Privacy Policy
Effective date: March 26, 2026 · Last updated: July 20, 2026
At VeloSend, privacy is a core design principle — not an afterthought. This policy explains what data we collect, why we collect it, and how we protect it.
The short version
- · Your files never touch our servers. Ever.
- · We store no file metadata — no names, sizes, or types on our side.
- · We do not sell your data to anyone, for any reason.
- · Our signaling server only holds temporary room IDs in memory — nothing is written to disk.
- · Anonymous session tokens are stored locally in your browser only.
1. Who We Are
VeloSend is operated by HRS Tech. References to "we", "us", or "our" in this policy refer to HRS Tech as the data controller for the VeloSend service accessible at velosend.net.
Contact us with privacy-related requests at: privacy@velosend.net
2. Who This Policy Applies To
This Privacy Policy applies to everyone who uses VeloSend, whether or not you create an account. Free-tier users who transfer files without signing in are still required to comply with this Privacy Policy and our Terms of Service.
By using VeloSend anonymously — for example, to send or receive a file without logging in — you automatically accept this Privacy Policy and the Terms of Service, in the same way a registered account holder does by checking the acceptance box at sign-up. If you do not agree to this Privacy Policy, do not use VeloSend, even without an account.
3. What VeloSend Does — and Doesn't Do
VeloSend uses WebRTC to establish direct, encrypted, browser-to-browser connections. When you send a file:
- File data is encrypted inside your browser using DTLS (WebRTC's mandatory encryption layer).
- The encrypted stream travels directly from your device to the recipient's device.
- Our signaling server's only role is to help the two browsers find each other. It never sees your file data.
- Once the WebRTC connection is established, our servers are not in the path of the transfer.
In rare cases where a direct peer-to-peer connection cannot be established (e.g., certain firewalls), TURN relay servers may be used. Even then, TURN relay traffic is encrypted — the relay server cannot read the contents of your files.
4. Data We Collect
We aim to collect as little data as possible. Here is a precise breakdown:
| Data | Purpose | Stored Where | Retention |
|---|---|---|---|
| Temporary room ID | Match sender & receiver | Server RAM only | Deleted at session end |
| ICE candidates (IPs) | WebRTC connection setup | Server RAM only | Deleted at session end |
| Anonymous session token | Track free TURN usage | Your browser (localStorage) | You can clear anytime |
| TURN relay byte count | Enforce free-tier cap (500 MB/mo) | Your browser (IndexedDB) | Cleared each month |
| Account email (Pro) | Authentication & billing | Encrypted database | Until account deletion |
| Transfer-history metadata (signed-in users) | Profile stats, history, and device sessions | Encrypted database | Until account deletion |
| Subscription status | Feature access control | Encrypted database | Until account deletion |
| Creem customer ID (Pro/Family) | Link your account to your Creem subscription for billing management | Encrypted database | Until account deletion |
We do not collect file contents, file types, IP addresses for logging purposes, behavioral advertising data, or analytics tracking. For signed-in accounts, we do store limited transfer-history metadata such as file names, counts, sizes, connection type, and timestamps so the profile page can show account history across devices.
5. Cookies and Local Storage
VeloSend does not use advertising cookies or third-party tracking cookies of any kind.
We use your browser's localStorage and IndexedDB to store:
- Your anonymous session token (used to track TURN quota — no personal information is used to generate this).
- Your UI theme preference (dark / light).
- Transfer resume state (in case your connection drops mid-transfer — cleared automatically on completion).
The local storage items above remain on your device. Separate account metadata, including transfer-history summaries for signed-in users, is stored on our servers and can be removed by deleting your account.
6. Third-Party Services
We use a minimal set of third-party services to operate VeloSend:
- Cloudflare (TURN relay):We use Cloudflare's TURN service as a fallback relay. Cloudflare may process IP addresses as part of routing traffic. See Cloudflare's privacy policy for details.
- Railway (Hosting):Our signaling server is hosted on Railway. Railway may collect server-level logs (e.g., connection timestamps). We do not access per-request logs.
- Creem (Payments & Billing, Pro/Family subscriptions):Creem (operated by Armitage Labs OÜ) acts as the merchant of record for all paid subscriptions and independently collects and processes billing information — including your name, email, payment details, and billing address — to complete your purchase, calculate tax, and provide customer support for billing issues. Creem acts as its own data controller for this information; see Creem's Privacy Policy for details. We never receive or store your card details ourselves — only your subscription status and Creem-assigned customer ID are shared back to us to manage your account access.
- Google Fonts:We load the Inter and JetBrains Mono fonts from Google Fonts. This means your browser makes a request to Google's servers with your IP address. You can block this in your browser if desired.
We do not use Google Analytics, Meta Pixel, or any behavioural advertising network.
7. Data Security
All WebRTC transfers are encrypted using DTLS-SRTP, providing end-to-end encryption between browsers. Our signaling server communicates over HTTPS/WSS. Paid-plan account data is stored in encrypted databases with access controls.
We follow security best practices and conduct regular reviews of our infrastructure. While no system is perfectly secure, VeloSend is designed so that even a complete server breach would not expose file contents because files are never stored on our servers. Signed-in account metadata, including transfer-history summaries and active sessions, is protected with access controls and database security measures.
8. Children's Privacy
VeloSend is not directed at children under 13. We do not knowingly collect any personal information from children under 13. If you believe a child under 13 has provided personal information to us, please contact us at privacy@velosend.net and we will remove it promptly.
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request that we correct inaccurate personal data.
- Deletion: Request that we delete your personal data.
- Portability: Request your data in a machine-readable format.
- Objection: Object to specific types of processing.
- Withdrawal of Consent: Withdraw any consent you have previously given.
To exercise any of these rights, contact us at privacy@velosend.net. We will respond within 30 days. For free-tier users with no account, most of your data exists only in your own browser — you can delete it directly by clearing your browser's site data.
10. Data Retention
Session data (room IDs, ICE candidates) is held in server memory only and deleted immediately when a room expires or is closed. We do not write session data to disk or any persistent storage.
Account data for Pro subscribers is retained until you delete your account. After deletion, we purge all associated personal data within 30 days.
11. International Transfers
Our infrastructure may be located in various regions. If you access VeloSend from outside the country where our servers are located, your data (including temporary signaling data) may be transferred internationally. By using VeloSend, you consent to such transfers.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Material changes will be communicated to Pro subscribers via email. Your continued use of VeloSend after changes constitutes your acceptance of the updated policy.
13. Contact
For any privacy-related questions, requests, or concerns:
privacy@velosend.net