S2UShare2Us
الرئيسيةالاستخدامالمزاياالأمانتنزيلالأسعارتواصلGitHubبوابة العملاء
Legal

Privacy Policy

Last updated: effective immediately

Operator/Controller: Share2Us, operated by legal entity, Pakistan.

Contact: support@share2.us. Privacy/abuse: support@share2.us.

This policy explains what we collect, why, and your rights, including under the EU/UK GDPR.

1. Data we process

  • Account data: email, display name, Firebase user ID, plan, and account status.
  • Content: files and text you upload, stored encrypted at rest. Text-share payloads are encrypted before storage.
  • Share metadata: file name, size, content type, SHA-256, expiry, download counts, and opaque share IDs.
  • Usage and security data: request metadata, IP address for rate limiting and abuse prevention, device/session identifiers, and API/CLI/MCP credentials stored only as hashes.
  • Share analytics (viewer data): when someone opens or downloads a share, we record the viewer's IP address, an approximate country derived from that IP via Cloudflare, and the browser user-agent string. The person who owns the share can see this as share analytics: aggregate view/download counts, approximate unique-viewer counts, and a list of recent accesses. This is separate from the IP address we use for rate limiting and abuse prevention.
  • Audit events: uploads, share creation, downloads, revocations, logins, token/session changes, and MCP activity recorded as coarse, safe metadata.
  • Payment data: handled by our merchant-of-record provider. We receive subscription status and limited billing metadata, not full card details.

2. Why we process it

  • Contract: to provide accounts, uploads, and shares.
  • Legitimate interests: security, abuse and fraud prevention, service improvement, and cost protection.
  • Legal obligation: responding to lawful requests and detecting or reporting CSAM.
  • Consent: for non-essential cookies and any advertising personalisation.

3. Content integrity and abuse

We do not proactively inspect the content of your files. We reserve the right to scan, validate, and moderate content where necessary to operate the Service securely — for example to check file type and integrity, or to respond to abuse. Prohibited material (including illegal content and CSAM) is barred by our Acceptable Use terms and acted on when reported: we remove it, preserve evidence where the law requires, and report CSAM to the appropriate authorities (such as NCMEC) as required by law. We do not use your content to train models and do not sell your content.

4. Storage and international transfers

  • Content is stored in Cloudflare R2 and served via Cloudflare's global network. PostgreSQL and Redis are hosted on our own server.
  • Data may be processed outside your country, including the US and EU. Where required, transfers rely on appropriate safeguards via our processors.

5. Retention

  • Shares expire and become inaccessible per their expiry or revocation.
  • Stored objects are physically deleted on a later best-effort schedule.
  • Backups are retained for a rolling window, currently 48 hourly snapshots, and then purged.
  • Share analytics / access events (viewer IP, country, user-agent) are retained for a limited period, by default 90 days, and then automatically deleted; the retention window is configurable.
  • Account and audit data are retained per plan and legal requirements, then deleted or anonymised.

6. Your rights

You may request access, rectification, erasure, restriction, portability, and objection. You may withdraw consent for non-essential processing at any time. To exercise rights, contact support@share2.us. We will respond within the legally required timeframe.

Account deletion deletes your Firebase auth record and associated account/content per our deletion process. Some records may persist in backups until they rotate out or where retention is legally required.

7. Processors and sub-processors

  • Google: Firebase Authentication, Cloud Run, Secret Manager, and GCS backups.
  • Cloudflare: edge, R2 storage, and Access.
  • Merchant-of-record payment provider: Lemon Squeezy or Paddle.
  • Transactional email provider: self-hosted or SMTP.

A current sub-processor list is available on request.

8. Cookies

The website uses essential cookies for authentication and security. Non-essential or advertising cookies, if any, are used only with consent via our consent tool for EU/UK visitors.

9. Security

We use encryption at rest for content, hashed credentials, scoped and revocable tokens, private storage with signed-URL access, rate limiting, and audit logging. No system is perfectly secure; we cannot guarantee absolute security.

10. Children

The Service is not intended for children.

11. Changes and contact

We may update this policy; material changes will be notified. Contact: support@share2.us.

© 2026 Share2Us · share2.us← Back to home