Data Protection & Retention

Privacy is not a feature.
It's the baseline.

What we collect, why, how long we keep it, and how to get a copy or have it deleted.

Last updated: September 19, 2026

Privacy Policy

SECTION 01

Who We Are

GetFileShare (getfileshare.cloud) is operated by Muhammad Tahir Ali, who is the data controller for the personal data described in this policy.

For any privacy question or request, use the contact form and choose “Privacy Request”, or use the self-service tools on the Your Data page.

SECTION 02

What We Collect and Why

We collect only what each feature needs. There are no advertising or ad-tracking scripts on this site.

FeatureWhat we collectWhy
Direct (E2E) transferIP addresses, browser user agents and approximate location (country, as reported by our network provider) of both devices; the size and type of each file (not its name); transfer timing and outcome; and connection diagnostics — whether the file travelled directly, through our TURN server or through our relay, how long the connection took to set up, measured round-trip time and an estimated connection speed, and whether chunks had to be re-sent. File contents are end-to-end encrypted: they travel device to device, or pass through our relay or TURN server as ciphertext in memory — which happens when a direct connection cannot be established, and for transfers small enough that setting one up would take longer than sending the file. They are never stored.Connecting the two devices, rate limiting, abuse prevention, and measuring and improving transfer reliability.
Cloud Share uploadYour email address; file names, sizes and types; recipient addresses you enter; expiry and download-limit settings; your IP address and user agent; a random device ID kept in your browser; and a device fingerprint — a hash of screen, hardware, timezone, graphics and canvas characteristics — computed only when you submit an upload. File contents are stored until the share expires or you delete it.Providing the share and emailing recipients; the weekly upload quota and multi-account abuse prevention (device ID and fingerprint).
Downloading a shareIP address; approximate location (country, region and city, as reported by our network provider); browser user agent; referring site; which files were requested and whether the download completed.Download limits, abuse prevention, and the share owner's download statistics and notifications (Section 06).
File RequestsRequester: email, title, instructions, invitee addresses. Submitter: the file and its name, whatever name, email and message you choose to give, your IP address and user agent.Delivering the file to the requester; quota and abuse prevention.
Email sign-inEmail address; the one-time code and the one-click sign-in link token (both stored only as hashes, and only for 10 minutes); when you verified and last signed in; and your notification preference.Proving you control the address, keeping you signed in, and respecting whether you want download notifications.
Contact and DMCA formsWhat you enter (for DMCA notices this includes name, postal address, phone and signature), and your IP address.Answering you; handling copyright notices.
Site analytics (only with your consent)Pages visited — with share links, file names and codes removed — plus device and browser type, through Google Analytics.Understanding aggregate use of the site.
SECTION 04

How Long We Keep It

Deletion is automatic and runs daily. Nothing below is kept indefinitely.

DataKept for
Cloud Share file contentsUntil the share expires or reaches its download limit, then deleted within two days — or immediately when you delete the share.
File Request submissions (the files)Until the request expires, or immediately when the requester deletes it.
Raw IP addresses, browser user agents, referrers, device IDs and fingerprints30 days
Cloud upload and download records (file names, sizes, times, hashed IP, country, browser type)180 days after the last activity
Direct (E2E) transfer records (file count, size range, file type, times, hashed IP, country, browser type — no file names)180 days after the last activity
Records of expired or deleted shares and file requests90 days after the files are deleted — so a link can say it expired rather than never existed
Your account (email address)Until you delete it. Removed automatically after 12 months with no sign-in and nothing active; addresses never verified are removed after 7 days.
Contact messages12 months
DMCA notices, and records of privacy requests (hashed email only)3 years
Web server logs (IP address, request path, time)Up to 14 days, for security and troubleshooting
SECTION 05

Cookies and Browser Storage

Everything below is needed for a feature you use, except the Google Analytics cookies, which are set only if you accept them. If your browser sends a Global Privacy Control signal, we treat it as a refusal of analytics.

NameKindPurposeDuration
ux_5d3e (cookie)Strictly necessaryKeeps you signed in after verifying your email. Signed, and unreadable by scripts.30 days
ux_c41d (local storage)Strictly necessaryRemembers your cookie choice.Until you clear site data
ux_7e08, ux_b5d6 (local storage)FunctionalRemember the email you used and whether it is verified, so you don't retype it.Until you clear site data or delete your account
ux_3b7c (local storage)FunctionalLight or dark theme.Until you clear site data
ux_9f2a (local storage)SecurityRandom device ID, created at your first Cloud Share upload and sent with uploads for quota and abuse checks.Until you clear site data (server copy: 30 days)
sw-download.js (service worker)Strictly necessaryRegistered when you download a multi-file share, so the files can be streamed into a ZIP without filling memory. It stores no data.Until you clear site data
Device fingerprintSecurityNot stored in your browser. Computed when you submit a Cloud Share upload and sent with it.Server copy: 30 days
_ga, _ga_* (cookies)Analytics — consent onlyGoogle Analytics, to count visits and pages.Up to 2 years; deleted when you withdraw consent
SECTION 06

Who Receives Your Data

  • Share owners. The first time each new person downloads a share, its owner may be emailed that person's approximate location (city and country) and device type (for example “Chrome on Windows”). Owners also see download counts by country, device, browser and referring site. Owners never see IP addresses.
  • Recipients you enter receive your email address and the file name in their notification. File requesters receive the file and whatever name, email and message the submitter gives.
  • Service providers that run the service for us, under their data-processing terms: Cloudflare (DNS, network security, R2 file storage), Hetzner (application servers), MongoDB Atlas (database), our transactional email provider (sign-in codes and notifications), and Google (analytics, only with consent).
  • Authorities, only when legally compelled by valid legal process.
SECTION 07

International Transfers

Our providers may process data in countries other than yours, including outside the EEA and UK. Where they do, we rely on the transfer safeguards in their data-processing terms, such as the European Commission's Standard Contractual Clauses.

SECTION 08

Security

All traffic is encrypted in transit with TLS. Cloud files sit in encrypted-at-rest object storage, separate from the metadata database. Password-protected shares are encrypted in your browser (AES-256-GCM / Argon2id); the password is never sent to or stored on our servers. A strict Content Security Policy limits the site to scripts we serve from this domain and names every other origin the page may contact, which blocks injected inline scripts and limits where the page can send anything. The API validates every request against a strict schema and is rate-limited. Access to raw logs is restricted to the operator, who reviews them only to investigate abuse or security incidents, or to answer a privacy request.

SECTION 09

Your Rights

You can ask to access, correct, delete, restrict or port your data, object to processing based on legitimate interests, and withdraw consent at any time. Here is how:

  • Download a copy or delete your account — the Your Data page, after confirming your email with a code.
  • Delete a single share early — My uploads → Delete.
  • Withdraw analytics consent — Cookie Settings in the footer.
  • Anything else — corrections, objections, restriction, or data we may hold about you without an account (as a recipient, downloader or direct-transfer user) — the contact form. We reply within one month and may ask you to confirm you control the address. Without an account we can only find records by email address or IP address, and raw IP addresses are deleted after 30 days.

Your email address is your account's identity, so it is corrected by starting to use the new address and deleting the old account.

Deleting your account removes your shares and their files, your file requests and what was submitted to them, download records, contact messages, and your address wherever it appears in someone else's share or request. Three things are kept: upload records from the last 7 days keep their byte counts and device ID — with your email and other identifiers removed — so the weekly quota cannot be reset by deleting an account; DMCA notices are kept for 3 years in case of legal claims; and a file you uploaded to someone else's file request stays with the person who asked for it, stripped of your name, address and message, because it is theirs as much as yours. Ask us if you need such a file removed as well.

A download covers everything stored against your account. It does not include our web server access logs (IP address, path and time, kept for up to 14 days for security), the short-lived cache of active shares, or the delivery logs held by the provider that sends our email — none of which is filed under your account. Ask us and we will look in them for you.

You also have the right to complain to the data protection authority where you live or work.

SECTION 10

California Residents

The California Consumer Privacy Act applies to businesses above certain size thresholds, which we do not believe we currently meet. We describe our practices here anyway and honor the same requests.

  • Categories collected: identifiers (email address, IP address, device ID); internet or network activity (the records in Section 02); approximate geolocation (country, region, city).
  • Sources: you, your browser, and people who share files with you or request them from you.
  • Purposes and retention: Sections 02 and 04. Disclosure: only to the service providers in Section 06.
  • We do not sell personal information or share it for cross-context behavioral advertising, and we honor the Global Privacy Control signal.
  • You may request to know, delete or correct your information as described in Section 09. We will not treat you differently for doing so.
SECTION 11

Automated Limits

Upload quotas and abuse limits are applied automatically — an upload may be refused when an account or device exceeds the weekly limit. These limits have no legal effect on you. If you think one was applied wrongly, contact us and a person will review it.

SECTION 12

Children

GetFileShare is not directed at children under 16, and we do not knowingly collect their personal data.

SECTION 13

No Sale of Data, No Ad Targeting, No AI Training

We do not sell or rent your file content, file metadata, IP addresses or any other data, and we share nothing with advertisers or data brokers. None of it is used to train machine learning or AI models — ours or anyone else's. The only third-party analytics is the consent-based Google Analytics in Section 05, which never receives file content, file names or share links.

Some pages, such as a download page, may show a sponsor banner. These are static images hosted on our own domain with a plain link out — there is no ad network, no ad script, no cookie and no tracking pixel behind them. Nothing about you, your file or your visit is shared with the advertiser, and what you see is the same for everyone rather than chosen from anything we know about you. Only if you click does your browser go to their site, at which point their own privacy policy applies.

SECTION 14

Changes to This Policy

When this policy changes, we update the date at the top of this page.