last updated: august 20, 2026
Files are stored temporarily on Cloudflare R2. We never read them. Uploading to a portal requires no account. We collect only what's needed to receive files into your portals and hand them to you. We log upload and download activity — opens, downloads, previews — and countries for your analytics. Payments are processed by Dodo Payments; we don't see your card details.
When a file is dropped into a portal, it's split into chunks and uploaded directly to Cloudflare R2 object storage via presigned URLs. Each upload gets a unique session ID and a download token. The file is accessible only through that token — there's no browsing or listing of files.
For each upload we store: filename, file size, MIME type, chunk progress, upload session ID, download token, and expiry timestamp. If you buy a pack, we store the payment reference. If you sign in with Google, we store your email, name, and profile picture to manage your account and Dashboard.
For portals, we store the portal name, optional message, owner email, the portal mode (shared or inbox), and an optional password hash. Portal passwords are hashed with scrypt and a random salt — we never store them in plain text. When someone uploads to a portal, the name they provide is stored alongside the file and shown to anyone with permission to view the portal (everyone with the link in shared mode; only the owner in inbox mode). The name is self-reported, free-text, and not verified — treat it accordingly.
This metadata is stored in a SQLite database on our server. It exists to manage uploads, generate download links, and run your Dashboard. Nothing more.
When someone interacts with your file — viewing its link page, opening it in the browser, previewing it, or downloading it — we log the event type (view, open, preview, or download), the country derived from Cloudflare's CF-IPCountry header, and a timestamp. We don't store IP addresses. We do store a one-way keyed hash of the IP — it lets us count distinct visitors without being able to tell who anyone is, and it can't be reversed into an address. On email-gated files, the email the downloader enters is stored and shown to the file owner — that's the point of the gate. This data powers the per-file analytics in your Dashboard. We don't store browser fingerprints or anything else about the downloader.
We don't read, scan, or analyze your file contents. We don't use third-party analytics or tracking scripts. We don't store IP addresses — only the one-way keyed hash described under download analytics. We don't use cookies for tracking — only for session management, password-protected file access, and portal password access. Theme preference is stored in your browser's localStorage.
We use the following cookies, all httpOnly and secure: a session cookie for signed-in users (30-day expiry), a download access cookie for password-protected files (1-hour expiry), a portal access cookie for password-protected portals (1-hour expiry), an email-access cookie for email-gated files (1-hour expiry), and a temporary OAuth state cookie during sign-in (10-minute expiry). No tracking cookies.
Files on free-tier portals expire after 24 hours. Pack-credited files expire after 30 days. After expiry, files are permanently deleted from Cloudflare R2. Metadata is cleaned up during routine maintenance. Signed-in users can also delete files early from the Dashboard.
Portals are shared links — you create one and share it so others can upload files to you; in shared mode, anyone with the link can also view and download what's there. Files uploaded through a portal are stored under your account and appear in your Dashboard. The uploader does not need an account. Portal links are accessible only to people you share them with — there is no public directory of portals.
No account is required to upload or download files. Signing in with Google is optional and gives you access to the Dashboard (to manage your active links and portals) and the ability to buy packs. When you sign in, we store your Google ID, email, name, and profile picture. We don't access your Google contacts, drive, or any other Google data.
Pack purchases are processed through Dodo Payments, which acts as the Merchant of Record. When you pay, your email and name are shared with Dodo Payments to create the checkout. Dodo handles all payment processing, billing, and tax compliance. We do not see or store credit card numbers or payment method details.
For pack purchases, we store your Dodo customer ID, payment IDs, the tier purchased, and the GB credited. Your remaining credit balance is stored on your user record and decrements as you upload. There are no recurring charges.
Files sent through P2P rooms are transferred directly between devices using WebRTC. These files never touch our servers. Chat messages in rooms are also peer-to-peer. Room codes are temporary and expire when both parties disconnect.
Railway — application hosting and database.
Cloudflare — R2 file storage, DNS, email routing, TURN relay for P2P.
Dodo Payments — payment processing and billing.
Files are automatically deleted after their expiry period. There is no way to recover a file after it expires. Signed-in users can delete individual files or entire folders early from the Dashboard. If you need your account or upload metadata removed, contact us.
We'll update this page when the product changes. The date at the top reflects the most recent revision.
Questions about privacy? [email protected]