Legal

Privacy Policy

Effective date: March 26, 2026  ·  Last updated: July 20, 2026

At VeloSend, privacy is a core design principle — not an afterthought. This policy explains what data we collect, why we collect it, and how we protect it.

The short version

  • · Your files never touch our servers. Ever.
  • · We store no file metadata — no names, sizes, or types on our side.
  • · We do not sell your data to anyone, for any reason.
  • · Our signaling server only holds temporary room IDs in memory — nothing is written to disk.
  • · Anonymous session tokens are stored locally in your browser only.

1. Who We Are

VeloSend is operated by HRS Tech. References to "we", "us", or "our" in this policy refer to HRS Tech as the data controller for the VeloSend service accessible at velosend.net.

Contact us with privacy-related requests at: privacy@velosend.net

2. Who This Policy Applies To

This Privacy Policy applies to everyone who uses VeloSend, whether or not you create an account. Free-tier users who transfer files without signing in are still required to comply with this Privacy Policy and our Terms of Service.

By using VeloSend anonymously — for example, to send or receive a file without logging in — you automatically accept this Privacy Policy and the Terms of Service, in the same way a registered account holder does by checking the acceptance box at sign-up. If you do not agree to this Privacy Policy, do not use VeloSend, even without an account.

3. What VeloSend Does — and Doesn't Do

VeloSend uses WebRTC to establish direct, encrypted, browser-to-browser connections. When you send a file:

  • File data is encrypted inside your browser using DTLS (WebRTC's mandatory encryption layer).
  • The encrypted stream travels directly from your device to the recipient's device.
  • Our signaling server's only role is to help the two browsers find each other. It never sees your file data.
  • Once the WebRTC connection is established, our servers are not in the path of the transfer.

In rare cases where a direct peer-to-peer connection cannot be established (e.g., certain firewalls), TURN relay servers may be used. Even then, TURN relay traffic is encrypted — the relay server cannot read the contents of your files.

4. Data We Collect

We aim to collect as little data as possible. Here is a precise breakdown:

DataPurposeStored WhereRetention
Temporary room IDMatch sender & receiverServer RAM onlyDeleted at session end
ICE candidates (IPs)WebRTC connection setupServer RAM onlyDeleted at session end
Anonymous session tokenTrack free TURN usageYour browser (localStorage)You can clear anytime
TURN relay byte countEnforce free-tier cap (500 MB/mo)Your browser (IndexedDB)Cleared each month
Account email (Pro)Authentication & billingEncrypted databaseUntil account deletion
Transfer-history metadata (signed-in users)Profile stats, history, and device sessionsEncrypted databaseUntil account deletion
Subscription statusFeature access controlEncrypted databaseUntil account deletion
Creem customer ID (Pro/Family)Link your account to your Creem subscription for billing managementEncrypted databaseUntil account deletion

We do not collect file contents, file types, IP addresses for logging purposes, behavioral advertising data, or analytics tracking. For signed-in accounts, we do store limited transfer-history metadata such as file names, counts, sizes, connection type, and timestamps so the profile page can show account history across devices.

5. Cookies and Local Storage

VeloSend does not use advertising cookies or third-party tracking cookies of any kind.

We use your browser's localStorage and IndexedDB to store:

  • Your anonymous session token (used to track TURN quota — no personal information is used to generate this).
  • Your UI theme preference (dark / light).
  • Transfer resume state (in case your connection drops mid-transfer — cleared automatically on completion).

The local storage items above remain on your device. Separate account metadata, including transfer-history summaries for signed-in users, is stored on our servers and can be removed by deleting your account.

6. Third-Party Services

We use a minimal set of third-party services to operate VeloSend:

  • Cloudflare (TURN relay):We use Cloudflare's TURN service as a fallback relay. Cloudflare may process IP addresses as part of routing traffic. See Cloudflare's privacy policy for details.
  • Railway (Hosting):Our signaling server is hosted on Railway. Railway may collect server-level logs (e.g., connection timestamps). We do not access per-request logs.
  • Creem (Payments & Billing, Pro/Family subscriptions):Creem (operated by Armitage Labs OÜ) acts as the merchant of record for all paid subscriptions and independently collects and processes billing information — including your name, email, payment details, and billing address — to complete your purchase, calculate tax, and provide customer support for billing issues. Creem acts as its own data controller for this information; see Creem's Privacy Policy for details. We never receive or store your card details ourselves — only your subscription status and Creem-assigned customer ID are shared back to us to manage your account access.
  • Google Fonts:We load the Inter and JetBrains Mono fonts from Google Fonts. This means your browser makes a request to Google's servers with your IP address. You can block this in your browser if desired.

We do not use Google Analytics, Meta Pixel, or any behavioural advertising network.

7. Data Security

All WebRTC transfers are encrypted using DTLS-SRTP, providing end-to-end encryption between browsers. Our signaling server communicates over HTTPS/WSS. Paid-plan account data is stored in encrypted databases with access controls.

We follow security best practices and conduct regular reviews of our infrastructure. While no system is perfectly secure, VeloSend is designed so that even a complete server breach would not expose file contents because files are never stored on our servers. Signed-in account metadata, including transfer-history summaries and active sessions, is protected with access controls and database security measures.

8. Children's Privacy

VeloSend is not directed at children under 13. We do not knowingly collect any personal information from children under 13. If you believe a child under 13 has provided personal information to us, please contact us at privacy@velosend.net and we will remove it promptly.

9. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request that we correct inaccurate personal data.
  • Deletion: Request that we delete your personal data.
  • Portability: Request your data in a machine-readable format.
  • Objection: Object to specific types of processing.
  • Withdrawal of Consent: Withdraw any consent you have previously given.

To exercise any of these rights, contact us at privacy@velosend.net. We will respond within 30 days. For free-tier users with no account, most of your data exists only in your own browser — you can delete it directly by clearing your browser's site data.

10. Data Retention

Session data (room IDs, ICE candidates) is held in server memory only and deleted immediately when a room expires or is closed. We do not write session data to disk or any persistent storage.

Account data for Pro subscribers is retained until you delete your account. After deletion, we purge all associated personal data within 30 days.

11. International Transfers

Our infrastructure may be located in various regions. If you access VeloSend from outside the country where our servers are located, your data (including temporary signaling data) may be transferred internationally. By using VeloSend, you consent to such transfers.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Material changes will be communicated to Pro subscribers via email. Your continued use of VeloSend after changes constitutes your acceptance of the updated policy.

13. Contact

For any privacy-related questions, requests, or concerns:

HRS Tech — VeloSend
privacy@velosend.net