Privacy Policy
Last updated: July 22, 2026
The short version: Drop is built to know as little about you as possible. No account, no profile, no ads, no selling data — and your files delete themselves. We never open, scan for marketing, or train AI on anything you transfer.
1. Who we are
WeScanTransfer ("Drop", "we", "us") operates www.wescantransfer.com — a service for moving files between your own devices and for sending files to others by email (DropMail). For anything privacy-related, contact privacy@wescantransfer.com.
2. What we collect — and what we deliberately don't
- •Your transfers ("User Content"). Files, photos, scans and text you move through the service, plus minimal metadata (filename, type, size). Device↔device transfers auto-delete after 24 hours; DropMail links after 48 hours — or immediately when you press "Delete now".
- •DropMail details. The recipient's email address, the sender name/reply email you type, and your optional message — used only to deliver that one transfer, then deleted with it.
- •Waitlist email. Only if you choose to leave it, only to tell you about early access. One click unsubscribes.
- •Technical basics. Standard server logs (IP, browser type) kept briefly by our hosting provider for security and abuse prevention. For rate limiting we store a salted hash of your IP — not the IP itself. We also count page visits in aggregate, cookieless form — no personal profiles, no cross-site tracking.
- •Usage measurement. We use Google Analytics to understand how the site is used — pages visited, where visitors come from, device types. It sets its own cookies for this measurement. It never sees the content of your files, messages or transfers, and we do not use it to build advertising profiles.
We do not require registration, do not build profiles, do not use advertising trackers, and do not process sensitive categories of data. Session links use long random identifiers that we never log in full.
3. What we do with it (legal bases)
- •Running the service — storing and delivering your transfers (performance of a contract).
- •Security & abuse prevention — automated bot checks, rate limiting, blocking dangerous file types (legitimate interest).
- •Early-access updates — only with your consent, which you can withdraw anytime.
We never use the content of your files for service improvement, analytics, advertising, or training AI models. Period.
4. Who touches the data (sub-processors)
To run the service we rely on a small set of vetted third-party infrastructure providers, each bound by its own data-processing agreement and each processing only what is strictly needed for its function:
- •Encrypted object storage — holds your files, encrypted at rest (AES-256), and hard-deletes them on our schedule.
- •Managed database & realtime infrastructure — stores transfer metadata and carries the live device-to-device channel.
- •Application hosting & content delivery — serves the site securely over TLS.
- •Transactional email delivery — sends DropMail notification emails (only when you use DropMail).
- •Aggregate web analytics — cookieless, aggregate usage measurement (see section 3). Never sees file, message or transfer content.
- •Payment processing — handles paid-plan payments; card details are entered directly with the processor and never touch our servers.
We name providers by function rather than brand here. The current list of named sub-processors is available to any user or customer on request at privacy@wescantransfer.com. Each provider is bound by its own data-processing terms and only processes what is needed to run the service. We do not sell personal information, and we only disclose data if legally compelled to.
5. Security
Transfers travel over TLS 1.3 and rest encrypted (AES-256). Database access is deny-by-default; each session can only ever see its own rows. Download links are short-lived signed URLs. No system is 100% secure — but our best protection is simple: we keep almost nothing, and not for long.
6. Retention
- •Device↔device transfers: hard-deleted after 24 hours (files and records).
- •DropMail files: hard-deleted after 48 hours, or instantly via "Delete now".
- •Waitlist emails: until you unsubscribe or we launch and no longer need the list.
- •Rate-limit hashes and logs: rotated automatically within days.
7. Your rights
Depending on where you live (e.g., GDPR), you may have rights to access, correct, delete, restrict, or port your data, and to object to processing. Since we hold almost nothing beyond what auto-deletes, the fastest route for most requests is the built-in "Delete now" button. For anything else, email privacy@wescantransfer.com and we'll respond promptly. You may also lodge a complaint with your local data protection authority.
8. Children
The service is not directed at children under 16, and we do not knowingly collect their data.
9. Changes
We'll update this page when our practices change and bump the date above. Material changes get a prominent notice on the site.