RapidLink

Privacy Policy

Last updated: September 14, 2026

RapidLink is an ephemeral tool for sending text and files between devices. It is built to collect as little as possible and to forget quickly. This policy explains exactly what we handle, why, and for how long.

What we collect

We deliberately keep data collection minimal. Specifically:

  • Session content — the text and files you drop into a session. Both are encrypted with AES-256-GCM in your browser before they are uploaded, so we store ciphertext and nothing else, and it exists only for the lifetime of the session.
  • A session name and settings — the memorable name you choose, its expiry time, and whether it is public or password-protected. File sizes are visible to us; filenames are not, as they are encrypted with the content.
  • Minimal technical data — request logs and IP address, used only for rate limiting and abuse prevention, never for profiling.
  • Pseudonymous session analytics — a session-scoped hash records joins, active duration, exit time, device category, browser, operating system, country, language, timezone, screen and viewport size, colour scheme, connection category, app display mode, referral hostname, and actions such as download, share, link copy, QR opening and session close. We never attach content, filenames, IP addresses or raw user-agent strings to this analytics record, and its identifier cannot be correlated between different sessions.

We do not require accounts. We do not ask for your name, email, or any personal detail to use the transfer tool.

How long we keep it

Sessions are ephemeral by design. Content expires automatically after the timer you choose (a few minutes by default), or the moment you close the session manually.

After expiry, content is purged. Session metadata and its pseudonymous visit records are retained for up to 30 days for aggregate product analytics and abuse investigation, then permanently deleted with the session.

Cookies

We use a functional cookie to remember your language preference. A random identifier is also kept in local storage to count the same browser only once inside each session; the server converts it into a different one-way hash for every session. We use no advertising cookies and perform no cross-site tracking.

To order the language selector, we keep monthly totals by browser and interface language for up to 100 days. These counters contain no session IDs, filenames or content. Session storage prevents repeated counting within the same tab and month. These language samples respect the browser's Do Not Track preference.

Advertising

RapidLink may display ads to keep the service free. We use privacy-first advertising that does not track you:

  • Ads are contextual, not behavioural — they are chosen by the page content, not by a profile of you.
  • Our advertising partner (EthicalAds) does not use cookies, does not build a profile, and does not sell personal data.
  • Advertisers who book placements directly through our tool pay via Stripe; their business contact details are processed only to fulfil and invoice the booking.

Third-party processors

We rely on a small set of trusted providers to run the service:

  • Neon — managed PostgreSQL database hosting.
  • Vercel — application hosting, file storage (Vercel Blob), and privacy-friendly aggregate analytics.
  • Stripe — payment processing for advertisers only.
  • EthicalAds — cookieless, contextual ad serving.

Each processes data only as needed to provide its part of the service.

Data security

Session content is encrypted with AES-256-GCM in your browser, before it is sent. Our storage and database only ever hold ciphertext, and traffic is served over HTTPS on top of that. What differs is who holds the key.

If you set a password on a session, the key is derived from that password on your device using PBKDF2-SHA256 and is never transmitted. We receive only a separate value derived from the same password, which proves you know it but cannot decrypt anything. Such a session is end-to-end encrypted: we cannot read it, and neither can anyone who compels or breaches us. If you lose the password, the content is unrecoverable — including by us.

If you do not set a password, we hold the key, sealed at rest with a separate master key. This is what allows anyone who knows the session name to open the drop without extra secrets, and it does mean we are technically able to decrypt those sessions. We do not, but you should choose a password for anything you would not want us to be able to read. The interface states which of the two applies before you create a session, and again once it exists.

Access to internal systems is restricted, and the ephemeral design means there is very little data to protect at any given moment.

Your rights

Under the GDPR and similar laws you may request access to, correction of, or deletion of any personal data we hold about you. Because sessions are anonymous and short-lived, in most cases the fastest route is simply to close or let your session expire.

For anything else, contact us and we will respond within the timeframes the law requires.

Children

RapidLink is not directed at children under 13, and we do not knowingly collect data from them.

Changes to this policy

We may update this policy as the service evolves. Material changes will be reflected in the “last updated” date above.

Contact

Questions about privacy? Reach us at team@lyfeman.com.