Privacy Policy

Last updated: Aug 31, 2026

1. Overview

VeilShare is a privacy-focused file sharing service designed to minimize data collection.

Files uploaded to VeilShare are encrypted client-side before being transmitted to our servers. Encryption and decryption occur in your browser using AES-256-GCM. We never receive your decryption keys in usable form and cannot decrypt uploaded files. Even for files saved to an account, keys are only ever stored encrypted, protected by your account password to preserve end-to-end encryption.

Creating an account is optional. You can upload, share, and download files without ever signing up. An account is only needed if you want to buy a plan or manage your uploaded files.

This Privacy Policy explains what information we process, why we process it, and how long it is retained.

2. Information We Process

To operate VeilShare, we process a limited amount of technical and encrypted data.

Encrypted File Blob

Before a file is transmitted to our servers, it is encrypted locally in your browser using AES-256-GCM encryption. We store only an encrypted file blob required to deliver the file to recipients.

We don't have access to:

  • The unencrypted contents of your files
  • Decryption keys

When uploading a file, an encryption key is generated client-side in your browser. This key is used to encrypt the file before upload and is required to decrypt it upon download. The key itself never reaches our servers in usable form. It's embedded in the URL fragment, and if you're logged in, the file is saved to your account, and the key is stored encrypted behind your account password so you can access it from any device by logging in. Either way, we have no way to decrypt your files.

File Metadata

We store minimal metadata necessary for functionality, both encrypted and unencrypted, including:

  • File name (end-to-end encrypted)
  • File size
  • File expiration date
  • File download limit
  • When file link was last opened. Used to decide which files to remove if your storage execced your plans limits (ex. if your plan expires - see Retention below for more)

Password Protection

We optionally allow files to be protected with a password before download. Password protection is intended to prevent unauthorized downloads by users who possess the file link. It does not provide additional encryption of the uploaded file itself.

Your password is always stored in a hashed form.

Account Information

If you choose to create an account, we process:

  • Your email address, used for login, verification, and account-related notices
  • A hashed version of your password (we never store your password in plain text)
  • Session information such as your browser's user agent and when a session was created and last used, so you can view and revoke active sessions
  • Short-lived verification codes (hashed) used for actions like email verification, password resets, email address changes, and account deletion

If you change your email address, we keep a record of the change for account security purposes.

When you create an account, you're shown a one-time recovery key. If you forget your password and don't have this recovery key, files you'd previously saved to your account become permanently inaccessible when you reset it - we have no way to recover them.

Deleting your account permanently removes this account data. See Retention below for what happens to your files.

Payment Information

Paid plans are purchased with Bitcoin.

When you purchase a plan, we generate a unique Bitcoin deposit address for that purchase and record the amount expected, the amount received, and the payment status (pending, confirmed, or expired). We do not require or store your personal wallet address beyond the transaction that pays our generated address.

Bitcoin transactions are recorded on the public Bitcoin blockchain, which is outside of our control. If you have concerns about payment privacy, that's worth keeping in mind when choosing how you acquire and send Bitcoin.

Technical & Security Data

To protect the service against spam, abuse, and automated attacks, we process technical information such as IP addresses for rate limiting and security purposes. This data is not used for advertising or analytics.

Cookies

If you're logged in, we set a session cookie to keep you signed in. It is not used for tracking, analytics, or advertising.

3. What we DON'T collect

VeilShare is designed to minimize data collection.

We don't collect:

  • Client-side tracking or analytics
  • Advertising identifiers or trackers
  • Content of your files (they are encrypted)
  • The decryption key to your files in usable form (it stays client-side, and if saved to your account, it is protected by your accounts password)
  • Payment card or billing information (payments are Bitcoin-only)

Even for accounts, we only ask for what's needed to run the service. We don't sell or share your data with advertisers.

4. Retention

Temporary files (the default, no account required): the encrypted file blob and its metadata are automatically deleted within an hour of expiry or once the download limit is reached. Files become inaccessible immediately and cannot be downloaded.

Permanent files (available on qualifying paid plans): these do not expire automatically while your plan remains active. If your plan lapses and your storage exceeds your new plan's limit, we'll email a warning and give you 30 days to download your files or renew. After that, files over your limit are deleted untill you're back within your limit.

Account data: retained while your account is active. Deleting your account removes your account data and your stored files.

5. Third Parties

We rely on a small number of providers to run VeilShare:

These providers only receive what's necessary to perform their function. You can read their respective privacy policies for more detail.

6. Contact

If you have any questions, feel free to send us an email.

Email: [email protected]