Read this first
We are not lawyers, and nothing on this page is legal advice. It is a plain-language statement of the rules we intend to operate under, published early so it can be reviewed properly rather than written in a hurry after a problem.
DRAFT — NOT YET REVIEWED BY A LAWYER. This page is written to start that review, not to replace it. Sharing is disabled in the running product and must stay disabled until this document has been reviewed for the jurisdiction the operating entity is registered in.
What we can and cannot see
A share link stores a file we cannot read. It is encrypted in your browser before anything is uploaded, and the key travels in the part of the link after the # symbol, which browsers never send to a server. That is the point of the feature, and it is also the honest limit of what we can police.
We cannot scan shared files for anything, because we cannot decrypt them. Any service that offers end-to-end encrypted sharing and also claims to scan content is doing one of those two things badly. We would rather say plainly which one we are not doing.
What we can see is a random identifier, the size of the encrypted blob, when it was uploaded and when it expires, and the network address it came from. We can delete a file by its identifier without ever decrypting it, and that is the mechanism behind everything below.
What must not be shared
- Material that sexually exploits or abuses children. There is no context in which this is acceptable, and reports of it are acted on before review rather than after.
- Malware, ransomware, or anything designed to gain unauthorised access to a computer or account.
- Material intended to defraud — phishing kits, forged documents, fake credentials.
- Content that harasses, threatens or endangers a person, including material published to expose someone against their will.
- Anything you do not have the right to distribute.
Limits, and why they are what they are
| Limit | Reason |
|---|---|
| Links expire within 24 hours, always | The cap is a safety measure, not a paywall. A service that will hold something for a day is close to useless for distributing anything durably, and it bounds how much could ever be handed over under a legal order. |
| Modest size cap without a licence | Same reasoning. Large files are where the abuse value is, and a low cap removes most of it without affecting the ordinary case of sending someone a document. |
| Rate limits per address and per network | Automation is the difference between a nuisance and a distribution channel. |
| A challenge before a link is created | Not to identify you. To make creating thousands of links cost something. |
Reporting something
Every recipient page carries a report link, and you do not need an account, a name or an email address to use it. Give us the share identifier — the long code in the link, before the # — and choose a category. The identifier alone is enough for us to delete the file.
Reports of child sexual abuse material and of malware take the file down immediately, before a person reviews it. The link would have expired within a day anyway, so a mistaken removal costs someone a re-share; the opposite mistake costs a great deal more.
Other categories are reviewed by a person before anything is removed. We are not willing to build a button that lets anyone destroy any link by naming it.
What we do with reports
We record the identifier, the category, and anything you tell us, so that a person can act on it and so we can count them. We do not — and cannot — record what the file was.
Where we are legally obliged to report something to an authority, we will. We cannot provide them with the contents of a file, for the same reason we cannot provide it to ourselves.
If you break these rules
We delete the link. There is no account to suspend, because there are no accounts. Repeated abuse from a network may lead to that network being blocked from creating links, which is a blunt instrument and is why it is a last step.