Cookie Policy

Last updated: 7 October 2026

This Cookie Policy explains how EchoStream SRL (“Transferify”, “we”, “us”) uses cookies and similar technologies when you visit or use our website and services. It describes what these technologies are, the categories we use, and how you can manage or withdraw your consent at any time. It should be read together with our Privacy Policy, which explains in more detail how we handle personal data.

What are cookies and similar technologies?

Cookies are small text files that a website places on your device to store information. Similar technologies include local storage (the browser’s localStorage), which lets a site keep small amounts of data in your browser between visits, and IndexedDB, a database built into your browser, which lets a site keep larger amounts of data there, files included. Throughout this policy, references to “cookies” also cover these similar technologies unless we say otherwise.

We use both first-party technologies (set by Transferify) and third-party technologies (set by Google, by Reddit and, on transferify.ro and the Romanian pages of transferify.cloud, by Meta, our analytics and advertising providers). Third-party cookies are only used for advertising measurement and advertising audiences, and only after you consent - see below. Analytics sets no third-party cookie at all: it uses only first-party entries in your browser’s local storage, and the measurement reaches Google through our own servers rather than through a script on the page.

Your choices: an opt-in consent model

We use an opt-in approach for non-essential cookies, and the banner asks about three separate purposes: analytics, advertising measurement and email offers. The first two are cookie purposes; the third sets no cookie. On your first visit, a cookie banner appears. No Google tag is loaded - not even an anonymous request - until you grant the advertising purpose, and no analytics tag is loaded from Google at all. The strictly necessary sign-in service described below is also operated by Google and runs regardless, because you cannot sign in without it. The third purpose is that choice which is not a cookie: an optional, off-by-default “Email me Transferify offers and discounts.” preference. It uses no cookie and no tracking; it is a choice we save, and it takes effect for your account when you sign up or log in. “Accept all” grants both cookie purposes and the email choice together; “Customize” lets you turn each on without the others; declining or ignoring the banner leaves only the strictly necessary technologies described below.

You can change your decision at any time. Once you have answered, every page carries a “Cookie Settings” button in its bottom-left corner that re-opens the preferences in one press, and the same entry sits under the “Resources” menu; either lets you grant or withdraw each choice separately. Withdrawing takes effect immediately: we stop the Google tag, Reddit’s measurement pixel and Meta’s measurement tag from collecting anything further in that same visit and delete the Google, Reddit and Meta cookies already set (_ga*, _gcl*, _gac*, _rdt_*, _fbp, _fbc) and the entries Meta’s tag keeps in your browser’s local storage - you do not have to reload or wait for your next visit. For the email-offers choice, the account preference and the unsubscribe link in every message remain the withdrawal route once it is saved with your account. Your choice is remembered in your browser’s local storage (under the key cookie-consent-v3), not in a cookie itself. Because the record lives in your browser, clearing your browser storage will reset your choice and the banner will appear again on your next visit.

Counting your answer, and how a visit reached us

Your answer to the banner is itself counted, and that count needs no cookie and no consent. When you accept, reject, or save your own selection, we send ourselves one anonymous message saying, for each purpose you answered - the optional email choice included only once you have answered it - whether it was granted or denied, and which control recorded it - nothing else. It carries no email address. It sets no cookie, writes nothing to your browser storage, carries no identifier, no session and no account, and it never reaches Google or any other third party. Only the totals are kept, and nothing on our side records your individual answer.

We count it because the visitors who decline are invisible to every analytics and advertising tag by design - no tag runs to report a refusal - so a first-party count is the only way to know how many people decline. A second count works differently, and needs no cookie either. From the moment you open the site, a coarse acquisition category - one word from a closed list: paid-search, paid-social, organic, ai, social, referral, direct, recipient-page, recipient-page-game, recipient-page-control, request-page or referral-invite, of which ai says only that the visit came from an AI assistant’s site and never what was asked there, while the words from recipient-page onwards say only that you opened one of the pages someone reaches because another person sent them something (a transfer to download, or a request asking you for files), or that the address you followed carried someone’s referral code, which is never read on this path, and recipient-page-game and recipient-page-control say in addition which of two test groups the download page load was put in, never anything you did on it - travels with the requests your browser makes to our servers, alongside the sign-in token those requests already carry. We read it at two moments: when an account is first established, where we add one tick to a total for that category, and on every request that carries it, where we add one to that day's request total for the category and, on the first request of each page load that carries it, one to its visit total. From that second count only the daily totals are kept, and nothing about you or the request is stored beside them. Where the link carried one of Google’s or Reddit’s advertising click parameters we use only the fact that one was present - its value is never read, stored or sent anywhere unless you granted the advertising purpose - and the address of the site you came from is never sent with this count. What each count contains, what is never collected for it, and the legal basis we rely on are set out in Section 11 of our Privacy Policy.

Categories of cookies we use

1. Strictly necessary (essential)

These technologies are required for the service to function and are always on. They do not require your consent because Transferify cannot operate without them. They are used to keep you signed in via Google's authentication service (managing your login session) and to remember your own cookie-consent choice and basic application state. If you block these technologies in your browser, sign-in and core features will not work.

While a transfer is running you can choose to play a small game. The game keeps your best score in your browser’s session storage so it can show it to you again. It is one number, only the game reads it, and it is written only after you have played. It needs no consent because it exists only for the game you chose to start. It is removed when you close the browser tab.

When you are signed in, your browser also keeps, for your account, which of our own plan suggestions and offers it has already shown you or you have closed with "Not now": the dates, and for a suggestion about an address you send to, a number worked out from that address rather than the address itself. Only this site reads it, and it exists so the same suggestion is not shown to you again, or not again for a while. It is kept until you clear your browser storage.

2. Analytics

Analytics helps us understand aggregate product usage so we can improve Transferify. It is off by default and starts only after you click “Accept all” on the cookie banner, or switch the analytics purpose on under “Customize”. If you decline or ignore the banner, nothing described in this section happens at all.

No analytics service runs in your browser, and this purpose sets no cookie. Once you grant it, your browser keeps one randomly generated identifier in local storage under analytics.clientId.v1, sends what it measures to our own servers, and our servers pass it on to Google’s analytics service. Google is still the analytics provider and still receives the measurements; what changed is that they travel through us instead of through a Google script on the page. The identifier is a pair of random numbers. It is never your account identifier, your email address or anything derived from them, it is created only at the moment the first measurement is sent - so a visitor who declines never has one - and withdrawing the analytics purpose deletes it.

This purpose also covers a record of how your first visit reached us: whether it came from a paid advertisement, from an unpaid search result, from a link on another website, or directly, together with the page you first landed on and the domain of that other website where there was one (never the page you were reading there). That record is kept against your account and is only made once you grant this purpose; the anonymous channel total described above is a separate count that carries no link to you and no landing page.

Earlier versions of Transferify did load Google’s analytics service in the browser, and it set the cookies _ga and _ga_<container>. We no longer set either. If your browser still holds them from an earlier visit, withdrawing consent deletes them along with the advertising cookies described below.

3. Advertising measurement and audiences

These cookies let us measure which advertising campaigns brought people to Transferify, so we do not keep paying for advertising that does not work, and they place your browser in the advertising audiences described below. They are off by default and are only set after you grant the advertising purpose. What we do is limited on purpose:

  • Where the advertisement's link carried them, we record the three labels we put on our own advertisements: which network it was, which campaign, and which version of the advertisement. They are kept against your account and are only recorded once you grant this purpose. Whether a visit came from an advertisement, and the page you first landed on, are recorded under the analytics purpose instead (see Analytics above).
  • If you arrived from a Google or Reddit advertisement, or on transferify.ro and the Romanian pages of transferify.cloud through any link from Facebook or Instagram, the link carries a click identifier (gclid, gbraid, wbraid, rdt_cid or fbclid). We only read its value once you have granted this purpose - if you decline, we never read the value, and use only the bare fact that such a parameter was present - and it is stored against your account for at most 365 days, then deleted.
  • We report six events to Google: that an account was created, that it sent its first transfer, that a plan limit stopped one of its requests, that a checkout was started, with its amount, that a subscription payment was made, with its amount, and that a one-off purchase was made, with its amount. Once you have an account and have granted this purpose, each carries a one-way hash (SHA-256) of your account email address, so Google can match the event to the ad click; none carries the address itself or any file information. The recipient is Google Ireland Limited.
  • We report two events to Reddit: that an account was created, and that a purchase was completed, with its amount. To match them to the ad click, Reddit receives the click identifier and a one-way hash (SHA-256) of your account identifier and email address; nothing about your files.
  • On transferify.ro and the Romanian pages of transferify.cloud, Meta’s measurement tag reports the pages you view, a sign-up and a purchase. Once it has started there, it also reports the pages you go on to open in the same visit and records the buttons you click and the titles of those pages, including inside your account after you sign in, never the content of your files, and it puts your browser in advertising audiences Meta holds for us, so that we can stop advertising to people who already subscribe and advertise again to people who looked at Transferify without buying; a membership lasts at most 180 days from your last visit. Our servers also report six events to Meta for accounts that accepted advertising under this wording: that an account was created, that it sent its first transfer, that a plan limit stopped one of its requests, that a checkout was started, with its amount, that a subscription payment was made, with its amount, and that a one-off purchase was made, with its amount. To match them to an ad, Meta receives the click identifier, an identifier its tag set in your browser, details of the browser you used, a reference number for your account and for each event, and a one-way hash (SHA-256) of your email address and of the country recorded for your account; nothing about your files. Meta’s tag may also read contact details typed into our forms while it runs, including the addresses of the people you send files to, and hashes them before sending. The recipient is Meta Platforms Ireland Limited.
  • Google’s measurement and advertising follow your consent choices. When you grant this purpose, Google adds your browser to advertising audiences of people who have visited Transferify, which it holds for us. This is so that we can stop showing advertisements to people who already subscribe to Transferify, and show advertisements again to people who looked at Transferify without buying a plan. A membership lasts at most 540 days from your last visit. Withdrawing this purpose stops us adding you to an audience and stops an existing membership being refreshed, so it runs out. Matching a contact list happens when you accept advertising cookies or when you switch on “Use my email for Transferify ads on Google” in your account settings: either one sends Google a one-way hash (SHA-256) of your account email address so it can add you to those audiences, and switching it off in either place asks Google to remove you, which usually takes about a day. We still do not add Google’s data about signed-in users to our analytics.
  • In plain terms, as Google asks its advertisers to state: third-party vendors, including Google, show our advertisements on websites and apps across the internet; those vendors, including Google, use cookies and device identifiers to show you our advertisements based on your past visits to Transferify; and the audiences are built by the remarketing feature of Google’s advertising service (Google calls it simply “Remarketing”), which uses Google’s own advertising cookies and device identifiers. Besides the Cookie Settings button described below, you can opt out of this kind of advertising on Google’s Ads Settings page (adssettings.google.com), on the Network Advertising Initiative opt-out page (optout.networkadvertising.org), or in your device’s advertising settings. Those routes act on Google and on advertising networks generally; withdrawing the advertising purpose here is what stops Transferify’s own tags.

Cookie inventory

Name / technologyProviderCategoryPurposeRough duration
Sign-in session (local storage)Transferify (first-party)Strictly necessaryKeeps you signed in and manages your authenticated session.Persistent until sign-out or browser storage is cleared
cookie-consent-v3 (local storage)Transferify (first-party)Strictly necessaryRemembers your consent choices, the email-offers answer included, and basic app state.Persistent until you change your choice or clear browser storage
byteRunner.best.v1, fileInvaders.best.v1, packTheZip.best.v1, game2048.best.v1 (session storage)Transferify (first-party)Strictly necessaryRemembers your best score in the game offered while a transfer runs, one key per game. Written only after you play; only the game reads it.Until you close the browser tab
upsell.moments.v1 (local storage)Transferify (first-party)Strictly necessaryRemembers, for your signed-in account, which plan suggestions you have been shown or closed with "Not now", so they are not repeated: dates, limit-event dates and a number worked out from an address you send to often. Only this site reads it.Until you clear browser storage
upsell.dismissed.v1 (local storage)Transferify (first-party)Strictly necessaryRemembers which signed-in accounts on this browser have closed our own discount offer, so it is not offered to them again: the account identifier only. Only this site reads it.Until you clear browser storage
purchases.noteSeen.v1 (local storage)Transferify (first-party)Strictly necessaryRemembers, for your signed-in account, which of your unused one-off purchases you had in front of you when you closed the note about them on the send form, so the note stays closed until a purchase you have not seen appears: the account identifier and purchase identifiers only. Only this site reads it.Until you clear browser storage
transferify-upload-sessions (IndexedDB)Transferify (first-party)Strictly necessaryKeeps a hosted upload you start while signed in, so you can continue it in this browser after a reload, a closed tab or a lost connection. For each kept upload it holds the transfer’s identifier and your account identifier; the file encryption key and a secret used to derive the encryption IVs, which is why the upload can only be continued in this browser; for a Zero-Knowledge link, the part of the link after # that carries the key, optionally protected by the link’s password; for a default transfer, the encrypted copy of the key already sent to us; the names, sizes, modification dates and types of the files, with their folder paths; your message, if you wrote one, and for a send to recipients their email addresses and the group identifiers; the expiry chosen for the link, whether it has a password (never the password itself) and its download limit; how far the upload got; a 16-byte authentication tag for each piece already encrypted for sending; and, only when the whole selection is at most 2 GiB and the browser has room, a copy of the files themselves. Nothing is kept in it until you start a hosted upload. It is used only for that upload, never for analytics or marketing, and nothing in it is sent anywhere except to our servers as part of the upload. Only this site reads it.Until the upload finishes, is cancelled or is discarded, or you sign out. Otherwise until you next open Transferify in this browser after the upload’s deadline has passed. That deadline is the link’s own expiry, counted from when the upload began, and is never more than 7 days after it began. If you never open Transferify in this browser again, until you clear browser storage.
transferify.ads.firstTouch (local storage)Transferify (first-party)Analytics and advertising measurementHolds how your first visit reached us (analytics) and the click identifier and campaign labels described above (advertising measurement) until you sign in, so they can be attached to your account once. Each part is written only if you granted its purpose, and is removed from your browser when you withdraw that purpose.Up to 365 days
analytics.clientId.v1 (local storage)Transferify (first-party)AnalyticsA randomly generated identifier that joins one browser’s measurements together. Written only once you grant the analytics purpose, and deleted when you withdraw it.Until you withdraw consent or clear browser storage
_gcl_auGoogle (third-party)Advertising measurementLinks an advertisement click to an action taken on the site, for conversion measurement.~90 days
_gac_<property>Google (third-party)Advertising measurementCarries campaign information for Google’s conversion measurement.~90 days
_rdt_uuidReddit (third-party)Advertising measurementIdentifies your browser to Reddit so an ad click can be matched to a later sign-up or purchase.~90 days
_rdt_cidReddit (third-party)Advertising measurementHolds the click identifier Reddit appends to the ad’s landing address (rdt_cid).~90 days
_rdt_emReddit (third-party)Advertising measurementHolds a one-way hash (SHA-256) of your account email for matching; written only while you are signed in.~90 days
_fbpMeta (third-party, transferify.ro and transferify.cloud/ro only)Advertising measurementIdentifies your browser to Meta so an ad click or view can be matched to a later sign-up or purchase.~90 days
_fbcMeta (third-party, transferify.ro and transferify.cloud/ro only)Advertising measurementHolds the click identifier Meta appends to the ad’s landing address (fbclid).~90 days

Exact cookie names, containers and durations set by Google, Reddit and Meta may vary; the values above reflect the typical behaviour of Google’s advertising cookies, Reddit’s measurement pixel and Meta’s measurement tag.

How to manage or withdraw consent

You can manage analytics and advertising cookies in two ways:

  • Cookie Settings on our site: press the “Cookie Settings” button that every page carries in its bottom-left corner once you have answered, or open the same entry under the “Resources” menu, to re-open the preferences and grant or withdraw each purpose at any time. Withdrawing stops collection in the current visit, deletes the Google, Reddit and Meta cookies already set, and stops any advertising-audience membership being refreshed.
  • Your browser controls: most browsers let you block or delete cookies and clear local storage. Please note that blocking essential cookies and storage will break sign-in and other core Transferify features.
  • Google’s and the advertising industry’s own opt-outs: Google’s Ads Settings page, the Network Advertising Initiative opt-out page and your device’s advertising settings, described under “Categories of cookies we use”. They do not replace the Cookie Settings button, which is what withdraws the consent you gave us.

Relationship to our Privacy Policy

This Cookie Policy is part of, and should be read alongside, our Privacy Policy, which explains what personal data we collect, the legal bases we rely on, how long we keep it, and the rights you have over it. Where analytics data collected via cookies constitutes personal data, its processing is described in the Privacy Policy. To erase the data held about you, see our Data Deletion Instructions.

Changes to this policy

We may update this Cookie Policy from time to time to reflect changes in the technologies we use or for legal, regulatory or operational reasons. When we make material changes, we will update the “Last updated” date above and, where appropriate, ask for your consent again through the cookie banner.

Contact

If you have questions about this Cookie Policy or how we use cookies, contact us at support@transferify.cloud.