Transparency & Trust

Privacy Policy

Last updated: October 2026. We believe privacy is a fundamental standard, not an optional feature.

1. Introduction

ShareOnline (“we”, “our”, or “us”) operates shareonline.net. This policy transparently describes our practices regarding the files and metadata processed when you use our service. Our primary principle is data minimization: we do not collect personal profiles, email addresses, or unnecessary telemetry.

2. Information We Process

  • Uploaded File Content: Files you choose to upload are temporarily stored on our servers or secure object storage to enable download by the recipients you share links with.
  • File Metadata: We store basic technical metadata necessary for file delivery: original file name, sanitized file name, file size in bytes, detected MIME type, creation timestamp, expiration timestamp, and scrypt password hash (if you enabled password protection).
  • Network & Abuse Prevention Data: When requests are made, temporary IP addresses are processed in volatile memory solely to enforce rate limits and mitigate DDoS or brute-force attacks against password-protected shares.

3. What We Do NOT Collect

  • We do not require user accounts, passwords, or emails to upload or download.
  • We do not use invasive third-party advertising trackers or sell your data.
  • We use cookieless, privacy-preserving Vercel Web Analytics solely to measure aggregated page views and service performance.
  • We do not inspect, parse, or monetize the contents of your shared files.
  • We do not store passwords in plain text anywhere.

4. Storage, Retention, and Automatic Deletion

Files uploaded to ShareOnline are subject to the expiration policy configured at the time of upload (defaulting to 7 days, with options for 1 hour, 1 day, or 30 days). Once the designated expiration timestamp is reached:

  • Access to the share link is immediately disabled.
  • The physical file in storage is permanently purged.
  • The associated database record is purged during scheduled or lazy cleanup cycles.

5. Security Safeguards

All network communication takes place over HTTPS with modern TLS encryption. Uploaded files are served strictly as attachments with hardened HTTP security headers (Content-Disposition: attachment, X-Content-Type-Options: nosniff, Content-Security-Policy) to protect recipients against malicious scripts.

6. Third-Party Hosting

Our application runs on modern cloud infrastructure (such as Cloudflare, AWS, or enterprise VPS providers) that adhere to industry security standards. These providers process raw byte streams solely to execute transmission on our behalf.

7. Contact and Inquiries

If you have questions regarding this policy or wish to report illegal content, please visit our Abuse Reporting page.