BackFileDrop

Privacy Policy

Effective 24 September 2026

In short: FileDrop has no accounts, ads or analytics. We only handle what is needed to move your file from one device to another, and we delete it when the transfer ends. We never sell your data or look at your files.

Who we are

FileDrop is made by Probably Fine Labs. This policy covers the FileDrop website (filedrop.imanandhu.in), the FileDrop desktop app for Windows and the FileDrop app for Android. Questions: mails@imanandhu.in.

What we process, and why

Device name and device ID. The name you give your device (shown to the person you are sending to) and a random ID created on your device so the service can recognise it between visits. Both are stored on your device.

File details.The name, size and type of the file you send, so the receiver can decide whether to accept it. These are kept in our server's memory only while the transfer is active.

File contents.When the two devices can connect directly (on the same network or peer-to-peer), the file goes straight from one device to the other and never passes through our servers. When they can't, the file is relayed: it is uploaded in pieces to temporary cloud storage (Cloudflare R2) and downloaded by the receiver.

Connection information. Your IP address and technical details of the connection, which our server needs to talk to your device and which it records in operational logs to keep the service running and secure.

Update checks (Windows app downloaded from our website).The app sends its version number, operating system and processor type to check for updates. The Microsoft Store and Android versions don't do this.

What we don't do

No accounts, no advertising, no analytics or tracking tools, no cookies for tracking. We don't sell or share your data for marketing, and we don't open, scan or read the files you transfer.

How long we keep it

Transfer details are removed from our server when the transfer finishes, is cancelled or fails. An unused transfer code expires after 30 minutes.

Relayed files are deleted from cloud storage automatically when the transfer ends, normally within a minute. Anything left behind by an interrupted transfer is removed within 24 hours.

Operational server logs are kept for up to 30 days and then deleted.

Security

Connections to our servers and to cloud storage use HTTPS/TLS encryption. Peer-to-peer transfers use the encryption built into WebRTC. Direct transfers between two FileDrop desktop apps on the same local network are protected by a one-time secret for each transfer, but travel unencrypted over that local network.

Files are not yet end-to-end encrypted: while a relayed file is in temporary storage, it is not encrypted with a key only you and the receiver hold. We are working on end-to-end encryption and will update this policy when it ships.

Services we rely on

Cloudflare provides the temporary storage for relayed files. To set up peer-to-peer connections, your device contacts connection helper (STUN) servers run by Cloudflare and Google, which see your IP address. Our servers are run by hosting providers who process data only on our behalf. If you download FileDrop from the Microsoft Store or Google Play, their own privacy policies apply to the store.

Data on your device

The website and apps store your device name, device ID and display preferences on your device. Files you receive are saved where you choose. On Android, FileDrop opts out of system backups, so received files and your device ID are not copied to your cloud backup.

Children

FileDrop is not directed at children under 13, and we don't knowingly collect their data.

Your choices and rights

You can clear your device name and ID at any time by clearing the site's data in your browser or uninstalling the app. To ask about or request deletion of any data we might hold about you, email mails@imanandhu.in.

Changes

If we change this policy, we will update it here and change the effective date above.