Privacy
What Poftim receives
The transfer page has no account, no sign-in and no file storage, so most of what a privacy notice usually has to explain simply does not exist here. A Poftim+ account is the one exception, and it has its own section below.
This describes Poftim as operated at poftim.app. The security architecture sets out how the guarantees below are actually enforced, and what their limits are.
Never received
What does not reach a server
Files are encrypted on the sending device and decrypted on the receiving one. The keys are agreed between the two devices and are never sent to us.
- File contentsNever received
- File names, sizes and typesEncrypted
- Encryption keysNever sent
- The secret inside the QR codeNever sent
- An account, email address or phone numberNever asked for
The pairing secret travels in the fragment of the join link, which browsers do not send to servers, and the page removes it from the address bar as soon as it has been read. Because Poftim is a web application, you must still trust the code poftim.app delivers. That limitation is described in full.
Received
What the service does handle
Connecting two devices cannot be done without some information passing through infrastructure. This is that information.
- A random session identifierHeld in memory
- Connection negotiation messagesRelayed, not stored
- IP addresses of both devicesProcessed to connect them
- Relayed traffic, when no direct route existsEncrypted, not stored
Sessions live only in the memory of the signalling service. An unscanned code expires after five minutes; a connected session that goes idle expires after fifteen. Nothing about a session is written to a database, because there is no database.
Web server logs record the request method, the path, the response status and a truncated IP address — the final part of an IPv4 address and the interface portion of an IPv6 address are discarded before writing. Query strings are deliberately excluded from the log format, because session tokens travel in them.
Analytics
Two surfaces, measured differently
The transfer page and the pages describing it are not the same thing, and they are not measured the same way. The transfer page runs no third-party code whatsoever; these document pages use Google Analytics after consent.
The transfer page — first-party counts only
Poftim's transfer page holds the pairing secret, the derived session keys and your files in readable form. No outside code is permitted to execute there, and that is enforced by the Content Security Policy served with the page rather than by our choosing not to include any: script-src 'self' refuses every external origin.
It reports five counts to poftim.app itself — a code created, a code scanned, a transfer started, a transfer completed, a transfer failed — with only the device's role, whether it paired by code or by shared link, and the number of files.
- A cookie or any identifierNever set
- Anything stored on your deviceNothing
- The address of any page you openedNever sent
- Session identifiers and pairing secretsNever sent
- File names, types, sizes and contentsNever sent
- What the server keepsRunning totals only
There is no per-visit record to hold, so there is nothing here that identifies you and nothing to withdraw. The server increments counters; it does not remember that a particular visit happened.
These document pages — Google Analytics, with consent
The pages that explain the product carry no session material, no keys and no file data, so they use Google Analytics to show how people find and read them. Analytics cookies are not strictly necessary, so nothing is loaded and no cookie is set until the bar at the foot of the page is answered. Declining leaves it that way permanently.
Accepting sets two cookies, _ga and _ga_WDQ32BCK4B, which Google Analytics uses to recognise a returning browser and group its visits into sessions. Your choice itself is remembered in your browser's local storage under poftim.analytics, which is not sent anywhere. Because cookies belong to the whole domain, your browser will still attach them to requests for the transfer page — but no Google code runs there to read them, and our server ignores them.
You can change your mind at any time with the Analytics link at the foot of any document page. Withdrawing consent stops the reporting and clears both cookies. Advertising and cross-device identity features are switched off permanently. Google acts as our processor for this data; it is a company with operations outside the UK, and analytics data may be processed in those locations.
On your device
What is kept in your browser
poftim.analytics— your measurement choiceLocal storagepoftim.relayOnly— the network privacy switchSession storage- The offline shell — pages, styles and scriptsCache storage
Received files are held in the page while you save them and are not written to any of these. Clearing site data for poftim.app removes all three.
Poftim+ accounts
The one place a name is held
Everything above describes the transfer page, which never asks who you are. A Poftim+ account is the exception, and it is the only part of Poftim that holds personal data at all.
- Your email addressTo sign you in and to reach you about the subscription
- Device names you chooseSo the device list means something to you
- Device public keysTo recognise your devices. The private halves never leave them
- Subscription status and renewal dateTo know whether Poftim+ is active
- Your card detailsNever. Those go to Paddle and are never received here
- Anything about your transfersNever. There is no record to hold
The lawful basis is the contract you enter when you subscribe: this data is what makes the subscription work, and there is no part of it kept for marketing. Account records are held while the account exists and are deleted when you delete it. Sign-in links and session tokens are stored only as hashes and expire on their own.
You can download everything held about you, and delete the account entirely, from the account page. Deletion is scheduled rather than instant, and you are emailed a link that cancels it — so a deletion nobody intended can be undone. Deleted records may persist in encrypted backups until those rotate, within 30 days.
Third parties
Who else is involved
- Google Analytics — on these document pagesOnly with consent
- Formspree — delivers the security report formOnly if you submit it
- Paddle — sells and bills Poftim+Only if you subscribe
- Postmark — delivers account emailOnly if you have an account
None of the four is involved in a transfer. The security report form is delivered by Formspree, so anything you type into it — including a contact address you choose to give — passes through their service in order to reach us.
Paddle is the merchant of record for Poftim+: it is the seller on the transaction and handles payment, tax and refunds under its own privacy policy, as a controller of the data you give it. Your card details go to Paddle and never reach us — we receive only whether a subscription is active and when it renews. Postmark delivers sign-in and account emails on our behalf, and therefore handles your email address to send them.
Everything else the site loads comes from poftim.app itself.
Your rights
Asking us about your data
Poftim is operated from Romania, so the GDPR applies. You have rights of access, correction, erasure, restriction, objection and portability over personal data held about you, and the right to complain to a supervisory authority — in Romania that is the ANSPDCP, and you may also complain to the authority in the country where you live.
For the transfer page there is still very little to exercise them against. Sessions exist only while they are running and hold no identifying information; logs hold a truncated address and a path; analytics data is tied to a cookie rather than to you, and you can erase it yourself by withdrawing consent, which clears that cookie.
For a Poftim+ account, access and erasure are not a request you have to make and wait on. Both are buttons on the account page: one downloads everything held about you as a file, the other deletes the account. Ask us anyway if you would rather, or if something is not covered by those.
Send questions about this notice through the contact form. Please do not include private files, live pairing links or another person's personal information in a message.