Privacy Policy
Last updated: 18 August 2026.
This policy explains what data we process, for what purpose and for how long. It covers the website and the platform.
1. The short version
- We do not store the IP address of people who visit the pages you publish
- We do not store the full referring URL, only the domain
- Visit data is deleted automatically after 180 days
- Bots and link previews are never counted in any statistic
- Your HTML is served in an isolated context, with no access to our cookies or your session
2. Data we process
From your account
Name, email, profile picture if you upload one, and subscription and billing data processed by the payment provider. Passwords are stored hashed and never in clear text.
From the content you publish
The files you upload, their names, folders, labels and sharing settings. We do not read the content of your files for any purpose beyond storing and delivering them.
From people who visit your links
To produce visit statistics we record: country, device type, browser, operating system, the referring domain (not the full URL) and the time the page stayed open.
The visitor identifier is generated with a secret that changes every day and per organisation. In practice: the same person is counted once per day, and the identifier cannot be used to follow them across days or to cross-reference data between different customers.
When you enable reader identification
On paid plans you can ask for an email before releasing the content. In that case the visitor is told, on that screen, that the address goes to you. That data is yours; we only store and display it for you.
3. Data we do NOT process
- IP addresses of visitors to published pages
- Full referring URL
- The content of your files for model training or profiling
4. Legal bases
| Purpose | Legal basis |
|---|---|
| Creating and maintaining your account, delivering the service | Performance of a contract |
| Billing and tax obligations | Legal obligation |
| Aggregated visit statistics | Legitimate interest, with minimised data |
| Essential product communications | Performance of a contract |
| Marketing email | Consent, withdrawable at any time |
5. Sharing with third parties
We use service providers for infrastructure, email delivery and payment processing. They process data only under our instructions and for the purposes above. We do not sell personal data.
If you enable your own pixel (Meta or Google Analytics 4) on a file, the data from that file is also processed by that provider, under their policy and under your responsibility as controller of that configuration.
6. Retention periods
| Data | Period |
|---|---|
| Visit data and statistics | 180 days, deleted automatically |
| Files in the trash | 30 days, then permanent deletion |
| Previous versions of a file | the last 25 |
| Deleted account | data removed after 30 days |
| Payment and tax records | for the applicable legal period |
7. Your rights
You can request access, correction, portability, anonymisation or deletion of your data, and withdraw consent. Write to [email protected]. We reply within the applicable legal deadline.
Much of this is available directly in the product: edit your profile, change your email, revoke access for connected apps and delete your account.
8. Security
We rate-limit login attempts across three separate windows, verify email changes at the new address, and end all sessions when the password changes. Each organisation is isolated from every other.
9. Cookies
We use strictly necessary cookies for session, language and theme. We do not use advertising cookies on the website.
10. Changes
Material changes to this policy are announced before they take effect. The date at the top shows the last update.
11. Data protection contact
This document describes the product's actual behaviour, but it is a standard text and not a substitute for legal advice. Complete the company registration details and have it reviewed by a lawyer before operating commercially at scale.