Privacy Policy
Last updated: July 22, 2026
The short version: Drop is built to know as little about you as possible. No account, no profile, no ads, no selling data — and your files delete themselves. We never open, scan for marketing, or train AI on anything you transfer.
1. Who we are
WeScanTransfer ("Drop", "we", "us") operates www.wescantransfer.com — a service for moving files between your own devices and for sending files to others by email (DropMail). For anything privacy-related, contact privacy@wescantransfer.com.
2. What we collect — and what we deliberately don't
- •Your transfers ("User Content"). Files, photos, scans and text you move through the service, plus minimal metadata (filename, type, size). Device↔device transfers auto-delete after 24 hours; DropMail links after 48 hours — or immediately when you press "Delete now".
- •DropMail details. The recipient's email address, the sender name/reply email you type, and your optional message — used only to deliver that one transfer, then deleted with it.
- •Waitlist email. Only if you choose to leave it, only to tell you about early access. One click unsubscribes.
- •Technical basics. Standard server logs (IP, browser type) kept briefly by our hosting provider for security and abuse prevention. For rate limiting we store a salted hash of your IP — not the IP itself. We also count page visits in aggregate, cookieless form (Vercel Analytics) — no personal profiles, no cross-site tracking.
- •Usage measurement. We use Google Analytics to understand how the site is used — pages visited, where visitors come from, device types. It sets its own cookies for this measurement. It never sees the content of your files, messages or transfers, and we do not use it to build advertising profiles.
We do not require registration, do not build profiles, do not use advertising trackers, and do not process sensitive categories of data. Session links use long random identifiers that we never log in full.
3. What we do with it (legal bases)
- •Running the service — storing and delivering your transfers (performance of a contract).
- •Security & abuse prevention — bot checks (Cloudflare Turnstile), rate limiting, blocking dangerous file types (legitimate interest).
- •Early-access updates — only with your consent, which you can withdraw anytime.
We never use the content of your files for service improvement, analytics, advertising, or training AI models. Period.
4. Who touches the data (sub-processors)
- •Cloudflare R2 — encrypted file storage (files are encrypted at rest, AES-256).
- •Supabase — metadata database and realtime channels.
- •Vercel — hosting and delivery.
- •Resend — sends DropMail notification emails.
- •Google Analytics — site usage measurement (see section 3).
- •Stripe — will process payments when paid plans launch; card details never touch our servers.
Each provider is bound by its own data-processing terms and only processes what is needed to run the service. We do not sell personal information, and we only disclose data if legally compelled to.
5. Security
Transfers travel over TLS 1.3 and rest encrypted (AES-256). Database access is deny-by-default; each session can only ever see its own rows. Download links are short-lived signed URLs. No system is 100% secure — but our best protection is simple: we keep almost nothing, and not for long.
6. Retention
- •Device↔device transfers: hard-deleted after 24 hours (files and records).
- •DropMail files: hard-deleted after 48 hours, or instantly via "Delete now".
- •Waitlist emails: until you unsubscribe or we launch and no longer need the list.
- •Rate-limit hashes and logs: rotated automatically within days.
7. Your rights
Depending on where you live (e.g., GDPR), you may have rights to access, correct, delete, restrict, or port your data, and to object to processing. Since we hold almost nothing beyond what auto-deletes, the fastest route for most requests is the built-in "Delete now" button. For anything else, email privacy@wescantransfer.com and we'll respond promptly. You may also lodge a complaint with your local data protection authority.
8. Children
The service is not directed at children under 16, and we do not knowingly collect their data.
9. Changes
We'll update this page when our practices change and bump the date above. Material changes get a prominent notice on the site.