Privacy Policy

Your privacy and credentials belong entirely to you.

Last Updated: October 2026

1. Local-First Architecture

BucketStack operates on a strictly local-first architectural model. When you use the BucketStack desktop client, all cloud operations (such as listing buckets, downloading objects, uploading files, generating presigned links, and syncing directories) occur directly between your personal computer and your chosen S3 storage endpoint.

There are no intermediary proxy servers, relay nodes, or centralized servers operated by BucketStack through which your data passes.

2. Storage of S3 Credentials

Your Access Key IDs and Secret Access Keys are stored only on your device, in a file encrypted with AES-256-GCM using a key derived from your computer's machine identifier. Connection details such as names, endpoint URLs, regions and bucket names are stored locally in the app's settings. Your Secret Access Key is never transmitted: it is only used on your device to sign requests sent directly to the storage provider you configured. None of this information is sent to BucketStack or any other third party.

The app also keeps an activity history (for example uploads, renames and deletions) in a local database on your device. You can turn it off for any connection, export it at any time, and remove it along with all other app data by resetting the app.

3. Telemetry and Analytics

The BucketStack desktop application does not collect telemetry, usage analytics, or behavioral tracking. To check for updates, the app downloads a small update file from GitHub Releases (github.com), and installs updates only after verifying their cryptographic signature. GitHub receives the standard request data, such as your IP address, under its own privacy policy.

The website (bucketstack.app) does not use cookies or analytics scripts. It is hosted on Cloudflare, which processes standard request data (such as IP addresses) to deliver the site. To show the latest version and download links, your browser fetches release information from GitHub's public API.

4. Third-Party Cloud Providers

When connecting BucketStack to third-party providers (such as Amazon Web Services, Cloudflare, Backblaze, Wasabi, or MinIO), your interactions are governed by the respective privacy policies and terms of those providers.

5. Contact Us

If you have any questions regarding this privacy policy, please contact us at akash@bucketstack.app.