Uploading (no account): the file, its hash, filename, size, and type.
Developer API (signed in): your Google email + user ID via Supabase Auth, plus a hash of your API key (never the key itself) and when it was last used.
No analytics, no ad trackers, no cookies beyond what keeps you signed in.
We hash your IP address and keep it briefly, only to rate-limit uploads and catch abuse. It isn't stored alongside the file, isn't used to figure out who uploaded what, and isn't linked to any file record — it exists purely to answer "is this IP sending too many requests," nothing else.
Files stay until deleted via the delete link or removed by us. Account data stays until you delete your account or we do, for a rules violation.
Delete any file with its delete link. Revoke your own API keys anytime from your account page.
If you upload without an account, we can't tie it to you — which also means we can't prove it's yours later if you lose the delete link.
If this policy changes in a way that matters, we'll update this page. Use of the product implies that you have accepted the privacy policy.