Short version: the server helps two browsers find each other, then gets out of the way. It never sees a file.
File contents never reach our servers. Your browser sends the bytes directly to the other device over an encrypted WebRTC data channel. The bytes are not proxied, not buffered, not logged, not scanned, and not stored — we could not hand them to anyone if asked, because we never receive them.
That also means we cannot recover a file for you after the fact, and we cannot tell you what a file contained.
Room state lives in memory only. Close the sender tab (or wait out the grace period) and it is gone. There is no database of your transfers and no history.
If a direct connection cannot be made (a strict network or carrier-grade NAT), the app may use a TURN relay to carry the connection. With a relay in the path, the relay operator can observe that an encrypted connection happened and how much data crossed it — but not the contents, which remain end-to-end encrypted between the two devices. When no relay is configured, this never happens at all.
If you report a transfer, we store the room ID, the reason, and any contact detail you choose to include, so an operator can act on it. Confirmed abuse disables the room immediately. These reports are the only thing kept longer than a session. Ask us to delete one and we will.
The app is not directed at children under 13, and it collects no personal information from anyone, children included. If you believe a child has shared something concerning, report it and we will act.
If this policy changes, the new version will be posted at this address and the change will be described here rather than made silently.
Questions, or a report to escalate: use the report page, or the Report this transfer link on the page where you received the files, which reaches the operator directly.