Skip to content

Privacy Policy

Last updated: July 4, 2026

Our Commitment to Privacy

OpenSend is built with privacy as a core principle. Your files and data belong to you. We do not collect, sell, rent, or share your personal information with any third party. You can send and receive files without signing up or providing any personal information.

Guest Transfers (No Account)

You can send and receive files without signing up or providing any personal information. Guest transfers work through temporary pair codes and direct peer-to-peer connections. No account, no email, no tracking.

Signed-In Users

Signing in with Google is entirely optional. If you choose to sign in, we receive only the email address associated with your Google account. This is used solely for managing your trusted devices, synchronizing transfer history across devices, and generating MCP access tokens.

Cloud Transfers

When you use Cloud Transfer (the fallback method), your files are uploaded to temporary encrypted storage on Supabase. They are automatically deleted after 24 hours and cannot be recovered after expiry. Only people with the claim code can access your transfer.

Direct Transfers

Direct transfers use WebRTC to establish a peer-to-peer connection between devices. Files are encrypted in transit via DTLS and never pass through our servers. Once the transfer completes, no copy remains on any infrastructure we control.

What We Collect

We collect the minimum necessary to provide the service:

  • Guest transfers: Nothing beyond connection metadata (IP addresses and ports for WebRTC relay).
  • Cloud transfers: Your files (encrypted, auto-deleted after 24h).
  • Signed-in users: Email address from Google OAuth, transfer metadata, and device names you provide.

We do not use advertising, ad tracking, browser fingerprinting, third-party analytics, or cookies for tracking purposes.

Third-Party Services

OpenSend uses Supabase for authentication, database, and file storage. Supabase is SOC 2 compliant. Data is stored in the us-east-1 region. See Supabase's Privacy Policy.

The application is deployed on Vercel. Vercel may process standard HTTP request logs (IP address, user agent, request path) as part of their hosting service. See Vercel's Privacy Policy.

Direct transfers use Google STUN/TURN relay servers, which see only connection metadata (IP addresses and ports) and never the file content.

Data Deletion

  • Cloud transfers: Files are automatically deleted after 24 hours.
  • Signed-in transfer history: Can be deleted from your history page at any time.
  • Full account deletion: Email sparshsam@gmail.com — data removed within 7 days.

Data Export

Signed-in users can view and export their transfer history from the history page. Files sent via direct transfer are not stored on our servers. Cloud transfer files must be downloaded before the 24-hour expiry window closes.

Changes to This Policy

If this policy changes materially, the "Last updated" date at the top will be revised. We will never reduce your privacy rights without notice.

Contact

For privacy questions or data deletion requests, email sparshsam@gmail.com.