EN

Möchten Sie sich wirklich von diesem Gerät abmelden?

Privacy Policy

Privacy Policy

Effective: 29 June 2026 Last updated: 8 July 2026 Version: 1.1
Zero-knowledgeNo adsWe never sell your data

This policy explains what we collect, why, and the choices you have. The short version: we cannot read your files, we collect the minimum needed to run the Service, and we never sell your data.

Contents
  1. 1. The short version
  2. 2. What we DON'T see
  3. 3. Information we collect
  4. 4. How we use your information
  5. 5. Third-party providers
  6. 6. Storage & retention
  7. 7. Security
  8. 8. International transfers
  9. 9. Your rights
  10. 10. Children
  11. 11. Changes to this policy
  12. 12. Contact

1.The short version

🛡 Your files are end-to-end encrypted on your device — we can't see their contents or file names. We collect the minimum needed to run the Service, never sell your data, and don't show ads.

2.What we DON'T see

  • The contents of your files
  • Your file names (encrypted before they reach us)
  • Your passwords, encryption keys, or device keys

3.Information we collect

3.1 Account data

If you create an account, we store your email address and, optionally, a display name. Account sign-in can use email/password or Google/Apple sign-in.

3.2 Transfer data

We store your encrypted file blobs and minimal metadata required to deliver a transfer — for example, size, number of files, expiry time, and whether a password is set. We do not store the plaintext of your files or their names.

3.3 Technical data

Like most online services, we process basic technical data (such as IP address and request logs) to operate the Service, prevent abuse, and keep it secure.

3.4 Feedback and reports

When you send feedback or an abuse report through the Service, we collect the message you write and, if you choose to provide one, an email address so we can reply. To help us diagnose and reproduce issues, your submission also includes a short technical summary of your device — your browser and operating system (for example, "Chrome 120" on "Windows 10/11"). We include only this summary, not your full browser User-Agent string. Feedback is submitted without linking it to your account or transfers; an abuse report includes the transfer you are reporting so our team can review it. We rely on our legitimate interest in operating, securing, and improving the Service as the legal basis for this processing (Art. 6(1)(f) GDPR); where you provide an email, we use it solely to respond to you.

4.How we use your information

  • To provide, maintain, and improve the Service
  • To deliver your transfers and enforce expiry and self-destruct
  • To secure the Service and prevent fraud or abuse
  • To review, respond to, and act on feedback and reports you send us, and to diagnose and fix the problems they describe
  • To communicate with you about your account or important changes
  • To comply with legal obligations

We do not use your data for advertising, and we do not sell or rent your personal data to anyone.

5.Third-party providers

We rely on a small number of trusted providers (sub-processors) to run the Service. They process data only as needed to provide their function and under their own terms and privacy policies:

ProviderPurpose
CloudflareEncrypted file storage (R2), bot protection (Turnstile), and connection relay (TURN) for device-to-device transfers
StripePayment processing (global)
XenditPayment processing (Southeast Asia)
Google & AppleOptional sign-in (OAuth) — only if you choose to use it
Email providerTransactional email such as verification and password reset

We add providers only when needed and keep this list current. We do not maintain a separate sub-processor page.

6.Storage & retention

Encrypted files are stored on Cloudflare R2 and are automatically deleted at expiry or after a self-destruct download. We do not keep copies.

Account data is retained while your account exists. When you delete your account, your personal data is permanently and immediately removed from our systems.

Feedback and abuse reports (including any email you provide and the browser/operating-system summary described in section 3.4) are kept only for as long as necessary to handle them and to keep the Service safe, and are then deleted or anonymised.

7.Security

Files are encrypted end-to-end, so only people with the link (and password, if set) can decrypt them. We use Cloudflare Turnstile to block bots — it protects the Service without profiling you or using tracking cookies.

For more detail, see our Security Overview.

8.International transfers

We operate globally and our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards for cross-border transfers.

9.Your rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal data, and to object to certain processing.

  • Delete your transfers at any time from your dashboard
  • Delete your entire account and all its data from your settings
  • Contact us to exercise any other applicable right

Our processing is governed by Singapore's Personal Data Protection Act (PDPA), and by the EU/UK GDPR where it applies to you.

10.Children

The Service is not directed to children under 13 (or under 16 in the EU where applicable). We do not knowingly collect data from children below the applicable age.

11.Changes to this policy

We may update this policy from time to time. Material changes will be announced in our Policy Changelog, and registered users will be notified of significant changes.

12.Contact

For any privacy question or request, contact us at:

Privacy

📧 privacy@senderly.me

🏢 Senderly, 60 Paya Lebar Road, Singapore 409051

Read together with our Terms of Service and Cookie Policy.