WispFile

Privacy Policy

Last updated 24 September 2026

This policy explains what personal data WispFile processes, why, and your choices. It is written from how WispFile is actually built; a field-by-field list is on What WispFile stores.

WispFile is developed by Mohiemen (mohiemen.com), who is responsible for the personal data described here. Contact: [email protected].

The short version

  • We never store your files, and we never have the key that decrypts them.
  • You can send and receive without an account and without giving us any personal data.
  • We do not sell data or show ads. Our information pages count visits, with Google Analytics only if you allow it; the pages that send or receive files never run analytics.
  • Our logs do not record IP addresses or file names by default.

What we process, and why

DataWhyLegal basisKept for
File names, sizes, optional title and message, expiry settingTo show the receiver what is on offerProviding the serviceWhile the link exists, and afterwards so the link can say it ended and appear in the sender’s history
Download outcome: bytes, direct or relayed, finished or failedTo close one-download links, and to measure reliabilityLegitimate interestsAs long as the link record
Email address and, if you give it, what you usually sendTo invite you to the private alpha, if you join the waitlistConsentUntil you are invited or ask us to remove it
Email address and name (name only with Google sign-in)Your account, if you create oneProviding the serviceUntil you ask us to delete the account
Session and sign-in records (only a fingerprint of each token)Keeping you signed in; sign-in linksProviding the serviceSessions 30 days; sign-in links 15 minutes
Plan, Stripe customer reference, relay bytes usedBilling and plan limitsProviding the service; legal obligations for tax recordsWhile you subscribe, and as tax law requires
Branding, notification settings, inbox names, team members and rolesFeatures you choose to useProviding the serviceUntil you change or delete them
Team audit log (who changed what, by email)Accountability for team owners and adminsLegitimate interests of the teamFor the life of the team
Email address for a back-online alertTo tell you once when a sender returnsConsentUntil the email is sent, or 7 days
Abuse reports: the link and your descriptionTo investigate and remove abuseLegitimate interests; legal obligationsAs long as needed to deal with the report
Error reports from the web page, if enabledFixing crashesLegitimate interestsPer the error tracker’s retention; stripped of link keys and personal details

Encrypted database backups are kept for 14 days, so deleted records can remain in a backup until it expires.

What we never collect

  • The contents of your files.
  • The key in the link (after the #), which browsers never send to a server.
  • Link passwords, which are checked only in the browser.
  • Card numbers, which go only to Stripe.

Network addresses

To connect two browsers directly, each learns the other’s network address, as in a video call. In swarm mode, which the sender chooses per link, receivers can also connect to each other and see each other’s address. Our servers handle IP addresses in memory to route connections and to limit abuse, and do not log them by default.

Who else processes data

  • Cloudflare: delivers the website and protects it from attacks.
  • Our server hosting provider: runs the API, signaling and relay servers.
  • Stripe: payments, if you subscribe.
  • Resend: sends sign-in, alert and notification emails.
  • Google: only if you choose to sign in with Google.
  • Sentry: error reports from the web page, if enabled.
  • Google Analytics: visits to our information pages, only if you allow it. Never on the pages that send or receive files.
  • Cloudflare Web Analytics: cookieless visit counts on our information pages.

These providers may process data outside your country. Where the law requires it, we rely on their standard contractual protections for international transfers.

Your rights

Depending on where you live, you can ask to access, correct, export or delete your personal data, object to or restrict how it is used, and withdraw consent. Email [email protected]; we answer within 30 days. You can also complain to your local data protection authority.

Children

WispFile is not directed at children under 13, and we do not knowingly collect their data.

Changes

When this policy changes, we update the date at the top, and tell account holders by email about significant changes.