Privacy
A plain-language summary of how DropLink handles data. Last updated October 2026.
Your files
Files go straight from the sender's device to the receiver's device over an encrypted WebRTC connection (DTLS). They are never uploaded to or stored on our server. When two devices can't reach each other directly, the data passes through an encrypted relay to get across. The relay does not keep it.
What our server does keep
- For each link: a random room ID, its access limit, expiry time, and the names and sizes of the files being shared.
- A random ID for each visitor's browser and how many have joined or finished, to enforce the access limit.
- If you set a password: only a bcrypt hash of it, never the password itself.
Links are removed after they expire (7 days at most). Wrong-password attempts are counted briefly, by IP address, in memory only, to slow down guessing.
Logs
Our web server and the network in front of it (Cloudflare) keep standard access logs, such as IP addresses and request times. These do not contain your files.
On your device
Your browser stores your theme choice, your transfer history, a random ID per link, and any partly downloaded file (so it can resume). None of this leaves your device. Clear History in the app, or clear this site's data in your browser, to remove it.
Accounts and tracking
There are no accounts. DropLink does not use advertising trackers.