Privacy Policy
Last updated: August 8, 2026
The short version: Drop is built to know as little about you as possible. No account, no passwords, no selling your data — and your files delete themselves. We never open, scan for marketing, or train AI on anything you transfer. We do use analytics and ad-campaign measurement to run the site, which you can opt out of (see section 3a).
1. Who we are
WeScanTransfer ("Drop", "we", "us") operates www.wescantransfer.com — a service for moving files between your own devices and for sending files to others by email (DropMail). For anything privacy-related, contact privacy@wescantransfer.com.
2. What we collect — and what we deliberately don't
- •Your transfers ("User Content"). Files, photos, scans and text you move through the service, plus minimal metadata (filename, type, size). Device↔device transfers auto-delete after 24 hours; DropMail links after 48 hours — or immediately when you press "Delete now".
- •DropMail details. The recipient's email address, the sender name/reply email you type, and your optional message — used only to deliver that one transfer, then deleted with it.
- •Waitlist email. Only if you choose to leave it, only to tell you about early access. One click unsubscribes.
- •Technical basics. Standard server logs (IP, browser type) kept briefly by our hosting provider for security and abuse prevention. For rate limiting we store a salted hash of your IP — not the IP itself. We also count page visits in aggregate, cookieless form — no personal profiles, no cross-site tracking.
- •Usage & advertising measurement. We use Google Analytics to understand how the site is used (pages visited, referral source, device type), and — on the WeScanDrop site — Google Ads and the Meta (Facebook) Pixel to measure how our ad campaigns perform and to show our own ads to people who have already visited ("remarketing"). These set their own cookies/identifiers. They never see the content of your files, messages or transfers. See section 3a for the details and how to opt out.
We do not require registration, do not sell your data, and do not process sensitive categories of data. The advertising measurement above is limited to coarse campaign and remarketing signals — never the content of your transfers — and you can opt out at any time (section 3a). Session links use long random identifiers that we never log in full.
2a. Account & subscription data (paid plans only)
The free product stays anonymous — no account, no email, nothing to sign in to. If you choose a paid plan (Plus or Pro), we then hold a small amount of account data that free users never give us:
- •Your email address and a password hash (or, if you sign in with Google, your Google account identifier and email). We never see your Google password.
- •Subscription state — which plan you are on, whether you are in a trial, the renewal date, and payment status. This is what decides your plan's limits.
- •A customer identifier from our payment processor, so we can link your account to your subscription and show you your invoices.
- •What you save — if you save files to your vault, we keep those files (and their names, sizes and types) until you delete them or your plan ends. If your plan includes transfer history, we keep a metadata-only record of your transfers: kind, direction, filename, size and time — never the file contents or the text of a message.
We never see your card details. Card entry happens directly with our payment processor (Stripe); the number never reaches our servers. We keep a record of charges because we are legally required to.
Deleting your account removes your saved files, folders and transfer history, and cancels any active subscription so you are not charged again. Records of payments already made are retained where tax and accounting law requires it, unlinked from your account. You can delete your account yourself at any time from your account page.
3a. Advertising measurement, cookies & your choices
On the WeScanDrop site we take part in Google's Advertising Features for Google Analytics and Google Ads — specifically remarketing (showing our own ads to people who have already visited), conversion measurement, and, when enabled, Google Signals (which associates measurement with Google account data for signed-in users who have consented to ads personalization, including across their devices). We use the Meta (Facebook) Pixel for the same purposes on Meta's platforms.
These features use cookies and advertising identifiers so we can understand which ads work and reach past visitors again. They never access the content of your files, messages or transfers, and we do not combine them with your transfer data.
Your choices — you can opt out at any time: Google ads personalization at adssettings.google.com; Google Analytics via the Google Analytics Opt-out Browser Add-on (tools.google.com/dlpage/gaoptout); Meta ads via your Meta ad preferences; and all of the above through your browser's cookie controls. Opting out does not affect your ability to use Drop.
Where local law — for example in the EEA, UK or Switzerland — requires your prior consent before advertising cookies are set, that requirement applies, and you can exercise or withdraw your choices using the controls above.
3. What we do with it (legal bases)
- •Running the service — storing and delivering your transfers (performance of a contract).
- •Security & abuse prevention — automated bot checks, rate limiting, blocking dangerous file types (legitimate interest).
- •Early-access updates — only with your consent, which you can withdraw anytime.
We never use the content of your files for service improvement, analytics, advertising, or training AI models. Period.
4. Who touches the data (sub-processors)
To run the service we rely on a small set of vetted third-party infrastructure providers, each bound by its own data-processing agreement and each processing only what is strictly needed for its function:
- •Encrypted object storage — holds your files, encrypted at rest (AES-256), and hard-deletes them on our schedule.
- •Managed database & realtime infrastructure — stores transfer metadata and carries the live device-to-device channel.
- •Application hosting & content delivery — serves the site securely over TLS.
- •Transactional email delivery — sends DropMail notification emails (only when you use DropMail).
- •Analytics & advertising measurement — Google (Analytics & Ads) and Meta measure site usage and ad-campaign performance and support remarketing (see sections 2 and 3a). Never sees file, message or transfer content.
- •Payment processing — handles paid-plan payments; card details are entered directly with the processor and never touch our servers.
We name providers by function rather than brand here. The current list of named sub-processors is available to any user or customer on request at privacy@wescantransfer.com. Each provider is bound by its own data-processing terms and only processes what is needed to run the service. We do not sell personal information, and we only disclose data if legally compelled to.
5. Security
Transfers travel over TLS 1.3 and rest encrypted (AES-256). Database access is deny-by-default; each session can only ever see its own rows. Download links are short-lived signed URLs. No system is 100% secure — but our best protection is simple: we keep almost nothing, and not for long.
6. Retention
- •Device↔device transfers: hard-deleted after 24 hours (files and records).
- •DropMail files: hard-deleted after 48 hours, or instantly via "Delete now".
- •Waitlist emails: until you unsubscribe or we launch and no longer need the list.
- •Rate-limit hashes and logs: rotated automatically within days.
7. Your rights
Depending on where you live (e.g., GDPR), you may have rights to access, correct, delete, restrict, or port your data, and to object to processing. Since we hold almost nothing beyond what auto-deletes, the fastest route for most requests is the built-in "Delete now" button. For anything else, email privacy@wescantransfer.com and we'll respond promptly. You may also lodge a complaint with your local data protection authority.
8. Children
The service is not directed at children under 16, and we do not knowingly collect their data.
9. Changes
We'll update this page when our practices change and bump the date above. Material changes get a prominent notice on the site.
Also available in:العربية·Deutsch·Español·Français·עברית·हिन्दी·Bahasa Indonesia·Italiano·日本語·한국어·Nederlands·Polski·Português·Русский·Türkçe·简体中文