Skip to policy
TransferSize

Privacy · updated 1 September 2026

TransferSize Privacy Notice

This notice describes the information used to operate TransferSize and the choices available to users. Do not upload personal data unless you have authority to share it and the service is appropriate for the required handling.
01

Information you provide

This can include account and profile details, company workspace membership and roles, chat handles, private messages, participant-submitted message reports, recipient addresses and transfer messages, transfer settings, uploaded file content, receive-link submissions, creator posts, support messages, and information needed to configure account features.

02

Information created through use

We process transfer and conversation identifiers, message sequence and read state, filenames, sizes, upload parts, download activity, expiry and limit state, browser and device information, IP and security signals, authentication events, content-free audit events, logs, and usage needed to run and protect the service.

03

Private chat and safety reports

Chat content is encrypted in transit and before database storage using server-managed keys. It is not end-to-end encrypted. TransferSize can decrypt content to deliver messages. When a participant reports a message, the selected message and their explanation are copied into a separately encrypted safety record for authorized review. Message text is not written to ordinary application logs.

04

Payments

Payment providers process checkout and billing information under their own notices. TransferSize receives transaction references, status, amount, currency, entitlement, and related records needed to unlock a delivery, manage a purchase or plan, prevent fraud, and reconcile commerce.

05

Why information is used

We use information to create accounts and transfers, operate private chat, store and deliver files and messages, send requested notifications, operate company, receive-link, and creator tools, provide support, prevent abuse, secure the service, enforce terms, comply with law, and improve reliability.

06

Service providers and disclosures

Infrastructure and operations may use providers including Cloudflare, Turso, Backblaze B2, Resend, identity providers, configured payment providers, and Google AdSense on eligible public editorial pages. Information may also be disclosed when required by law, to protect rights and safety, or in a business reorganization subject to appropriate safeguards.

07

Google advertising

On eligible public editorial pages, third-party vendors including Google may use cookies, web beacons, IP addresses, or similar identifiers to serve and measure ads. Google's use of advertising cookies enables Google and its partners to serve ads based on visits to TransferSize or other sites. Learn how Google uses information from sites that use its services at Google's partner-sites notice.

08

Advertising choices

We use a Google-certified consent management platform through AdSense Privacy & messaging. On eligible editorial pages, Google's consent message gives visitors in the EEA, UK, and Switzerland the choices Consent, Do not consent, and Manage options. Where available, use the privacy and cookie settings link at the bottom of an advertising page to revisit your decision. Visitors in supported US states can use Do Not Sell or Share My Personal Information to opt out. You can also manage personalized advertising at Google Ads Settings. TransferSize does not load AdSense on transfer downloads, receive links, the uploader, accounts, checkout, profiles, legal pages, or security and abuse-reporting pages.

09

Retention

Persistent My Files content remains while the account is active and within its allowance; a public share link can expire without deleting that owner copy. Temporary-transfer content follows its selected expiry. Deleted content remains recoverable for the plan's published recovery period before permanent deletion, subject to abuse, legal, account, and operational exceptions. Chat messages remain while at least one participant keeps the conversation. Conversations that no participant keeps are deleted after a 30-day recovery period. Resolved encrypted safety reports are deleted after 180 days unless a longer legal or safety hold is required. Content-free chat and Business audit events may be retained for up to 365 days. Backups, disputes, fraud prevention, legal preservation, and operational recovery can affect final deletion timing.

10

Cookies and local storage

Essential storage supports sessions, security, preferences, and core operation. The web chat keeps decrypted history in memory for the active session and does not intentionally persist message text in browser local storage. Optional advertising technology is limited to eligible public editorial pages and is described in the Cookies page.

11

Your choices and requests

You can change chat discoverability and contact permissions, block users, export chat data, delete conversations for yourself, or delete your chat profile in the product. Recipients may retain messages they received. For access, correction, deletion, objection, portability, withdrawal of consent, or other applicable privacy requests, email support@transfersize.com with subject “Privacy request.” Identity verification may be required.

12

Children and changes

TransferSize is not directed to children who cannot lawfully consent to the service. We may update this notice as the product or law changes and will revise the date shown above.