No ad tracking
We do not use advertising trackers, behavioural profiling, or analytics cookies.
No cloud file library
Message and file contents are not intentionally written to our billing database.
Encryption in your browser
Content is encrypted before it travels and decrypted by the connected recipient.
1. Who controls your information
Denovi Ltd is the controller of personal information described in this notice. We are registered in England and Wales under company number 09859016. Our registered office is The Garth, Bucklebury, Reading, England, RG7 6SB.
Email privacy@droptunnel.com about privacy or data rights. We have not appointed a formal data protection officer; privacy matters are overseen internally by Denovi Ltd. Our main establishment for this processing is the United Kingdom.
2. What this notice covers
This notice covers droptunnel.com, api.droptunnel.com, free tunnels, Droptunnel Plus, device linking, billing management, service emails, support, security, and abuse reports. A connected recipient and third-party websites have their own responsibilities and privacy practices.
3. Information we handle
Tunnel and connection data
- a randomly generated eight-character tunnel code, random connection identifiers, peer role, connection and heartbeat times, tunnel plan, file-size limit, and expiry information;
- WebRTC signalling and network connection information needed to establish the peer connection, which can include IP addresses and ICE candidates; and
- encrypted message or file frames handled transiently by the Cloudflare relay if a direct WebRTC connection cannot be used.
We do not need your name or email to create a free tunnel. Tunnel codes are not intended to identify you, but they and associated network information can be personal information in context.
Message and file contents
Content, file names, file metadata, and text are processed in the two connected browsers. They are encrypted before transmission. We do not intentionally store plaintext transfer contents on our servers or in D1. Encrypted fallback frames may pass through the relay in memory but are not intentionally retained as a content archive.
Plus billing and device data
- Stripe customer, subscription, Checkout Session, and webhook event identifiers;
- subscription status, current billing-period end, cancellation status, and record timestamps;
- a random browser device identifier, a coarse label such as “Safari on iOS,” device role, creation and last-seen times, and revocation status;
- cryptographic hashes of short-lived device, owner-verification, and subscription-recovery tokens, plus hashed recovery rate-limit identifiers; and
- a signed Plus entitlement stored in your browser. It contains a subscription identifier, device identifier, role, plan, and expiry.
Stripe collects the payment and billing details shown on its hosted Checkout page. We do not receive or store your full payment-card number. When owner verification or subscription recovery is requested, we process the subscription email you provide or retrieve it from Stripe to send the one-time link. Our D1 database does not store the email address itself. Recovery rate limits use keyed hashes; a complimentary entitlement may use a one-way digest-derived customer identifier. Stripe and the email service may retain their own delivery and transaction records.
Technical, security, and support data
- request method, route category, timestamps, response information, errors, approximate location or network information, IP address, user agent, and security signals processed by Cloudflare;
- information you include in support, privacy, security, legal, or abuse communications; and
- evidence, correspondence, decisions, and available service metadata associated with a complaint, legal request, or investigation.
4. Cookies and local browser storage
Droptunnel does not currently use advertising cookies, analytics cookies, cross-site tracking, or marketing pixels. We therefore do not display a cookie-consent banner for the current service.
We use only storage we consider necessary to provide features you request:
- Local storage: a random browser device identifier and, for Plus, a signed entitlement so the browser can remain linked and prove access;
- Origin Private File System: large incoming files may be written temporarily to private browser storage so they do not have to fit entirely in memory; and
- Provider security technology: Cloudflare may use strictly necessary network, load-balancing, fraud-prevention, or security mechanisms when delivering the site.
This information stays on your device unless the relevant token or identifier is presented to our API. You can remove it through your browser’s site-data controls, although doing so will unlink Plus from that browser and may remove an undownloaded local file. If we later introduce optional analytics, advertising, or similar storage, we will update this notice and obtain consent where required before it is used.
5. Why we use information and our lawful bases
| Purpose | Information | UK/EEA lawful basis |
|---|---|---|
| Provide, connect, and expire tunnels | Tunnel, connection, signalling, and encrypted relay data | Contract; legitimate interests in operating the service |
| Sell and administer Plus | Billing, subscription, device, and entitlement data | Contract; legal obligations for financial records |
| Protect the service and prevent fraud or misuse | Technical logs, security signals, device and report data | Legitimate interests; legal obligations |
| Respond to support and rights requests | Correspondence, identifiers, and request evidence | Contract; legitimate interests; legal obligations |
| Handle illegal-content reports and legal process | Reports, evidence, available metadata, and decisions | Legal obligations; substantial public interest where applicable |
Our legitimate interests are providing a secure and reliable service, diagnosing failures, protecting users and infrastructure, enforcing our Terms, preventing fraud, and establishing or defending legal claims. We balance those interests against your rights and minimise the information used. We do not rely on consent for necessary service processing. If we ask for consent for an optional purpose, you may withdraw it at any time.
6. Who receives information
- Your connected peer: receives the content and transfer metadata you choose to send and may receive network information during WebRTC connection establishment.
- Cloudflare: provides DNS, content delivery, Workers, Durable Objects, D1, security, operational logs, and transactional email infrastructure.
- Stripe: acts as our payment and subscription service and also processes payment information under its own privacy terms.
- Google public STUN: helps browsers discover network routes for peer-to-peer connections and necessarily receives network requests and IP information; it does not receive Droptunnel plaintext transfer contents from us.
- Professional advisers and authorities: may receive necessary information for legal advice, insurance, audit, accounting, safety, enforcement, or compliance.
- Business successors: may receive information in a proposed or completed financing, reorganisation, acquisition, or transfer, subject to appropriate confidentiality and legal duties.
We do not sell personal information. We do not share it for cross-context behavioural advertising and do not use it to build advertising profiles.
7. International processing
Droptunnel is available worldwide and uses Cloudflare’s global network. The current deployment does not promise that all processing or stored operational data remains in the UK or EEA. D1 and Durable Object jurisdiction restrictions are not declared in the deployed project configuration, so Cloudflare may determine processing and storage locations across its infrastructure. Stripe, Google, and email infrastructure may also process information internationally.
Where data protection law restricts an international transfer, we use an applicable adequacy decision or contractual safeguards made available by our providers, such as the UK International Data Transfer Agreement or UK Addendum and the European Commission’s Standard Contractual Clauses, together with supplementary safeguards where required. Contact us for more information about safeguards relevant to your information.
8. How long we keep information
| Record | Typical retention |
|---|---|
| Tunnel control state | For the active tunnel and normally no more than approximately ten minutes after expiry or closure |
| Plaintext messages and files | Not intentionally stored by Denovi Ltd |
| Transient encrypted relay frames | Handled in memory for delivery; not kept as a content archive |
| Cloudflare Worker error logs | Up to seven days, depending on the Cloudflare plan |
| Subscription and Checkout records | For the subscription and up to seven years afterwards for accounting, tax, fraud, and legal claims |
| Active device records | While linked; revoked device data is normally removed after two years, subject to legal or security need |
| Expired activation, verification, and subscription-recovery token hashes | Normally removed within 30 days after expiry |
| Processed Stripe webhook identifiers | Normally up to two years for event integrity and audit |
| Routine support and privacy correspondence | Normally up to three years after closure |
| Safety, abuse, dispute, or legal records | Normally up to six years, or longer where a live investigation, safeguarding need, legal hold, or law requires it |
We may keep aggregated information that no longer identifies anyone. Provider backups may retain deleted records for a limited additional period before cycling out. Local browser data remains until the app or browser removes it, it expires, you clear site data, or your device storage system deletes it; Denovi Ltd does not control your device’s retention settings.
9. How we protect information
Measures include TLS, browser-side authenticated encryption, a password-authenticated pairing handshake, short-lived tunnel codes, two-peer limits, automatic tunnel expiry, signed and revocable Plus passes, hashed one-time tokens, origin checks, Stripe-hosted payment, restricted service bindings, and minimised application logging.
We limit application access according to operational need. No security system is perfect, and we cannot guarantee that unauthorised access, disclosure, loss, or misuse will never occur. Report a suspected vulnerability to security@droptunnel.com.
10. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to use of your personal information; obtain a portable copy; withdraw consent; and complain to a regulator. These rights can be limited where an exemption applies or information must be retained for contract, safety, fraud, legal, or accounting reasons.
Email privacy@droptunnel.com to make a request. Include enough information to locate the relevant record, such as a Stripe billing email, subscription reference, browser device identifier, request date, or prior correspondence. We may need to verify your identity and authority. We cannot retrieve plaintext tunnel contents that we do not hold.
In the UK, you may complain to the Information Commissioner’s Office at ico.org.uk. EEA residents may complain to their local supervisory authority. We would appreciate the opportunity to address the concern first.
11. Additional United States disclosures
Residents of certain US states may have rights to know, access, correct, delete, or obtain a copy of personal information and to appeal a denied request. Droptunnel does not sell personal information, share it for cross-context behavioural advertising, use it for targeted advertising, or provide financial incentives in exchange for it. We do not knowingly process children’s information through a service offered to children.
The categories handled during the preceding twelve months are identifiers and network activity, commercial and subscription records, device information, customer communications, and any information a person chooses to include in a report. They are used and disclosed for the purposes and to the recipients described above.
12. Automated decisions and children
We do not use personal information for solely automated decisions that produce legal or similarly significant effects, and we do not profile users for advertising. Automated security, token-validation, subscription-status, rate-limit, and device-limit checks may allow or deny a request; contact support if you believe a check is wrong.
Droptunnel is not intended for anyone under 18. Do not use the service or provide information to us if you are under 18. If you believe a child has contacted us or provided account-related information, email privacy@droptunnel.com. Because free transfers do not use accounts and contents are encrypted, we may not be able to identify the people using a tunnel from content.
13. Changes and contact
We may update this notice as the service, providers, or law changes. We will post the new version and date here and use an additional site or billing notice for material changes where appropriate.
- Privacy: privacy@droptunnel.com
- Security: security@droptunnel.com
- Misuse: abuse@droptunnel.com
- Legal: legal@droptunnel.com
Postal notices may be sent to Denovi Ltd, The Garth, Bucklebury, Reading, England, RG7 6SB.
