Privacy Policy
Last updated 24 September 2026
This policy explains what personal data WispFile processes, why, and your choices. It is written from how WispFile is actually built; a field-by-field list is on What WispFile stores.
WispFile is developed by Mohiemen (mohiemen.com), who is responsible for the personal data described here. Contact: [email protected].
The short version
- We never store your files, and we never have the key that decrypts them.
- You can send and receive without an account and without giving us any personal data.
- We do not sell data or show ads. Our information pages count visits, with Google Analytics only if you allow it; the pages that send or receive files never run analytics.
- Our logs do not record IP addresses or file names by default.
What we process, and why
| Data | Why | Legal basis | Kept for |
|---|---|---|---|
| File names, sizes, optional title and message, expiry setting | To show the receiver what is on offer | Providing the service | While the link exists, and afterwards so the link can say it ended and appear in the sender’s history |
| Download outcome: bytes, direct or relayed, finished or failed | To close one-download links, and to measure reliability | Legitimate interests | As long as the link record |
| Email address and, if you give it, what you usually send | To invite you to the private alpha, if you join the waitlist | Consent | Until you are invited or ask us to remove it |
| Email address and name (name only with Google sign-in) | Your account, if you create one | Providing the service | Until you ask us to delete the account |
| Session and sign-in records (only a fingerprint of each token) | Keeping you signed in; sign-in links | Providing the service | Sessions 30 days; sign-in links 15 minutes |
| Plan, Stripe customer reference, relay bytes used | Billing and plan limits | Providing the service; legal obligations for tax records | While you subscribe, and as tax law requires |
| Branding, notification settings, inbox names, team members and roles | Features you choose to use | Providing the service | Until you change or delete them |
| Team audit log (who changed what, by email) | Accountability for team owners and admins | Legitimate interests of the team | For the life of the team |
| Email address for a back-online alert | To tell you once when a sender returns | Consent | Until the email is sent, or 7 days |
| Abuse reports: the link and your description | To investigate and remove abuse | Legitimate interests; legal obligations | As long as needed to deal with the report |
| Error reports from the web page, if enabled | Fixing crashes | Legitimate interests | Per the error tracker’s retention; stripped of link keys and personal details |
Encrypted database backups are kept for 14 days, so deleted records can remain in a backup until it expires.
What we never collect
- The contents of your files.
- The key in the link (after the
#), which browsers never send to a server. - Link passwords, which are checked only in the browser.
- Card numbers, which go only to Stripe.
Network addresses
To connect two browsers directly, each learns the other’s network address, as in a video call. In swarm mode, which the sender chooses per link, receivers can also connect to each other and see each other’s address. Our servers handle IP addresses in memory to route connections and to limit abuse, and do not log them by default.
Who else processes data
- Cloudflare: delivers the website and protects it from attacks.
- Our server hosting provider: runs the API, signaling and relay servers.
- Stripe: payments, if you subscribe.
- Resend: sends sign-in, alert and notification emails.
- Google: only if you choose to sign in with Google.
- Sentry: error reports from the web page, if enabled.
- Google Analytics: visits to our information pages, only if you allow it. Never on the pages that send or receive files.
- Cloudflare Web Analytics: cookieless visit counts on our information pages.
These providers may process data outside your country. Where the law requires it, we rely on their standard contractual protections for international transfers.
Your rights
Depending on where you live, you can ask to access, correct, export or delete your personal data, object to or restrict how it is used, and withdraw consent. Email [email protected]; we answer within 30 days. You can also complain to your local data protection authority.
Children
WispFile is not directed at children under 13, and we do not knowingly collect their data.
Changes
When this policy changes, we update the date at the top, and tell account holders by email about significant changes.