Skip to main content

Privacy Policy

Last updated: 2026-09-05

Use DropAlways only for ordinary, temporary files whose disclosure would not cause serious harm. The service is not end-to-end encrypted. Do not upload confidential documents or highly sensitive personal data.

1. Scope

This Policy explains how DropAlways handles information when you use the website and temporary file-transfer service. For privacy questions or rights requests, contact support@dropalways.com.

2. Information we process

To create and deliver a transfer, we process files you choose to upload, original filenames, sizes, media types, storage-object identifiers, creation and expiry times, download limits and counts, hashes of pickup and keeper tokens, and salted hashes of optional passwords.

To operate and protect the service, we or our infrastructure providers may process request times, IP addresses, browser or device information, errors, security events, and necessary technical logs. We do not create ordinary user accounts.

3. Purposes and legal bases

We process information to provide the transfer you request, enforce retention and download limits, secure and troubleshoot the service, comply with legal obligations, and answer rights requests. Depending on applicable law, the legal basis may be performance of the service, consent, legal obligation, or legitimate interests in safe and reliable operation.

4. Cloudflare R2 and infrastructure

Uploaded files are stored in a private Cloudflare R2 bucket; transfer metadata is held in Cloudflare D1; and the site and API use Cloudflare Workers and related network services. Cloudflare processes information under its service terms, data-processing terms, and privacy policy.

Cloudflare states that R2 objects and metadata are automatically encrypted at rest with AES-256 and protected in transit with TLS. Actual processing and storage locations depend on bucket configuration, Cloudflare’s network, and any selected data-location controls, and may involve international processing.

We may use Cloudflare’s built-in reporting to view aggregate traffic, request, and performance information. Cloudflare states that its Web Analytics does not collect or use visitors’ personal data.

5. Advertising

The service may display advertising from Google AdSense or another third-party provider. Advertising providers may use cookies, web beacons, IP addresses, device identifiers, or similar technologies to deliver and measure ads and prevent fraud.

We provide the notices, consent management, and opt-out choices required by applicable law and provider policy. We will not provide uploaded file contents, filenames, pickup codes, or sharing tokens to advertising providers for ad targeting.

6. Cookies and local storage

The site uses browser local storage to remember the selected theme. This preference is not a file-transfer credential. Advertising services will use cookies or similar technologies only after the choices or consent required by applicable law.

7. Retention and deletion

Files are retained for the sender’s selected period of 6, 12, 24, or 48 hours and may be deleted earlier when a download limit is reached or the sender deletes the transfer. Related transfer records are removed with the files. A non-reversible tombstone of a used six-character pickup code may remain for up to seven days to prevent immediate reuse.

Security, error, and provider logs are retained as operationally necessary and according to provider settings and legal requirements. Some backups or technical records may age out on provider schedules after a deletion request completes.

8. Sharing, disclosure, and international processing

We disclose information only as needed to provide the service, maintain security, comply with law, respond to valid legal process, or complete a business reorganization. Recipients may include infrastructure, advertising, professional-adviser, and government-service providers acting under contracts or published terms.

Cloudflare, Google, or other providers may process information outside your location and use safeguards required by applicable law for international transfers.

9. Security and your responsibilities

We use TLS, private object storage, short-lived signed URLs, token hashing, and optional password protection to reduce risk, but no online service can guarantee absolute security. Anyone who knows the pickup details may obtain the files, and recipients may retain or forward them.

Confirm recipients, choose a short retention period, add a password when appropriate, and do not upload data whose disclosure would be unacceptable. Use an end-to-end encrypted solution for highly sensitive information.

10. Your choices and rights

You can use the keeper link to delete a transfer early and clear local preferences in your browser. Depending on where you live, you may have rights of access, correction, deletion, restriction, objection, withdrawal of consent, and data portability.

Because there are no accounts, we may need pickup or keeper details to reasonably locate a record. Withdrawing consent does not affect processing that was lawful before withdrawal. Contact support@dropalways.com for assistance.

11. Children, updates, and contact

The service is not directed to children, and we do not intentionally ask children for personal information. Contact us if you believe a child supplied information without appropriate permission.

We may update this Policy as the service, providers, or law changes and will post the revised date here. Privacy questions may be sent to support@dropalways.com.

Third-party privacy information