Privacy Policy
SaferDrop is built to hold as little of your data as technically possible. This page describes the little we do. Last updated 14 June 2026.
We never see your files. They stream browser-to-browser over WebRTC, encrypted with a key that is generated locally and lives only in the link's fragment — the part a browser never sends to a server. If a direct path is blocked, the encrypted stream falls back to a relay that still cannot read it.
What we never collect
- The contents of your transfers — they stream browser-to-browser, end-to-end encrypted, and no server can read them.
- File names, sizes, or recipient identities.
- Your security PIN — never in clear. The server only gets a session-bound hash, and the PIN alone can't decrypt anything without the link secret it never sees.
- The encryption key — it lives in the link's URL fragment, which never reaches our servers.
What we process
- Account data — your email and authentication identifiers, handled by our authentication provider.
- Billing data — subscription status and payment metadata, handled by our payments provider. We never store card numbers.
- Usage counters — an anonymous monthly transfer count per account, to enforce plan limits. It is not linked to any transfer contents.
- Abuse traceability — a short-lived mapping of session id to account (retained for up to 30 days) so we can act on abuse reports. It holds no file data.
- Branded links (Pro) — if you claim a public account name, we store that name and your chosen slugs. This is account branding, not transfer metadata.
- Analytics — aggregate, cookieless page metrics. No cross-site tracking, no content.
Your rights
You can delete your account at any time, which removes your account data, usage counters and branded names. For any other data request, contact us at the address below.
Contact
This is a plain-language summary and must be reviewed by qualified counsel before launch.