Legal

Privacy Policy

Your data is automatically deleted after download or 10 minutes

1. Files You Upload

Temporary and cloud storage

Realtime Sender is a free temporary file transfer service. (Cloud Storage is an internal, administrator-only feature and is not part of the public service.)

Temporary Transfers:

  • Automatically deleted after one successful download, or
  • Automatically deleted after 10 minutes if not downloaded

Cloud Storage (administrator use):

  • Files stored until you manually delete them
  • Optional expiration dates you can set per file
  • Password protection available for sensitive files
  • Download limits can be configured per file

We do not keep backups of temporary files. Cloud Storage files persist until you delete them or they expire based on settings you control.

2. Technical Information We Collect

Security and abuse prevention

To keep the service secure and prevent abuse, we may automatically collect limited technical data, including:

  • IP address
  • Browser and device type (User-Agent)
  • Date and time of access
  • Pages or routes accessed

This information is stored in temporary server logs and used only for:

  • Security monitoring
  • Abuse prevention
  • Service reliability

Logs are automatically deleted after a limited retention period (typically within 14 days).

3. GDPR Compliance

European data protection

EU/EEA/UK Users: Realtime Sender welcomes users from the European Union (EU), European Economic Area (EEA), and the United Kingdom (UK). We are committed to complying with the General Data Protection Regulation (GDPR).

Your Rights Under GDPR:

  • Right to Access: You can request a copy of the personal data we hold about you
  • Right to Rectification: You can request correction of inaccurate data
  • Right to Erasure: You can request deletion of your personal data (account deletion)
  • Right to Restrict Processing: You can request limitation on how we use your data
  • Right to Data Portability: You can receive your data in a structured format
  • Right to Object: You can object to processing based on legitimate interests or direct marketing
  • Right to Withdraw Consent: You can withdraw cookie consent at any time

To exercise these rights, contact us at support@realtimesender.com. We will respond within 30 days.

4. Cookies and Advertising

Cookies and third-party ads

We may use cookies and similar technologies to:

  • Operate and improve the website
  • Understand usage patterns
  • Serve advertisements through our advertising partner Adsterra

Our advertising partners may use cookies to show ads based on your visits to this or other websites. You can manage personalized advertising through your browser settings and the consent options on this site.

5. Data Security

Technical and organizational measures

Encryption at Rest: We protect your personal data using industry-standard encryption:

  • AES-256-GCM encryption for all personally identifiable information (email addresses, names, IP addresses) stored in our database
  • Unique encryption keys stored separately from the database (environment variables)
  • Authentication tags ensure encrypted data hasn't been tampered with

Password Security:

  • User account passwords are hashed using bcryptjs (computationally resistant to brute-force attacks)
  • Cloud Storage optional passwords use SHA-256 hashing (one-way, cannot be reversed)
  • Passwords are never stored in plain text

Encryption in Transit:

  • TLS 1.3 (Transport Layer Security) on all connections - the latest and most secure protocol version
  • HTTPS-only access with no unencrypted endpoints
  • Strong cipher suites and certificate pinning

Access Controls and Monitoring:

  • IP-based rate limiting to prevent automated attacks
  • DDoS protection and abuse detection systems
  • Access logging with 14-day retention for security monitoring
  • Firewall protection and intrusion detection

Data Minimization:

  • Temporary files automatically deleted after download or 10 minutes
  • No backups of temporary file data
  • Server logs purged after 14 days
  • Minimal personal data collection (email only for accounts, no real names/addresses required)

Cryptographic Security:

  • Share codes generated using cryptographically secure random number generators (crypto.randomBytes)
  • Session tokens signed with HMAC-SHA256
  • Secure lookup hashes using HMAC-SHA256 with salt for database searches
  • Timing-safe comparison functions to prevent timing attacks

Note: While we implement these comprehensive security measures, no internet service can guarantee absolute security. We continuously monitor and improve our security posture.

6. Legal Basis for Processing

How we process your data

We process personal data based on the following legal grounds under GDPR:

  • Consent: For cookies and advertising (you can withdraw consent anytime)
  • Contractual Necessity: For providing the file transfer service you request
  • Legitimate Interests: For security, abuse prevention, and service improvement
  • Legal Obligations: For tax/accounting purposes if you make a purchase

Data Retention: Temporary transfer logs are deleted after 14 days. Account data is retained until you delete your account. Files are deleted according to the retention policies outlined in Section 1.

7. International Data Transfers

Cross-border data protection

Data Storage Locations: Your data may be stored and processed on servers located outside the European Union (EU) and European Economic Area (EEA), including in the United States and other countries where our hosting providers and third-party services operate.

Safeguards for International Transfers: When we transfer personal data outside the EU/EEA, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs): We use EU Commission-approved Standard Contractual Clauses with our service providers
  • Adequacy Decisions: We only transfer to countries recognized by the EU as providing adequate data protection, or with appropriate safeguards
  • Technical Measures: All data transfers use TLS 1.3 encryption to protect data in transit
  • Data Minimization: We limit the personal data transferred internationally to the minimum necessary

Your Rights Remain Protected: Regardless of where your data is processed, your GDPR rights (access, deletion, portability, etc.) continue to apply. Contact us at support@realtimesender.com to exercise these rights.

8. Third-Party Services

Providers we may use

We may use third-party providers for:

  • Cloud storage
  • Hosting and infrastructure
  • Advertising services (Adsterra)
  • Advertising partners (to keep the service free)
  • Email delivery (Brevo)

These providers may process limited technical data as necessary to provide their services. All third-party providers are contractually bound to protect your data and comply with applicable data protection laws, including GDPR where applicable.

9. Children's Privacy

Not for children under 13

Realtime Sender is not intended for children under the age of 13. We do not knowingly collect personal information from children.

10. Data Breach Notification

Your right to know

Our Commitment: In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify affected users without undue delay and no later than 72 hours after becoming aware of the breach, as required by GDPR Article 33.

What Constitutes a Breach: A data breach is a security incident that leads to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. This includes:

  • Unauthorized access to our database containing encrypted user information
  • Compromise of encryption keys that protect personal data
  • System intrusion resulting in potential exposure of user data

Notification Contents: If a breach occurs, our notification will include:

  • The nature of the breach and categories of data potentially affected
  • The likely consequences of the breach
  • Measures we have taken or plan to take to address the breach
  • Recommendations for steps you can take to protect yourself
  • Contact details for further information

How We Notify: We will use the email address associated with your account to send breach notifications. If you don't have an account, and the breach affects temporary transfer data, we will post a notice on our website homepage.

Reporting to Authorities: We will also report significant breaches to the relevant supervisory authority (Data Protection Authority) within 72 hours when required by law.

Risk Mitigation: Due to our security measures (AES-256-GCM encryption, bcryptjs password hashing, TLS 1.3), even in a breach scenario, your data remains protected. Encrypted data cannot be read without the encryption keys, which are stored separately from the database.

11. Sub-processors (Third-Party Processors)

Who processes data on our behalf

Data Processing Agreements: We have formal Data Processing Agreements (DPAs) in place with all third-party service providers who process personal data on our behalf. These agreements ensure GDPR compliance and appropriate security measures.

Our Sub-processors:

Provider Purpose Location Data Processed
Cloud Hosting Provider Server infrastructure US (with SCCs) Encrypted user data, files
Brevo (Sendinblue) Email delivery EU Email addresses (for transactional emails)
Razorpay Payment processing India (with SCCs) Payment information (we don't store card data)
Adsterra Advertising May be outside EU (with SCCs) Cookie data, IP addresses (with consent only)
MySQL Database Data storage Same as hosting All encrypted user data

DPA Availability: Copies of our Data Processing Agreements are available upon request. Contact support@realtimesender.com with subject "DPA Request".

Changes to Sub-processors: If we add new sub-processors, we will update this list and notify users via email if they have an account.

12. Data Retention Schedule

How long we keep your data

GDPR Principle: We retain personal data only as long as necessary for the purposes collected, or as required by law.

Data Type Retention Period Deletion Method
Temporary file transfer logs 14 days Automatic database deletion
Temporary files Until downloaded or 10 minutes Automatic secure deletion
User account data Until account deletion Permanent deletion on request
Cloud Storage files Until user deletes or account closes User-controlled deletion
Server access logs 14 days Automatic rotation/deletion
Payment records 7 years (tax compliance) Archived after account deletion
Cookie consent records 1 year Browser localStorage deletion

Early Deletion: You can request earlier deletion of your data by exercising your Right to Erasure (see Section 3). Contact support@realtimesender.com.

13. Record of Processing Activities

GDPR Article 30 compliance

Legal Requirement: Under GDPR Article 30, we maintain a record of all processing activities involving personal data. This section provides transparency about our processing activities.

Processing Activity 1: User Account Management

  • Purpose: Creating and managing user accounts
  • Legal Basis: Contractual necessity (Article 6(1)(b))
  • Data Subjects: Registered users
  • Data Categories: Email (encrypted), name (encrypted), password hash
  • Recipients: Internal only
  • Retention: Until account deletion

Processing Activity 2: Temporary File Transfer

  • Purpose: Providing temporary file transfer service
  • Legal Basis: Contractual necessity (Article 6(1)(b)) and Legitimate interests (Article 6(1)(f))
  • Data Subjects: All users (registered and anonymous)
  • Data Categories: IP address (temporary logs), file metadata (size, type), share code
  • Recipients: Internal only
  • Retention: 14 days for logs, files deleted immediately after download/10 min

Processing Activity 3: Cloud Storage Service

  • Purpose: Permanent file storage for administrators (internal feature)
  • Legal Basis: Contractual necessity (Article 6(1)(b))
  • Data Subjects: Administrators
  • Data Categories: Files, share codes, optional passwords (hashed), download history
  • Recipients: Internal only
  • Retention: Until user deletion or account closure

Processing Activity 4: Marketing and Analytics

  • Purpose: Website analytics and personalized advertising
  • Legal Basis: Consent (Article 6(1)(a)) - optional, user-controlled
  • Data Subjects: Users who consent to marketing cookies
  • Data Categories: Cookie data, IP address (anonymized), browsing behavior
  • Recipients: Adsterra (advertising), Google Ireland Ltd / Google LLC as processor for Google Analytics 4 (usage analytics), internal analytics
  • Retention: Cookies per cookie settings (up to 2 years); Google Analytics 4 event data retained for 14 months

Analytics measurement for visitors in the EU, EEA, and UK runs only on consent granted through the cookie banner. Until that consent is given, the Google Analytics 4 tag is not loaded and no analytics data is sent to Google.

Processing Activity 5: Security and Abuse Prevention

  • Purpose: Protecting service integrity, preventing fraud
  • Legal Basis: Legitimate interests (Article 6(1)(f))
  • Data Subjects: All users
  • Data Categories: IP address, User-Agent, access timestamps, behavioral patterns
  • Recipients: Internal only
  • Retention: 14 days

14. Changes to This Policy

Updates

We may update this Privacy Policy from time to time. Continued use of the service after changes means you accept the updated policy.

15. Withdrawing Consent (GDPR Article 7(3))

Your right to change your mind

Right to Withdraw: You have the right to withdraw your consent to data processing at any time. Withdrawing consent is as easy as giving it, and doing so will not affect the lawfulness of processing based on consent before its withdrawal.

How to Withdraw Consent:

  • Cookie Consent: Click the "Manage Cookies" link in the footer of any page, or use the cookie banner when it appears. You can disable Analytics and Marketing cookies at any time.
  • Marketing Emails: If you receive marketing emails (only sent to registered users who opted in), click the "Unsubscribe" link at the bottom of any email.
  • Account Data Processing: To stop processing of your account data entirely, you can delete your account via the Account Settings page or by contacting us.
  • Ad Personalization: Disable marketing cookies via the cookie settings to stop personalized advertising.

Consequences of Withdrawal:

  • Disabling Analytics cookies: No impact on service functionality. We simply won't track your usage for improvement purposes.
  • Disabling Marketing cookies: No impact on service functionality. You'll see generic ads instead of personalized ones.
  • Deleting your account: You will lose access to your account and transfer history. All your data will be permanently deleted.

Exercising Your Right: To withdraw consent, simply adjust your cookie preferences using the "Manage Cookies" link in the footer, or contact us at support@realtimesender.com with subject "Withdraw Consent". We will process your request within 24 hours.

16. Data Protection Contact

Your point of contact for GDPR matters

Data Controller: Realtime Sender is the Data Controller responsible for your personal data. We are committed to protecting your privacy and ensuring GDPR compliance.

Data Protection Contact:

For all data protection inquiries, GDPR rights requests, breach notifications, and privacy-related questions, please contact:

Jahangir Khan
Data Protection Contact & Founder
📧 support@realtimesender.com
🌐 https://realtimesender.com

Response Times:

  • General inquiries: Within 48 hours
  • GDPR rights requests (access, delete, portability): Within 30 days (as required by law)
  • Breach notifications: Immediate acknowledgment, full response within 72 hours
  • Urgent privacy concerns: Within 24 hours

When Contacting Us: Please include "Data Protection" in your email subject line for faster routing. Include as much detail as possible about your request to help us respond effectively.

Supervisory Authority: If you are not satisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority. Contact details for EU Data Protection Authorities can be found at: https://edpb.europa.eu/about-edpb/board/members_en

17. Contact Us

General Questions

For general questions about this Privacy Policy, technical support, or service inquiries, contact us at:

📧 support@realtimesender.com

For data protection inquiries, GDPR rights requests, or breach notifications, please see Section 16 above for direct contact information.