Last updated: August 6, 2026
Stashr is built with privacy at its core. This policy explains, in plain terms, what we collect, why we collect it, how long we keep it, and the rights and choices you have. The short version: we collect only what's needed to run the service and keep it safe, we never sell your data, anything you encrypt in your browser stays unreadable to us, and files sent through P2P Transfer never reach our servers in the first place.
Whether or not you are logged in, when you upload a file we create and store a record of that upload. This record contains:
The data is collected for the purpose of operating the platform and preventing abuse. All collected data is automatically deleted after a period of 30 days.
Creating an account is optional. If you do, we additionally store: your username, an optional display name, your password (kept only as a salted hash), your email address if you provide one (used for password recovery and account notices), your account creation date and last login time, and running totals of your uploads and storage used. Files you upload while logged in are linked to your account so you can manage them.
When someone reports a file, we store the reason given, any optional details or contact information they provide, and the reporter's IP address. We use this solely to investigate the report and to keep records for legal compliance.
Client-side encryption is an optional feature you can switch on per upload. When you enable it:
This makes client-side encryption effectively zero-knowledge: we have no way to read your file's contents. Even if we are compelled by a legal process, we can only hand over the encrypted data, which is useless without the password only you hold.
P2P Transfer is an alternative to uploading. Instead of storing your file, we help two browsers find each other, and the file then travels straight from one device to the other over an encrypted WebRTC connection.
Your files play no part in this. They are never uploaded to our servers, never stored, never scanned, and never logged. We do not learn the name, size, type, or contents of anything you send this way, and we cannot produce or recover it afterwards, including in response to a legal request. There is simply nothing on our side to hand over.
What we do process is the small amount of information needed to introduce the two devices to each other:
This data is deliberately short-lived: connection messages are deleted after 2 minutes, a device record disappears 20 seconds after it stops responding, and the pairing code itself is removed after 15 minutes. Once a session ends, nothing about it remains.
Two things follow from the transfer being genuinely direct, and we would rather state them plainly than leave them in the small print:
Your data serves three primary purposes within Stashr. First and foremost, we use it to operate the service itself—storing and delivering your files securely, enforcing the access controls you set, managing automatic file expiration, and generating secure sharing links. Every piece of data we collect directly supports these core functions.
Security and abuse prevention form our second priority. We actively monitor for malicious uploads, spam, and automated abuse attempts. When users report problematic content, we investigate and take appropriate action. This continuous monitoring helps maintain Stashr as a safe platform for legitimate file sharing while preventing misuse.
Finally, we analyze aggregated usage patterns to improve service performance and reliability. This helps us identify technical issues, optimize file transfer speeds, and develop new features that benefit all users. All analytics are conducted on anonymized, aggregated data to protect individual privacy.
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects, and we never build advertising profiles about you.
We process your personal data on the following legal grounds:
Uploaded files are stored on third-party messaging and cloud infrastructure rather than on servers we own directly. All transfers between your device and Stashr use TLS/SSL encryption. Files you password-protect have that password enforced on our side; files with client-side encryption are encrypted in your browser before they ever reach us.
How long we keep things:
We never sell, rent, or trade your personal information to third parties for marketing purposes. This is a core principle that will not change.
We share data only in limited circumstances. Your uploaded files are stored on and delivered through the third-party infrastructure listed in Section 10, including the messaging and cloud storage provider we use as our storage backend, which therefore processes your files and certain metadata to provide storage and delivery.
We disclose information to authorities when required by law, court order, or a valid law-enforcement request, reviewed and fulfilled only to the extent legally required. As a service based in the Netherlands, we report suspected child sexual abuse material to the appropriate authorities and hotlines, such as the Dutch EOKM / offlimits.nl and, where relevant, NCMEC, as required by law. In emergencies involving imminent harm, we may share necessary information to help prevent it.
Important note on encrypted files: For files uploaded with client-side encryption, we can only provide the encrypted data in response to legal requests. Without your encryption password (which we never have), this data cannot be decrypted.
When you upload, you control important privacy settings up front: password protection, optional client-side encryption, download limits, and an expiry time (from 1 hour up to 30 days, or "keep forever"). If you have an account, you can manage and delete your uploaded files at any time from your dashboard, and deleting your account removes your files and account data with it. For uploads made without an account, the file is governed by the expiry and limits you chose at upload time; if you need an anonymous upload removed sooner, contact us using the details in Section 14 (the sharing link helps us locate it).
If you are located in the European Union or European Economic Area, you are entitled to specific rights under the General Data Protection Regulation (GDPR). You may at any time:
To exercise any of these rights, please contact us using the details provided in Section 14 below. We will respond to valid requests within 30 days.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
To submit a request under the CCPA, please contact us at privacy@stashr.wtf. We will verify your identity before processing your request and respond within 45 days.
Stashr uses cookies and similar technologies sparingly and only for essential purposes:
We do not use third-party tracking cookies or analytics services that track individual users.
Stashr honors Do Not Track (DNT) signals sent by your browser. Since we do not engage in cross-site tracking or serve targeted advertisements, our service operates in a privacy-respecting manner regardless of your DNT setting.
Stashr relies on the following third parties to operate, each of which has its own privacy policy:
Each third-party service operates under its own privacy policy and security standards. If Stashr links to external websites, those sites operate independently under their own privacy policies, which we encourage you to review.
Stashr is not designed for or directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected such information, we will take immediate steps to delete it from our systems.
As a global service, your data may be transferred to and processed in countries outside your own, including outside the EU/EEA. Where that happens, we rely on safeguards recognised under the GDPR, such as an EU adequacy decision or Standard Contractual Clauses, so your data keeps the same level of protection wherever it is processed.
Stashr does not delete accounts or associated files due to inactivity. Your account and all files linked to it will remain available indefinitely until you choose to delete them yourself. The only exception is files uploaded with a temporary expiration period, which are automatically removed once the configured timeframe has passed.
In the unlikely event of a security breach affecting user data, we have comprehensive response procedures in place. We will promptly investigate the incident, take immediate steps to mitigate any harm, and notify affected users if required by applicable law. We will also report the incident to relevant authorities as legally mandated. Note that files uploaded with client-side encryption remain protected even in a breach scenario, as the encrypted data is unusable without user passwords.
This Privacy Policy may be updated periodically to reflect changes in our practices or legal requirements. When we make changes, we'll update the "Last Updated" date at the top of this page. For material changes, we may provide additional notice through the service. Your continued use of Stashr after policy updates constitutes acceptance of the revised terms.
The data controller responsible for your personal data is:
Stashr
Based in the Netherlands
Contact: privacy@stashr.wtf
As the data controller, Stashr determines the purposes and means of processing your personal data as described in this Privacy Policy. For questions regarding data processing or to exercise your rights under applicable privacy laws, please use the contact details above or visit our contact page.
We welcome questions and concerns about this Privacy Policy or our data protection practices. You can reach us through: