Skip to content

Privacy Policy

Last updated: August 25, 2026

Shareboxed is a file sharing service, operated from the Netherlands. This policy describes what we process when you use the website at shareboxed.app, the Shareboxed app for Mac, and the links people share with it. Questions and requests: support@shareboxed.app.

Shareboxed is built to know as little as possible. Where we can serve a share without being able to read it, that is how it works. Where we do hold something readable, this policy says so plainly.

What we process, and why

Your account. Signing in takes an email address and nothing else: we send a code to it, or you use a passkey. We store the email address, passkey public keys, and session records for the devices you signed in on. We do not ask for your name. Legal basis: performing our agreement with you.

Files you share through Shareboxed hosting. Files are encrypted on your own device before they are uploaded; what our storage holds is ciphertext. We do store the file names, sizes and folder structure of a hosted share in readable form, because the download page lists them, and we hold the key material needed to serve the share. Hosted shares are not zero knowledge. They are deleted automatically when the share expires, at most 30 days after upload. Legal basis: performing our agreement with you.

Shares from your own storage. When you connect your own S3 compatible storage, we store the access credential you provide, encrypted at rest, and use it only to sign downloads for links you created. The list of file names in such a share is stored as an encrypted blob we cannot read; what we can read is the folder prefix the share covers. Turning the sharing switch off, or deleting the connection, deletes the stored credential and ends every link from it. Legal basis: performing our agreement with you.

Direct shares. A direct share is served from your own device. The file contents and file names never reach us. We store the share id, a hashed host token, and, when the transfer uses our relay, how many bytes the relay carried. Legal basis: performing our agreement with you.

Sync. The app can sync its configuration between your devices. What we store is a blob encrypted on your device with a key that never reaches us. We cannot read it. Legal basis: performing our agreement with you.

Email. We send transactional email only: sign in codes and service notices such as approaching your monthly limit. We keep delivery records (address, message type, delivery status) so we can see whether our mail arrives. There is no marketing mail. Legal basis: performing our agreement with you.

Payments. Subscriptions are sold by Polar, our merchant of record. Polar processes your payment details and billing information under its own privacy policy; we never see your card number. We store your subscription status and a customer reference. Legal basis: performing our agreement with you.

Logs and abuse prevention. Our servers keep request logs with shortened identifiers for seven days, to diagnose problems. IP addresses are used for rate limiting, so that guessing share links and flooding the service stay impractical. Legal basis: our legitimate interest in running a secure service.

Who processes data for us

We use three processors, each bound by a data processing agreement:

Processor What for
Cloudflare Hosting, storage, logs, and the transfer relay
Resend Sending transactional email
Polar Payments, as merchant of record

These providers are established in the United States. Transfers rely on the EU-US Data Privacy Framework and standard contractual clauses. We do not sell personal data, and we share it with nobody else unless the law obliges us to.

How long we keep things

Data Kept for
Hosted share files and metadata Until the share expires, at most 30 days
Own storage and direct share rows 7 days live, then 30 days in your share history
Server logs 7 days
Rate limiting counters Minutes to hours
Account, sessions, sync blob Until you delete your account
Email delivery records Until you delete your account
Subscription records As long as required for tax and bookkeeping

Deleting your account, which you can do yourself on the account page, removes your stored files, shares, connections, sync data, sessions and email records, and asks Polar to delete your customer record.

Your rights

You can access, correct, export or delete your personal data. Most of this you can do directly in the app or on the account page; for anything else, email support@shareboxed.app from the address on your account, which is how we verify the request is yours. We answer within four weeks.

If you believe we handle your data wrongly, you can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Children

Shareboxed is not directed at children under 16, and we do not knowingly process their data without parental consent. If you believe we hold data about a minor, contact us and we will remove it.

Cookies

The website sets only functional cookies: a session cookie when you sign in. There are no analytics or tracking cookies, and nothing from third parties.

Security

Files for hosted shares are encrypted on your device before upload. All traffic is encrypted in transit. Credentials you give the app are stored in your Mac's keychain, and credentials we store server side are encrypted at rest. No system is perfectly secure; if you find a weakness, we want to hear about it at support@shareboxed.app.

Changes

When this policy changes we update the date at the top, and for meaningful changes we notify account holders by email.

Terms of Service