Privacy policy
Last updated 14 September 2026
This page describes what we keep when you use Ditrib. It is written to be read, not to be defensible in court, so if anything here is unclear please ask.
What we store
- The file you upload, until it expires or you delete it.
- Its name, size and SHA-256 digest.
- For accounts: your email address, a password hash, and billing details held by our payment provider.
- Request logs containing a truncated IP address, timestamp, endpoint and response code.
What we do not store
- The email address of anyone you send a link to. We never contact recipients.
- Copies of expired transfers. Deletion is deletion, including from backups within 30 days.
- Third-party analytics or advertising identifiers. There are no trackers on this site.
Retention
Files follow the retention window of the plan the transfer was created on. Request logs are kept for 14 days and then dropped. Account records are removed within 30 days of you closing the account, except invoices, which tax law requires us to hold for seven years.
Who else sees your data
Our hosting providers, who store the encrypted objects, and our payment provider, who handles card details so that we never receive them. We do not sell data and we do not share it for advertising.
Legal requests
We respond to validly served requests from authorities with jurisdiction over us, and we will tell you unless we are legally barred from doing so. We publish the number of requests received each year on this page.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to hello@ditrib.online and we will respond within 30 days.
Changes
If we change this policy in a way that matters, account holders get an email at least 14 days before it takes effect.