt@nci.pl. You also have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), the Polish supervisory authority.
8. Children
The app is a general-purpose tool and isn't directed at children. It doesn't collect data from anyone, and therefore not from children either.
9. Changes
If we ever add a feature that requires sending anything outside your computer, we will describe it here before it is added to the app, and we will change the update date at the top.