Terms of use and privacy
In one sentence: TempDrop moves a file from your phone to your computer and forgets it existed.
What the service does
You open a Session on your computer, scan the QR Code on your phone, and send one file. The computer downloads it. The Session lasts 15 minutes and accepts one file up to 95 MB.
End-to-end encryption
The file is encrypted on your phone (256-bit AES-GCM) before it leaves. The E2E key travels inside the QR Code, in the URL fragment — the part browsers do not send to the server. The file name and type are encrypted too.
In practice: the server stores an encrypted envelope it cannot read, and whoever runs TempDrop cannot open what you transferred. If you lose the computer tab, the file becomes unrecoverable for everyone, including us.
Retention
- The file is deleted as soon as the download finishes.
- If nobody downloads it, it is deleted when the Session expires (15 minutes).
- There is no history, folder, trash, or backup. There is no screen to reopen an old transfer — not for you, not for us.
What we record
Per Invite we keep: a label, creation date, how many bytes you transferred in the month, and how many Sessions you opened in the day. That is what we need to enforce quota and size the cost. We do not record file names (they arrive encrypted), content, or recipients.
We also record technical funnel events (schema v3) to learn whether the product is understood and used: Invite redemption completed, upload completed, bytes actually transferred, and attempts after hitting the free quota. Each event carries the interface locale (pt-BR or en) and a two-letter country that Cloudflare derives from the request's network address at the edge. TempDrop receives only the country code and does not persist the IP address. Country is aggregate per event; by itself it does not identify you. Public events also carry only a closed campaign bucket (direct, the Google Search experiment, or another allowed source); raw UTM values, gclid, and the full URL are discarded.
The browser-emitted events are landing_view, pricing_viewed, signup_started, upload_started, access_requested, upgrade_interest, language_selected, human_engaged, checkout_opened, and checkout_completed_client. access_requested measures the click that opens an email client, not whether an email was sent. The two checkout events measure interaction and are not proof of payment. human_engaged is a probable human engagement signal: at least one trusted interaction (pointerdown or keydown) and 10 seconds accumulated while the tab is visible; hidden time does not count; one emission per browser session.
All browser-emitted events use the literal anonymous index, even when an Invite cookie already exists. They are client-declared, forgeable, and measure intent or trend — they are not proof of identity, not financial proof, and do not replace server-measured events. The IP address may be used transiently at the edge to limit abuse, but it is not included in the event. Server-measured events use the Invite hash as a stable pseudonymous identifier, so events from the same Invite can be counted together and linked to that Invite's operational record.
These events live in Workers Analytics Engine for up to three months and cannot be deleted line by line. They do not include IP address, visited URL, user-agent, referrer, access code or token, file name or type, content, email, or recipient. Pro billing PII never enters this dataset.
TempDrop Pro and billing (closed beta)
The free plan still asks for no name, email, phone number, tax ID, or address. TempDrop Pro is technically prepared in sandbox but remains unavailable while billing feature flags are off. When an explicit beta is enabled, the Brazilian BRL offer uses Woovi/Pix Automático and the international USD offer uses Paddle; enabling one does not enable the other.
For the international checkout, personal and payment details are collected directly by the Paddle-hosted checkout. Paddle acts as Merchant of Record. TempDrop does not receive or persist those form fields and never sends them to Worker logs or Analytics Engine.
The billing D1 database stores only an Invite hash or HMAC pseudonymous reference, provider, currency/offer, provider customer and subscription IDs, status, paid-through date, minimal webhook event identifiers, timestamps, and closed error codes. It never stores raw webhook bodies or checkout PII.
Paddle processes and retains payer data under its legal obligations and Privacy Policy. When billing is active, invoices, payment-method changes, and cancellation are handled in Paddle's hosted Customer Portal. Cancellation stops future renewals while paid access remains until the end of the confirmed period.
Invite-only access
Access is personal and comes from an Invite. Each person who joins gets a few Invites to pass on. An Invite can be revoked at any time, without notice, if it is used to break these terms.
If you email oi@tempdrop.app to ask for an Invite, that email lands in the inbox of whoever maintains TempDrop — like any email. It does not enter any product system, does not become an account, and is not linked to the Invite you receive.
Responsibility for content
You are solely responsible for what you transfer and for having the right to transfer it. Using TempDrop for illegal content or to distribute files to third parties is prohibited — it exists to move your file between your two devices.
If you transfer personal or sensitive data about other people (for example, health documents), you are the controller of that data: end-to-end encryption is the tool, but legal basis and duty of care remain yours.
Warranties
The service is provided as is, with no availability guarantee. Do not use TempDrop as the only copy of anything — it is a cable, not a vault.
Questions or revocation requests: talk to whoever invited you, or write to oi@tempdrop.app.