Overview
Privacy
What this service stores, how long it keeps it, and who else can see it.
Version 2026-09-29.
Files you upload
Files are stored in Cloudflare R2 and served from a URL that carries 128 bits of randomness. There is no endpoint that lists files, so a file is reachable only by someone who has its URL.
- Uploaded without an account: deleted three days later.
- Uploaded with an account: deleted 30 days later, or sooner if you delete it or asked for a shorter lifetime.
Deletion is not a promise that every copy is gone. A URL that was shared while the file was live may have been fetched and kept by whoever received it, and a copy taken by a cache along the way is not ours to recall. Treat anything you upload as public.
What is recorded about an upload
Nothing is recorded about an anonymous upload beyond the file itself.
For an upload made with an account, one row is stored so that the file can be shown in your dashboard: its identifier, the file name you sent, its size, the moment it was uploaded, and which account it belongs to. That row is deleted when the file is.
A page published on Pro is recorded the same way: its address, the file name you sent, its size, when it was published and last changed, and which account it belongs to. Nothing is recorded about the people who open a page beyond what any request leaves in the logs.
Accounts
Signing in is handled by Clerk, which holds your email address and, if you signed in with Google or GitHub, whatever that provider told it: usually a name and a profile picture. This service stores none of that; it stores the account identifier Clerk issues, and attaches it to your uploads and your API keys.
API keys are stored as a SHA-256 digest and never as the key itself. A key is shown once, when it is created. A copy of our database would leak no keys.
Paying
Payments are handled by Stripe, which holds the card details. This service never sees a card number and stores none of one.
What we send Stripe is your email address, so that its payment page arrives already filled in, and an account identifier so that a payment can be matched to the account that made it. What we keep back is a row saying which account is paying, what Stripe last said about the subscription, and when it renews. No invoices, no amounts, no card.
Logs
Cloudflare records requests to this service as part of running it, which includes IP addresses. Those logs are short-lived operational records and are not combined with account data or used to build a profile of anybody.
What we do not do
- No analytics, no tracking pixels, no advertising.
- No cookies except two, both about being signed in: the one Clerk sets to keep you there, and one of ours holding a single 1 so the front page can offer you your dashboard rather than a sign-in link. Ours carries no name, no address and no token, and deleting it costs you nothing.
- No selling or sharing of data with anybody, for any purpose.
- No reading of file contents.
Scanning
Nothing reads the contents of a file you upload. There is no proactive scanning here, of any kind, and nothing is inspected before somebody asks us to look at it.
Child sexual abuse material is removed and reported to the National Center for Missing and Exploited Children as soon as we know of it. Anything else unlawful is removed on the same footing. Reports go to contact@godrop.sh, and they are read.
Removing your data
Delete a file from the dashboard, or with the API, and it stops being served at once.
Deleting your account through Manage account removes everything attached to it: the files you uploaded, the pages you published, the rows that listed them, and every API key you had made. Keys stop working at the same moment, so one that was copied somewhere and forgotten cannot outlive the account. Clerk tells this service the moment you delete the account, and the removal happens then rather than at some later sweep.
Who holds this
Ddosify Inc., 1401 Pennsylvania Ave. Unit 105, Wilmington, Delaware 19806, United States, decides what is collected here and why.
Asking about any of this
contact@godrop.sh reaches us. Questions about what is stored, requests to remove something, and reports of a file that should not be here all go to the same place. Reporting a file has a page of its own: Reporting a file.