> ## Documentation Index
> Fetch the complete documentation index at: https://docs.dfine.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and privacy

> Where dfine.io Review stores your data, how you control who gets in, and how the activity log records access.

## Where your data lives

Files and data are region-pinned to the EU and served from the edge inside the European Union, under European data protection rules. Streaming Classic hosting is on [Technical facts](/en/reference/technical-facts).

## Who gets in

* A folder can have its own password: [Where do I turn on a password for a folder?](/en/review/turn-on/folder-password)
* A share link can have a password, an expiry of 24 hours, 7 days, a custom date or never, and its own permissions: [Where do I turn on a password, expiry or downloads for a share?](/en/review/turn-on/share)

## Your account

A session timeout ends unattended sessions. Two-factor authentication is optional and sits in your user profile. Both: [Where do I turn on two-factor sign-in and a session timeout?](/en/review/turn-on/sign-in-security)

## The record

The activity log records every important action with who and when, and you can download an audit copy: [Where do I see who opened, uploaded or changed what?](/en/review/find/activity)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.