# How Secure is the file upload?

**URL:** <https://community.glideapps.com/t/how-secure-is-the-file-upload/59898>\
**Category:** Ask for Help\
**Created:** [March 30, 2023, 3:40pm UTC](https://community.glideapps.com/t/how-secure-is-the-file-upload/59898 "2023-03-30T15:40:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Keren404](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/keren404/32/47015_2.png) [@Keren404](https://community.glideapps.com/u/Keren404)\
**Post date:** [March 30, 2023, 3:40pm UTC](https://community.glideapps.com/t/how-secure-is-the-file-upload/59898/1 "2023-03-30T15:40:03Z")

</div>

File storage Question:  
how private / secure is the file storage? We need to request KYC related materials from users, and I don’t want them just sitting around in the cloud.

Does anyone know of any plugins that do this, maybe? like allow some sort of service connection / private folder?

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [March 30, 2023, 4:03pm UTC](https://community.glideapps.com/t/how-secure-is-the-file-upload/59898/2 "2023-03-30T16:03:44Z")

</div>

> [@Keren404](#):
>
> how private / secure is the file storage?

Glide storage is neither private nor secure. When you upload a file/image to Glide, it’s stored and hosted in Google Cloud and a URL is returned. Although the URL isn’t discoverable or easily guessed, it is a public URL.

A Private/Authenticated storage option is a long term feature request.

> [@Private Storage Option](https://community.glideapps.com/t/private-storage-option/31011):
>
> This is something I’ve mentioned in private exchanges with some of the Glide team, but just wanted to throw it out there as an “official” feature request. By definition, I expect this would be an option only available for Private Apps, and possibly only for enterprise customers. Most of the apps I build are for corporate customers; the company I work for and some of our partners/clients. Often we want to store files and documents and make them available via the app, but some of them can contai…

> [@Keren404](#):
>
> Does anyone know of any plugins that do this, maybe? like allow some sort of service connection / private folder?

There are workarounds that you could implement. For example, you could transfer all files to your own Google Workspace or some other private storage location. But then you’re faced with the issue of allowing your App users to access the files. For example, if they’re using your App via public cellular or wifi network then they probably won’t be able to access the files, unless they’re logged into an account in your workspace, or connected via VPN, etc…

---

<div class="post-metadata">

**Author:** ![Keren404](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/keren404/32/47015_2.png) [@Keren404](https://community.glideapps.com/u/Keren404)\
**Post date:** [April 2, 2023, 12:56pm UTC](https://community.glideapps.com/t/how-secure-is-the-file-upload/59898/3 "2023-04-02T12:56:10Z")

</div>

Thanks @Darren_Murphy for the reply!

I upvoted the feature suggestion 🙂

I’m not concerned about the link being shared - as app users will only be employees who currently have open access to these files, anyways, and can hypothetically share them now, as well.  
I’m more concerned about someone stumbling on to the link / guessing the key in the URL / somehow hacking the drive it’s stored on. The documents we need to allow for upload are private documents, containing PII - so there’s a serious concern there, and moving the docs to private hosting (which was my initial thought) won’t do - as these sensitive docs would still be hosted on these public URLs - unless you know a way to actually delete these docs form glide storage once they are transferred?

Thanks again for your help 🙏

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [April 2, 2023, 12:58pm UTC](https://community.glideapps.com/t/how-secure-is-the-file-upload/59898/4 "2023-04-02T12:58:36Z")

</div>

> [@Keren404](#):
>
> as these sensitive docs would still be hosted on these public URLs - unless you know a way to actually delete these docs form glide storage once they are transferred?

There is no way to directly delete them from Glide storage, but if the link isn’t referenced anywhere in your App then the file will be removed after 30 days.
