Back to Home

Privacy Policy

A clear account of what we process and why.

Last updated: 19 August 2026

1. Data processed

We process shared content, files, file names and paths, creation/expiry timestamps, security settings, and view counters. Plain-text passwords are neither sent nor stored.

2. Network and abuse data

Network providers can see connection/IP information, and the application boundary may use it transiently for rate limiting. Unique views use a per-share HMAC of a random browser token retained for up to 30 days; raw IP addresses are not stored in the application database.

3. Retention and deletion

Expiring and one-time shares are made unavailable and queued for deletion. “Forever” means no scheduled expiry. Provider backups, failures, and operational delays mean immediate or absolute physical deletion cannot be guaranteed.

4. Security boundaries

Transport is protected with HTTPS. Password-protected text, URLs, and metadata are encrypted in the browser; file bytes are not end-to-end encrypted. Anyone with the link and, where configured, the password can access the content.

5. Analytics and consent

Google Analytics and Tag Manager load only after you opt in. Rejecting analytics does not affect core sharing, and you can change the choice later.

6. Providers and contact

Google Firebase provides hosting and data storage. For privacy questions, contact us through irontore.com or the project’s GitHub repository.