Skip to content

Privacy policy

Draft: to be reviewed by legal counsel before launch.

Who we are

theTransfer is an end-to-end encrypted file transfer service. This policy explains what personal data we process and why.

The files you send

Files, file names and messages are encrypted in your browser before upload. We store only ciphertext and cannot read it. Encrypted data is deleted automatically when the transfer expires, when you delete it, or when we act on an abuse report.

Data we process

Data Why How long
Account email, name, phone (optional) To run your account, send sign-in links and receipts Until you delete your account
Transfer metadata: size, number of files, timestamps, expiry, download counts To deliver and limit transfers, and to show you statistics Until the transfer is deleted, then aggregated
Download events: country, city, device type, browser, a daily-rotating salted hash of the IP address Statistics for the sender, abuse prevention Up to 400 days
Payment records (via Stripe) Billing, accounting obligations As required by law
Abuse reports To review and act on illegal content As long as needed for the decision and legal obligations

We do not store IP addresses in readable form, do not sell data and do not use advertising trackers.

Processors

We run on Cloudflare (hosting, storage, bot protection). Payments go through Stripe, emails through Mailgun and SMS through Twilio. Each processes only the data needed for its job.

Cookies

We use a single essential, HttpOnly session cookie when you sign in. No analytics or advertising cookies. Preferences like the theme or remembered links stay in your browser’s local storage and are never sent to us.

Your rights

You can access, correct, export or delete your data. Deleting your account (Account → Profile → Delete account) removes your transfers and encrypted files immediately and anonymises the account.