Privacy Policy
Our zero-cloud storage commitment and privacy-first architectural standards.
Overview and Privacy-First Architecture
At iFileSender (accessible from ifilesender.com), your privacy is our highest priority. We have specifically engineered our service so that your files are never uploaded to, inspected by, or stored on our servers.
This Privacy Policy explains what temporary technical information is handled when you use iFileSender, how our signaling architecture operates, and what happens when you contact us.
How File Transfers Work (Zero Server Storage)
iFileSender uses standard WebRTC DataChannels to stream binary file data directly between your paired devices:
- Peer-to-Peer Transmission: The contents of your files travel directly across your local network or internet connection between the two paired devices.
- Bidirectional Sessions: Once two devices are paired, either device can send files to the other in both directions without reconnecting.
- Temporary In-Memory Session History: A list of files transferred during your active session is displayed only in your active browser window for your convenience. This history is stored strictly in temporary browser memory and is never stored on our servers. When you close the page or disconnect, it is permanently erased.
- No Cloud Storage: We do not operate any cloud file storage, disk caches, or intermediate databases for your transferred files.
- No File Logging: We do not log or permanently record individual filenames or file contents on our servers.
Temporary Signaling and Connection Metadata
To establish a direct connection between two web browsers, our servers act temporarily as a "matchmaker" (signaling service):
- Session IDs: When a sender initiates a transfer, a temporary random session identifier is generated.
- SDP and ICE Candidates: The two browsers briefly exchange encrypted Session Description Protocol (SDP) messages and network connection candidates (IP addresses and ports) through our signaling room to discover the most direct network path.
- Session Destruction: This temporary signaling metadata is kept only in volatile memory during the connection handshake and is automatically erased when the transfer completes or after 15 minutes of inactivity.
STUN and TURN Relay Servers
In order to establish peer-to-peer connections across routers and firewalls, browsers use STUN (Session Traversal Utilities for NAT) servers to discover public IP addresses. In rare cases where firewalls block direct connections (such as strict corporate or university networks), encrypted data packets may pass through a TURN relay server. When a TURN relay is used, the traffic remains end-to-end encrypted (DTLS/SRTP) and is not readable or stored by the relay server.
Information Collected via Contact Form
If you voluntarily submit a message through our Contact Us form, we collect:
- Your name and email address
- The subject and message content you provide
- A cryptographic hash of your IP address strictly for anti-spam rate limiting
This information is used solely to respond to your support request, feedback, or inquiry, and is never sold or shared with third parties for marketing purposes.
Aggregate Usage Statistics
To monitor service health and showcase verified social proof, iFileSender maintains anonymous aggregate counters (e.g., total completed transfer sessions, total files transferred, total bytes transferred, and broad route categories such as Mac to Android). These statistics are purely numerical aggregates and contain zero personal identifiers, IP addresses, or filenames.
Cookies and Local Storage
iFileSender uses standard browser localStorage solely to remember your chosen theme preference (Dark or Light mode). We do not use third-party tracking cookies for normal file transfers.
Contact Information
If you have questions regarding this Privacy Policy or our security architecture, please reach out via our Contact Page.