Crate Link is built with no user accounts and no login. This policy explains the limited data the Service does collect, why, and for how long.
1. What we collect
For every file uploaded, we store:
- the file itself, in private storage, until it expires or is deleted;
- its filename, size, and MIME type;
- a random share token (its cryptographic hash, not the raw token — see below);
- expiration time, download limit, and current download count;
- the uploading device's IP address and the upload timestamp;
- whether the upload used the admin override (§10 of the Terms).
We do not collect names, email addresses, or any other account information — there is nothing to collect, since there are no accounts.
2. Why we collect the uploader's IP address
The IP address recorded at upload time is used only for:
- automated abuse prevention — detecting and temporarily blocking IP addresses that repeatedly try to exceed upload limits or brute-force the admin code;
- responding to valid legal requests and preserving evidence where required by law (§9 of the Terms) — for example, if a court or authorized government body lawfully requests information about who uploaded a specific reported file.
It is never shown to anyone downloading the file, never included in any share link or QR code, and never used for advertising, analytics, or profiling.
3. Your share token is hashed, not stored raw
The link you receive after uploading contains a 256-bit random token. We store only its cryptographic hash, not the token itself — so even someone with direct access to the database could not reconstruct working download links from it. Anyone who has the token (because you shared it with them) can use it to view file info and download the file; that's how the Service is designed to work.
4. Local browser storage (not cookies)
With your consent (shown as a banner on first visit), the Service uses your browser's own storage — not a cookie sent to our server — for two things:
- Session storage: your most recent upload result(s), so switching tabs or an accidental refresh doesn't lose a link/QR code you haven't copied yet. Cleared automatically when you close the tab.
- Local storage: up to your last 20 upload results ("Recent links"), so you can find an old link again without keeping a tab open. Stays until you clear it or clear your browser's site data.
Nothing in either is ever transmitted to us — it stays in your browser. Declining consent means neither is written.
5. How long we keep things
File content is deleted from storage once its link expires, reaches its download limit, or is kept permanently reversed — enforced immediately at the link level (an expired link stops working the instant it expires, regardless of when the underlying file is physically removed), with physical removal following shortly after via an automated cleanup process.
The associated record (filename, size, timestamps, uploader IP, and download count — not the file content) is retained indefinitely after the file itself is deleted, for abuse-prevention, security, and legal-compliance purposes described in §2. This matches what the Service actually does today; if that changes, this policy will be updated to match, consistent with our commitment that our stated practices reflect our actual ones.
6. Who can access this data
Only the Service's operator, via credentials that never reach the browser or any third party. The database enforces default-deny access at the database level for every role except the server itself. We do not sell, rent, or share this data with third parties, except where required to respond to a valid legal request (§9 of the Terms).
7. Children's privacy
The Service is not directed at children and is not designed to knowingly collect personal information from them.
8. Changes to this policy
We may update this policy from time to time; the "Last updated" date above reflects the most recent change.
9. Contact
For privacy questions, contact: 1.connectwithhemapriyan@gmail.com.