Privacy policy
Last updated:
SendTheStuff (sendthestuff.com) is a service of Arbitr Labs LLC, 800 6th St, PO Box 38, Paso Robles, CA 93446. "We" and "us" mean Arbitr Labs LLC. This policy says what we collect, why, how long we keep it, and who else handles it. Questions go to support@sendthestuff.com.
In short
- Files are encrypted in transit and at rest. A transfer's link works for 14 days. Then its files are deleted, along with their names, the message and the recipients' email addresses.
- We scan files for viruses, and use hash matching to find known child sexual abuse material. Matches are reported to the National Center for Missing & Exploited Children (NCMEC).
- Our analytics use no cookies. The only cookie we set keeps you signed in.
- We don't sell your information, show ads or send marketing emails.
What we collect
When you send files
- Your email address. Your account is your email address. We email you a six-digit code to sign in.
- Your files, with their names, folder paths, sizes and types.
- What you add: an optional title and message. For email transfers, your recipients' email addresses.
- Where the upload came from: its IP address, and your browser and device details (the user agent).
- Delivery details: when the transfer was created, finished uploading and went live, and how many times each file was downloaded. For email transfers, which recipients downloaded and when.
When you receive files
- We count downloads. If you download from the link in an email we sent you, the sender can see that you downloaded, and when.
- If you use "Report abuse", we keep the reason you picked, the time, and a keyed hash of your network (explained below).
When you visit any page
- Cloudflare Web Analytics counts page views and measures page speed. It sets no cookies and stores nothing on your device. Cloudflare says it doesn't store visitors' IP addresses for this.
- PostHog receives product events, such as "file selected" or "upload finished". They pass through our own server first, and never contain names, email addresses, file names or web addresses. PostHog is set to discard IP addresses.
- Linking events within a day only. Our server gives each browser a daily ID, made from a keyed hash of its IP address and browser details. The key is deleted when the day ends (midnight UTC), so events can't be linked across days.
- Sentry receives error reports from the site and our servers. We remove links, email addresses and file names from them before they're sent.
- Rate limits. To enforce limits, we count requests by keyed hashes of IP networks. When a network hits a limit, we keep its address prefix, unhashed, for 7 days, so we can spot abuse.
When you email support
We keep your email address and what you write. Mail to support@sendthestuff.com is forwarded to our support inbox at Gmail.
What a keyed hash is
A keyed hash is a scrambled form of a value, made with a secret key that only our servers hold. We use it to count and match, for example to apply a limit or a block, without keeping the value itself. Without that key, nobody can work out the original from it.
Cookies and your browser
- One cookie keeps you signed in. It lasts 30 days after you last use SendTheStuff in that browser. Signing out deletes it.
- Upload progress. While you upload, your browser stores your files' names, sizes and IDs, so the upload can resume after a closed tab. This is cleared when the upload finishes, when the transfer is deleted, 3 days after the upload started, or when you sign out. It never holds the encryption key.
- Nothing else. No advertising, tracking or analytics cookies. That's why there's no cookie banner.
How we use it
- To run the service: store and deliver files, send the emails you ask for, and keep you signed in.
- To keep it safe: scan files, enforce limits, act on reports, and block accounts that break our Acceptable Use Policy.
- To meet legal duties: report child sexual abuse material to NCMEC, respond to valid legal process, and handle copyright notices.
- To improve the service: measure how it's used, with the analytics above.
We don't sell or rent personal information, and we don't use it for advertising.
Emails we send
- Sign-in codes.
- Email transfers, to the recipients you name.
- One email to you when a transfer is first downloaded.
- A notice if we block one of your files because our virus scanner detected something.
- A confirmation when you delete your account.
We send no marketing emails or newsletters, and our emails have no open or click tracking.
What recipients see
- An email transfer comes from our address, with your email address in its sender name, such as "you@example.com via SendTheStuff". Replies go to you.
- The download page of an email transfer also shows your email address. A link transfer's download page doesn't.
- Both kinds show the title and message you added.
Scanning
Viruses
- What's scanned: files that can carry malware, such as apps, archives, documents and scripts, are checked for known malware with ClamAV, an open-source virus scanner.
- Until the scan finishes, a file of a scanned type can't be downloaded. The page says "Checking for viruses".
- If the scanner finds a virus, we block the transfer before anyone can download it. We email you the file's name and the name of what was detected. The files are deleted within a day. We keep the file's fingerprint (a hash of its contents), the detection's name and the transfer's details for 1 year.
- Files that can run on a computer, and files we can't fully scan, can still be sent. They show: "Only open this if you trust the sender."
No scanner catches everything. A file that passed a scan can still be harmful, so only open files from people you trust.
Child sexual abuse material
- How we check. We use automatic hash matching to find known child sexual abuse material. No tool catches everything.
- Only matching against known material. We don't use AI to judge what files show. Nobody at SendTheStuff views flagged files.
- New tools. We'll update this page before we add a matching tool from another company.
When a file matches:
- The transfer is suspended at once. Recipients see "This transfer is unavailable."
- The files and the transfer's details are preserved in locked storage for 1 year, or longer if law enforcement asks.
- The account is blocked, along with any account using a variant of the same email address. Their other transfers whose files still exist are suspended and preserved too.
- We report it to NCMEC's CyberTipline. The report can include the files, their fingerprints, and the upload's time, IP address and device details. It can also include the account's email address and the transfer's details, including recipients' email addresses. It says nobody at our company viewed the files. NCMEC may pass reports to law enforcement.
- We don't tell the account holder why.
When someone reports child abuse: we suspend and preserve the transfer at once, and check it with every matching tool we have. We report it to NCMEC even if nothing matches. That report says it came from a user and that nobody at our company viewed the files.
US law (18 U.S.C. 2258A) requires online services to report apparent child sexual abuse material they become aware of to NCMEC.
Encryption
- Files are encrypted in transit and at rest.
- Each transfer has its own key. When a transfer's files are erased, we destroy its key first, so nothing can read them from that moment. After Delete now, that happens within a day.
- We hold the keys, so our systems can read files to scan them, make previews and deliver downloads. We don't open or look at your files.
How long we keep it
| Information | How long we keep it |
|---|---|
| Files, file names and folder paths, titles, messages, recipients' email addresses, and the upload's IP address and user agent | Until the transfer is deleted: when its 14 days end, or within a day after you delete it or your account. An upload that never finishes is deleted within a day once 3 days have passed. If our own cleanup ever fails, our storage provider still deletes the files within 32 days of upload. The only exception is a preserved safety record. |
| Transfer records: sizes, dates, counts and status | Kept as anonymous numbers. For 31 days after an upload starts, the record also holds your account ID and keyed hashes of your email address and network. These count your monthly limits. |
| Your account's email address | Until you delete your account. It's then removed within a day, unless a safety record must keep it. |
| A keyed hash of the network an account was created from | As long as the account exists |
| Sign-in code requests: your email address, a keyed hash of the code, and keyed hashes of your network | 24 hours |
| Counts of wrong codes (keyed hashes) | 24 hours |
| Sign-in sessions | 30 days after last use, or until you sign out |
| Network prefixes that hit a rate limit | 7 days |
| Abuse reports | 1 year, or longer while a related safety record is kept |
| Safety records: what triggered them, what we did, fingerprints, NCMEC reports, preserved files, and our records of copyright notices | 1 year, or longer if law enforcement asks |
| Copyright notices and counter-notices emailed to our copyright agent | In the agent's mailbox, support@storagebites.com, at Gmail. Ask us, and we'll delete yours once our 1-year record of it ends. |
| A blocked email address | Only as a keyed hash, while the block stands. The address itself is deleted when the account's last safety record expires. |
| Copies of our emails at Resend, our email provider | 30 days |
| Database backups | 7 days. Deleted information can remain in backups that long. |
| Emails you send to support | In our Gmail support inbox. Ask us, and we'll delete yours. |
If you delete your account, keyed hashes of your email address stay on your transfer records for up to 31 days after each upload. They stay on copyright notices for 1 year. That way, deleting and re-creating an account doesn't reset the monthly limits or the repeat-infringer count.
Who else handles your information
We give each provider only what its job needs.
| Provider | What it does for us | What it receives |
|---|---|---|
| Cloudflare | Runs our site, servers, database connections and virus scanner. It also delivers downloads, caches image previews, runs the CSAM Scanning Tool and Web Analytics, and receives email sent to our addresses. | Everything our site and servers handle: every request, with its email and IP addresses, and files' decrypted contents while they're scanned, previewed or downloaded |
| Backblaze | Stores files | Your files, encrypted. Uploads go straight from your browser to Backblaze. Each request carries the transfer's key, and Backblaze keeps only a hash of it, which can't decrypt the files. |
| Neon | Hosts our database | Account, transfer and safety records |
| Resend | Sends our emails | Each email we send, with its addresses, codes, titles and messages. It keeps copies for 30 days, and our plan can't shorten that. |
| PostHog | Product analytics | Events with no names, email addresses, file names or web addresses. IP addresses are discarded. |
| Sentry | Error reports | Error reports with links, email addresses and file names removed |
| Google (Gmail) | Our support inbox, and our copyright agent's inbox | Emails you send to support@sendthestuff.com, and copyright notices and counter-notices sent to support@storagebites.com |
When we share information
- With your recipients: what's described under "What recipients see" above.
- With NCMEC: reports of child sexual abuse material, as described above.
- With law enforcement: we disclose file contents, titles and messages only under a search warrant. We disclose other information only under valid legal process, such as a subpoena or court order, or when the law requires it. The reports federal law requires us to make to NCMEC, described above, are separate.
- With copyright complainants: if you send a counter-notice, we forward it, including your contact details, to the person who sent the notice. See our Copyright Policy.
- If the business changes hands: if Arbitr Labs LLC sells or merges SendTheStuff, this information would pass to the new owner under this policy.
Your choices
- Delete a transfer at any time with "Delete now" in My transfers. The link stops at once, and the files are erased within a day, with no recovery.
- Delete your account while signed in. All its transfers are deleted within a day, and then the account.
- Sign out to remove the sign-in cookie and your browser's upload progress.
- Ask us anything about your information at support@sendthestuff.com. We aim to reply within 2 business days.
We can't delete safety records or copyright records before their time is up, or anything else the law requires us to keep.
Children
SendTheStuff isn't for children under 13, and we don't knowingly collect information from them. If you think a child under 13 has an account, write to support@sendthestuff.com.
Where we operate
SendTheStuff is run from the United States, in English, for people in the United States.
Changes to this policy
When we change this policy, we post the new version here and update the date at the top.
Contact
Arbitr Labs LLC, 800 6th St, PO Box 38, Paso Robles, CA 93446. Email support@sendthestuff.com.