Privacy
Last updated:
Template — review before launch. This describes what the software actually collects, but if you serve users in the EU, UK, or California you should have it reviewed and add your legal basis, controller identity, and any data-subject request process.
The short version
No accounts. No email addresses. No analytics scripts, ad networks, or third-party requests of any kind — every asset on this site is served from our own server. We keep the minimum needed to run the service and deal with abuse, and it goes away on a schedule.
What we collect
| Data | Why | How long |
|---|---|---|
| The files you upload | To deliver them to whoever you share the link with. | Until the transfer expires (15 days by default, or sooner if you choose), then permanently deleted. |
| Filenames, sizes, and your optional title and note | To show the recipient what they're downloading. | Deleted with the transfer. |
| A keyed hash of your IP address | Rate limiting and abuse handling. We store an HMAC, not the address itself — it can confirm two uploads came from the same connection but cannot be reversed into an IP. | 30 days for rate-limit records; deleted with the transfer otherwise. |
| Your browser's user-agent string | Diagnosing upload failures and identifying automated abuse. | Deleted with the transfer; download logs are trimmed after 90 days. |
| Download timestamps and counts | Enforcing download limits and showing the sender whether their files were collected. | 90 days. |
| Abuse reports | Reviewing and acting on reported content. Includes your email only if you choose to provide one. | Retained for our abuse records after the transfer itself is gone. |
What we don't collect
- No name, email address, or phone number — there is no signup form to put one in.
- No advertising or analytics cookies. The only cookie the site can set is a short-lived one that remembers you entered the correct password for a specific transfer.
- No cross-site tracking, fingerprinting, or third-party scripts.
- No raw IP addresses in our database.
Cookies and local storage
One cookie, set only when you unlock a password-protected transfer: it holds a signed token scoped to that single transfer's page, expires after six hours, and is marked HttpOnly and SameSite. Your colour-theme preference is kept in your browser's local storage and never sent to the server.
Encryption
All traffic is over HTTPS. Files are stored on disk outside the web root under generated names. They are not end-to-end encrypted — the server can read them, which is what makes previews, zip downloads, and resumable uploads work. If that matters for your content, encrypt it before uploading and share the passphrase through a different channel.
Who else sees your data
Anyone you give the link to. Our hosting provider, as the operator of the physical infrastructure. Law enforcement, if we receive a valid legal order. Nobody else — we don't sell, rent, or share data with advertisers or data brokers, and there are no third-party processors in the request path.
Your choices
- Delete a transfer immediately from the tab you uploaded it in.
- Set a shorter expiry, or a download limit, before you upload.
- Add a password so filenames and contents stay hidden without it.
- Simply don't upload it — that is always the strongest privacy control available.
Children
The Service is not directed at children under 13, and we don't knowingly collect their data. Since there are no accounts, we have no way to verify age.
Contact
Questions about this policy or a request about your data: hello@filmyduniya.cloud. Because uploads are anonymous, we may not be able to identify which data is yours without the transfer link.