Share2Me

Privacy Policy

Last updated: August 12, 2026

1. Introduction

Share2Me ("we," "us," or "our") operates the website share2.me. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information. By using our service, you agree to the collection and use of information in accordance with this policy.

Our core file and text transfer features are built on a zero-knowledge architecture. All file and text transfers are end-to-end encrypted directly in your browser using AES-GCM-256 before being sent over the network. Our servers only facilitate the initial WebRTC connection handshake and never possess your encryption keys or file contents.

2. Information We Collect

2a. Information We Do NOT Collect

  • We do not store your files, text, or encrypted chunks on any server or cloud database.
  • We do not log the content of your transfers.
  • We do not sell, rent, or share your personal data with third parties for their own marketing.
  • We do not track your file transfer history.

2b. Account Data (G2P Portal Users)

If you sign in to use the G2P (Vendor Portal) feature via Google OAuth, we collect and store the following in our database to operate the service:

  • Your Google account email address
  • Your Google account name and profile photo URL
  • A unique Share Code associated with your account
  • Metadata about file uploads sent to your portal (sender name, file names, file sizes, upload timestamps)

We retain this account data for as long as you maintain an active account. You may request deletion of your account and all associated data at any time by contacting us at privacy@share2.me.

2c. Ephemeral Connection Metadata

For P2P file transfers, our signaling servers temporarily hold connection metadata (the 6-digit OTC code and IP addresses) strictly for the duration of the active transfer. Once the browser session ends or the transfer completes, this metadata is immediately purged from memory. It is never written to permanent storage.

3. Third-Party Analytics Services

We use the following third-party services to understand how users interact with our website and to improve our service. Each of these services may collect data about your visit, including your IP address, browser type, pages visited, and time spent on pages.

  • Google Analytics (GA4): We use Google Analytics to collect aggregate statistics about site traffic and usage. Google Analytics uses cookies to track user sessions. Data is processed by Google LLC. You can opt out at Google Analytics Opt-Out.
  • Google Tag Manager: We use Google Tag Manager to manage and deploy analytics scripts on our site. GTM itself does not collect personal data but facilitates the services listed here.
  • Vercel Analytics & Speed Insights: We use Vercel's built-in analytics to monitor Core Web Vitals and page performance. Vercel processes anonymized performance metrics. See Vercel's Privacy Policy.

4. Advertising — Google AdSense & Cookies

We use Google AdSense to display advertisements on our website. Google AdSense uses cookies, including the DoubleClick cookie, to serve ads based on your prior visits to this website and other websites. These cookies allow Google and its partners to serve ads to you based on your visit to our site and/or other sites on the internet.

You may opt out of personalized advertising by visiting Google Ad Settings. You can also opt out of third-party vendor cookie usage by visiting aboutads.info/choices or youronlinechoices.eu.

For more information about how Google uses data when you use our site, see: How Google uses data from sites that use our services.

Cookie Types We Use

  • Session Cookies: Temporary cookies that are deleted when you close your browser. Used for WebRTC connection handshakes.
  • Analytics Cookies: Google Analytics places persistent cookies (_ga, _gid) to distinguish users across sessions.
  • Advertising Cookies: Google AdSense uses DoubleClick cookies (IDE, DSID) to track cross-site user behavior for ad targeting.

You can control cookie preferences through your browser settings. Note that disabling certain cookies may affect the functionality of our service.

5. Your Rights (GDPR & CCPA)

Depending on your location, you may have the following rights regarding your personal data:

  • Right to Access: You can request a copy of the personal data we hold about you.
  • Right to Erasure ("Right to be Forgotten"): You can request that we delete your account and all associated personal data.
  • Right to Rectification: You can request that we correct any inaccurate data we hold about you.
  • Right to Object: You can object to our processing of your personal data for direct marketing or analytics purposes.
  • Right to Data Portability: You can request a machine-readable copy of your data.
  • CCPA (California Residents): You have the right to know what personal information we collect, disclose, and sell. We do not sell your personal information.

To exercise any of these rights, contact us at privacy@share2.me. We will respond within 30 days.

6. Data Security

We take the security of your data seriously. All P2P file transfers are end-to-end encrypted in your browser before transmission using AES-GCM-256 with ephemeral ECDH key exchange. G2P portal data stored in our database is protected using industry-standard security measures including encrypted storage and secure HTTPS connections for all API communications.

7. Children's Privacy

Our service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately at privacy@share2.me.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the "Last updated" date at the top of this page. We encourage you to review this policy periodically.

9. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, you can reach us at: