Privacy Policy
Last updated: 20 August 2026
This Privacy Policy explains how EchoStream SRL ("Transferify", "we", "us" or "our") collects, uses, shares and protects personal data when you use the Transferify file-transfer service at transferify.ro and transferify.cloud (the "Service"). It is written to meet the requirements of the EU General Data Protection Regulation (GDPR) and applicable Romanian data-protection law.
For the purposes of the GDPR, the data controller is EchoStream SRL, a company registered in Romania under CUI RO46964705 and Trade Register no. J12/6242/05.10.2022, with its registered office at Str. Soporului nr. 8, bl. C, sc. 1, ap. 8, 400482 Cluj-Napoca, Romania. You can reach us about privacy at support@transferify.ro.
1. How Transferify works (and why it matters for your privacy)
Transferify lets you send files in two different ways, and each handles your data differently:
- Instant peer-to-peer (P2P) transfers. Files stream directly from the sender's device to the recipient's device over WebRTC and are end-to-end encrypted. The file contents are never stored on our servers. Our servers only help the two devices find and connect to each other (signaling) and may relay the encrypted stream if a direct connection cannot be established; we do not retain the file contents.
- Hosted transfers. Files are encrypted on your device (AES-256-GCM) and then uploaded to Amazon Web Services (AWS) S3 in the European Union (eu-central-1, Frankfurt). By default we hold the file's encryption key in escrow, wrapped by AWS Key Management Service (KMS), which means we are technically able to decrypt the file (for example to deliver it or comply with a lawful request). If you use the paid "Zero-Knowledge" mode, the file key is kept entirely off our servers and we cannot decrypt your files.
2. Personal data we collect
Depending on how you use the Service, we may collect:
- Account and identity data - the email address associated with your sign-in, your Firebase user identifier (UID), and the sign-in provider you used (Google, Microsoft, Yahoo, or Facebook). You may also use the Service with an anonymous session, in which case we hold only a temporary Firebase UID.
- Transfer and file metadata - information about your transfers such as file names, sizes and types, timestamps, chosen expiry, download limits, whether a transfer is password-protected, recipient email addresses you enter, and delivery status. For hosted transfers this also includes the wrapped encryption key (except in Zero-Knowledge mode). For P2P transfers we do not store the file contents.
- Sender email (optional) - if you choose to add your email address to a transfer, we store it as part of that transfer and show it to the recipients on the download page so they know who sent the files. It is also placed in the reply-to address of the email each recipient receives, and is handed to our email provider for that purpose, so be aware that adding it discloses your address to everyone you send to. Like the rest of the transfer record, it is kept for up to 24 months after the transfer expires (see section 7) and is deleted with it.
- Recipient email addresses supplied by senders - when a sender sends you files, or asks you to upload files, they type your email address into the Service. We did not obtain that address from you, so Section 5 sets out separately where it came from, what we do with it, who it goes to and how to stop the emails.
- Optional feature data - if you use them: contacts you save, share links you email, reminders, and settings for password protection, download limits and link expiry.
- Payment and billing data - if you subscribe to a paid plan, the billing details used for invoicing and tax - your billing address, VAT/tax identification number and company name - together with your payment card, are collected and held by Stripe on Stripe's own hosted checkout and Customer Portal pages. Depending on the purpose, Stripe acts as our processor or as an independent controller, as described in Section 4. We do not collect or store these billing details or your full card number on our own systems; on our side we retain only Stripe reference identifiers (such as your Stripe customer and subscription ids) and subscription metadata (plan, billing status and subscription period) needed to manage your plan.
- Technical, device and usage data - your IP address, browser and device type, operating system, and how you interact with the Service. This includes Firebase Analytics (Google Analytics 4) product-analytics data, which is only collected where you have consented (see Section 10, Cookies and analytics).
3. Why we use your data, and our legal bases
Under the GDPR we must have a legal basis for each use of your personal data. We rely on the following:
- To provide the Service - creating your account, authenticating you, accepting uploads, delivering transfers, enforcing expiry, download limits and password protection, and managing your subscription. Legal basis: performance of a contract (GDPR Art. 6(1)(b)).
- To keep the Service secure and working - preventing abuse and fraud, debugging, ensuring reliability, and understanding aggregate demand. Legal basis: our legitimate interests (GDPR Art. 6(1)(f)), balanced against your rights.
- To take payment and issue invoices - processing subscription payments through Stripe, and having Stripe collect the billing address, VAT/tax id and company name needed to issue tax-compliant invoices. Legal basis: performance of a contract (GDPR Art. 6(1)(b)) and compliance with our legal obligations (GDPR Art. 6(1)(c)) under applicable VAT, tax and accounting law.
- Product analytics - measuring how the Service is used so we can improve it, via Google Analytics 4. Legal basis: your consent (GDPR Art. 6(1)(a)). You can withdraw this consent at any time.
- Advertising measurement - measuring which advertising campaigns bring people to Transferify, so we do not keep paying for advertising that does not work. Where you arrived from a Google advertisement, this includes the click identifier its link carries (
gclid,gbraidorwbraid), the coarse channel your visit came from, the page you first landed on, and two events reported to Google: that an account was created, and that an account sent its first transfer. We do not send Google your email address, your account identifier or anything about your files, and we do not use this data to build a profile or to show you personalised advertising. Legal basis: your consent (GDPR Art. 6(1)(a)). We read the click identifier only after you have granted this consent, and we keep it for at most 90 days. You can withdraw this consent at any time. - Anonymous statistics counted without consent - keeping two aggregate totals: how visitors answer the cookie banner, and the coarse acquisition channel a visit came from. Section 11 sets out exactly what each total holds and what is never collected for it. The totals themselves are aggregate statistics rather than personal data and need no legal basis; the personal data on that path does - your IP address, and the session token the channel category accompanies. Legal basis: our legitimate interests (GDPR Art. 6(1)(f)), in knowing whether our own measurements are representative and in keeping an endpoint anyone can call usable.
- To communicate with you about your own account - service messages about your account, your transfers and your subscription. Legal basis: performance of a contract (GDPR Art. 6(1)(b)) for messages the Service owes you, and our legitimate interests (GDPR Art. 6(1)(f)) for security and operational notices you did not specifically ask for.
- To email the recipients a sender chooses - delivering the download link, or a file request, to the email addresses the sender entered, and recording whether that delivery succeeded so we do not send it twice. Towards the sender this is performance of a contract (GDPR Art. 6(1)(b)): sending the email is the service they asked for. The recipient has no contract with us, so towards them we rely on our legitimate interests and the sender's (GDPR Art. 6(1)(f)) in delivering a transfer that was deliberately addressed to them - balanced by sending only what delivery requires, by not using the address for marketing or profiling, and by the one-click opt-out described in Section 5.
- To honour an opt-out - keeping a suppression record of every address that has unsubscribed, so no later transfer can email it again. Legal basis: compliance with our legal obligations (GDPR Art. 6(1)(c)), because Art. 21 obliges us to stop and we cannot stop reliably without remembering who asked us to, and our legitimate interests (GDPR Art. 6(1)(f)) in not contacting people who have told us not to.
4. Who we share your data with
We do not sell your personal data. We share it only with service providers and other recipients that help us run the Service, under contract and only as needed:
- Google (Firebase Authentication, Google Analytics 4 and Google Ads) - for sign-in and, where you consent, product analytics and advertising measurement. For analytics Google acts as our processor; for advertising measurement Google acts as an independent controller of the data it receives, under its own terms.
- Amazon Web Services (AWS) - for hosted-file storage (S3, EU eu-central-1) and encryption-key management (KMS).
- Stripe - acts as our processor when it processes payment and subscription data on our instructions. Stripe acts as an independent controller for purposes it determines itself, including fraud prevention, security, and compliance with legal and regulatory obligations; its own privacy notice applies to that processing.
- Mailjet SAS (a Sinch company) - our email delivery processor. Every email the Service sends - transfer deliveries, file requests, account activation, sign-in codes and service notices - is handed to Mailjet for delivery, over an authenticated TLS (STARTTLS) SMTP connection to in-v3.mailjet.com or, for sign-in codes, over Mailjet's HTTPS send API. Mailjet delivers on our instructions only and does not use the addresses for its own purposes. We disable Mailjet's open tracking and click tracking on every message we send, so we do not learn whether you opened an email or which links you followed.
We may also disclose personal data where required by law, to respond to lawful requests from public authorities, or to protect our rights, users and the Service. A current list of processors can be provided on request at support@transferify.ro.
5. If someone sent you files: your address as a recipient
This section is for people who receive a Transferify email without ever having signed up. We did not get your email address from you, so this is the information we owe you under GDPR Art. 14. Where we send you a file request, that email carries a short first-layer version of this notice as well.
- Where your address came from. A Transferify sender - the person or organization sending you files, or asking you to upload files - typed it into the Service. That sender is the only source. We never buy, rent, scrape or otherwise acquire recipient addresses, and we do not add you to any mailing list.
- What we process about you. Your email address; whether the message to you was accepted for delivery, and the retry state if it was not; and the transfer metadata needed to deliver it - the transfer's identifier, its download link, its expiry and any download limit. If the sender chose to add their own email address, that travels with the message so you can see who sent it and reply to them. For a file request, the requester's name, email address and the note they wrote are the content of the email you receive.
- What is deliberately NOT in a transfer-delivery email. The sender's free-text message, the file names, the number of files and the file sizes are not put in the email and are not handed to our email provider. They stay behind the download link.
- Why we email you, and on what legal basis. To deliver the transfer or request the sender addressed to you, and nothing else. The bases are set out in Section 3: GDPR Art. 6(1)(b) towards the sender, whose instruction it is, and GDPR Art. 6(1)(f) towards you, on our and the sender's legitimate interest in delivering a transfer that was deliberately addressed to you. We do not use your address for marketing, advertising, profiling or automated decision-making.
- Who else sees it. Only Mailjet SAS, our email delivery processor (Section 4), plus Amazon Web Services as the host of the systems that store the transfer. Other recipients of the same transfer never see your address: we send each recipient their own message, and the visible "To" line carries only our own sending address.
- How long we keep it. Your address is part of the transfer record and is deleted with it - see Section 7. If you unsubscribe, we do not keep the address itself: we store a one-way cryptographic fingerprint of it on a suppression list, for as long as the opt-out stands, purely so that no later transfer can email you. The fingerprint lets us check a new transfer against your opt-out, but it cannot be turned back into your address or used to list who has unsubscribed. Your opt-out outlives the sender: if the account that emailed you is later deleted, the suppression entry stays, because forgetting it is the one thing that would let a new transfer reach you again.
- How to stop the emails. Every transfer email and file request we send carries an unsubscribe link, and email clients that support one-click unsubscribe can act on it directly. Confirming it stops file-transfer email to your address from every Transferify sender, not just the one who wrote to you. This is also how you exercise your right to object under GDPR Art. 21; as a matter of policy we honour it unconditionally, without asking you for a reason. The unsubscribe page needs the signed link from the email, so it cannot be reached by typing the address; if you no longer have the email, write to support@transferify.ro and we will record the opt-out for you - and we will remove it again if you later change your mind.
- If you have already unsubscribed. We still hold the fingerprint of your address on the suppression list and still check new transfers against it - that is the only way to keep the emails stopped - but you will not receive the notice above again, because we send you no email. You received it with the message that led you to unsubscribe.
Your other rights - access, rectification, erasure, restriction, portability and complaint to a supervisory authority - are in Section 8, and apply to you exactly as they do to account holders. The controller is EchoStream SRL, contactable at support@transferify.ro.
6. International data transfers
Hosted files are stored in the EU (AWS Frankfurt, eu-central-1). However, some of our providers - in particular Google and Stripe - may process certain data (such as authentication, analytics, or payment and billing/tax details) outside the European Economic Area, including in the United States. Applicable transfers are covered by the European Commission's Standard Contractual Clauses (SCCs), together with any applicable adequacy decision. Stripe is responsible for its own transfers when acting as an independent controller.
Email delivery. Our email processor Mailjet SAS is a French company and part of the Sinch group. Sinch publishes a data-processing agreement that incorporates the European Commission's Standard Contractual Clauses (controller-to-processor module) with the Sinch entity as data importer, and a sub-processor list which states that Mailjet's data centres are provided by Google Cloud France SARL inside the EU (Germany and Belgium), while several sub-processors listed against Mailjet process in the United States as well as the EU - Mailgun Technologies, Inc. for support, deployment and service provisioning, Atlassian Corporation for support ticketing and incident management, and Stripe Payments Europe, Limited for billing. Sinch's own privacy notice states that a customer's platform is hosted from data centres in the United States or Europe depending on the deployment the customer selected, so the region is a fact about our account rather than about Mailjet in general. Wherever a processing leg falls outside the European Economic Area, it is covered by the EU Standard Contractual Clauses incorporated in Sinch's published data-processing agreement for Mailjet; you can request a copy of the applicable safeguards by writing to support@transferify.ro.
7. How long we keep your data (retention)
- Hosted files automatically expire and are deleted according to the expiry the sender chooses (and any download limit that is reached first). After expiry, the encrypted file is removed from S3.
- P2P transfers are not stored: file contents exist only during the live transfer.
- Account deletion. Once we accept your request, access to the account and paid features is disabled immediately. Provider and product-data deletion is processed asynchronously. Deletion processing removes owned product data and hosted files and deletes the associated Stripe Customer, which cancels active subscriptions without waiting for period end and removes saved card details. A failed step may require retry or repair. Deletion does not itself request a full or prorated refund; statutory refund and withdrawal rights remain unaffected. The limited retention categories and purpose limits are described below.
- Mandatory accounting registers and supporting documents. Mandatory accounting registers and supporting documents are access-restricted and retained for 5 years, calculated from 1 July of the year following the financial year in which they were prepared. They are retained only to meet applicable Romanian accounting and tax obligations.
- Union OSS records. Only where the Union One Stop Shop scheme applies, the required transaction records are access-restricted and retained for 10 years from the end of the year in which the transaction occurred.
- Legal-claim records. The minimum records needed to establish, exercise or defend legal claims may be retained for the applicable limitation period. Access is restricted and the records are not used to provide the Service or for marketing.
- Security and anti-reprovisioning records. Minimal deletion-status and identity-link records may be retained only as necessary to block authentication or account reprovisioning and to protect the Service. Access is restricted, and the records are deleted or anonymized when no longer needed for those purposes.
- Deletion-completion and audit records. Minimal deletion state, retry or repair metadata, and audit evidence may be retained only as necessary to complete, repair or demonstrate the deletion process. Access is restricted, and the records are deleted or anonymized when no longer needed for those purposes, unless another stated legal obligation or legal claim requires retention.
- Stripe records. When acting as an independent controller, Stripe may retain payment, billing, fraud-prevention and compliance data under its own legal obligations and retention periods.
- Server logs are kept only for the short term, for security, abuse prevention and troubleshooting, and analytics are retained only as long as needed for the purposes described above.
- Abuse-limit records. The parts of the Service anyone can call without signing in are rate-limited, which keeps one row per network per window holding a keyed hash, a request count and a time - never an address in the clear, and never what the request was for. A row is needed only for the length of its window, typically an hour, and a routine sweep removes it afterwards. The sweep works through spent rows at a bounded pace shared with every other protected part of the Service, so a spent row can persist beyond its window - under sustained traffic, considerably longer - until its turn comes; it is not read again in the meantime.
- Advertising-measurement data - the click identifier, coarse channel and first landing page described in section 3 - is kept for at most 90 days and is then deleted, whether or not you are still a customer. It is deleted immediately if you delete your account.
- Transfer records (file names, sizes, timestamps, the optional sender email and recipient addresses - never the file contents) are kept for up to 24 months after the transfer expires, so that if you later create an account with a verified email you can claim your past transfer history. After that window they are permanently deleted; transfers belonging to an account are managed from your Transfers page instead.
- Recipient opt-out records. If you unsubscribe from transfer emails, we record a one-way cryptographic fingerprint of your address - not the address itself - together with the date and whether the opt-out arrived through the one-click header or the confirmation page. We keep that record for as long as the opt-out stands, with no fixed end date, because deleting it would let transfer emails to your address start again. It is used only to block delivery - never to contact you, and never for marketing. Write to support@transferify.ro if you want the record removed so that senders can reach you again.
- Email delivery records. Mailjet processes the messages it delivers for us and keeps its own delivery logs as our processor. Those logs are processed under its data-processing agreement solely for delivery, troubleshooting and abuse prevention - never for Mailjet's own purposes - and are deleted once they are no longer required for those purposes and Mailjet's legal obligations.
8. Your rights
Subject to the conditions and exceptions in the GDPR, you have the right to:
- Access - obtain a copy of the personal data we hold about you.
- Rectification - correct inaccurate or incomplete data.
- Erasure - ask us to delete your personal data ("right to be forgotten").
- Restriction - ask us to limit how we process your data.
- Portability - receive your data in a structured, machine-readable format.
- Objection - object to processing based on our legitimate interests.
- Withdraw consent - where we rely on consent (such as analytics), withdraw it at any time, without affecting processing already carried out.
You can erase your account and its data yourself from inside the product - the steps are on our Data Deletion Instructions page.
If you received a transfer email or a file request and simply want them to stop, you do not need to write to us first: use the unsubscribe link in that email. That is the direct way to exercise your right to object under GDPR Art. 21 to the processing described in Section 5, and it applies to every sender at once.
To exercise any of these rights, including after account closure, contact EchoStream SRL at support@transferify.ro. We will handle requests concerning our processing and, where appropriate, coordinate with or forward them to Stripe. Stripe may retain data for its independent legal obligations as described above. You also have the right to lodge a complaint with a supervisory authority. In Romania this is the National Supervisory Authority for Personal Data Processing (ANSPDCP). The governing law and jurisdiction for this Service is Romania / European Union.
9. How we protect your data (security)
We use technical and organizational measures designed to protect your data, including:
- Encryption in transit for connections to and within the Service.
- Client-side encryption of file contents (AES-256-GCM) before hosted uploads, with keys managed via AWS KMS.
- End-to-end encryption for peer-to-peer transfers, so file contents are not exposed to our servers.
- Encryption at rest for hosted files stored in AWS S3.
- Zero-Knowledge mode (paid), where the file key never reaches our servers and we cannot decrypt your files.
No method of transmission or storage is completely secure, so while we work to protect your data we cannot guarantee absolute security.
10. Cookies, analytics and advertising measurement
We use a small number of essential cookies and similar technologies to run the Service, and - only with your consent, and separately for each purpose - Google Analytics 4 for product analytics and Google’s advertising tags for campaign measurement. Until you grant one of those purposes, no analytics or advertising request is sent to Google. Signing in is separate: it is strictly necessary, it uses Google's Firebase Authentication, and it runs whatever you choose here. For details of what we use and how to control it, please see our separate Cookie Policy, which you can open from the same legal menu as this Privacy Policy.
11. Anonymous statistics we count without consent
Two things are counted whichever way you answer the cookie banner - and one of them is counted even if you never answer it at all. The totals themselves are aggregate statistics rather than personal data, so neither is something we ask you to agree to. Your IP address is personal data and does reach us on the way, so GDPR Art. 13 applies to that part - and rather than describe only that part, both counts are set out below in full.
- Your answer to the cookie banner. When you press "Accept all", press "Reject", or save your own selection in "Cookie Settings", we add one tick for EACH of the two purposes we ask about - a decision states both, not only the one you moved - recording for each whether it was granted or denied, and which of those three controls recorded it. That is the entire message: it carries no cookie, no session, no account and no identifier of any kind, and no stored record on our side says what any one visitor answered - only the totals move. A later change of mind is counted as a new decision, so the totals measure decisions rather than people. We count them because a visitor who declines is invisible to every analytics and advertising tag by design - no tag runs to report a refusal - so a first-party count is the only way to know what share of visitors decline.
- How your visit reached us. From the moment you open the site, a coarse acquisition category travels with the requests your browser makes to our servers - one word from a closed list:
paid-search,organic,social,referralordirect. It is worked out inside your browser, from the general kind of site you arrived from and, where the link carries one of Google's advertising click parameters (gclid,gbraidorwbraid), from the bare fact that such a parameter is present. Its value is never read, stored or sent anywhere on this path - only whether one is there at all - and the address of the site you came from never leaves your browser. - What happens to that category, and what it travels beside. We describe this plainly rather than let it sound smaller than it is: the category rides on the requests that already carry your sign-in token, which for a visitor who has not signed in is the temporary anonymous session described in Section 2. So it is not sent as a separate, unconnected message. What it contains is unchanged by that - one word from the list above, and nothing else. We read it at exactly one moment, when an account is first established, and all we do with it is add one tick to a total for that category; on every other request it is ignored and discarded. Nothing is written against your account, no page address is kept, and no total can be traced back to an individual signup. A category we do not receive or cannot recognise is counted as
untrackedrather than guessed at. We count it because the consent-based advertising measurement described in Section 3 can only ever see the people who consented, which makes the picture it gives systematically wrong; this total is what tells us by how much.
What is never collected for these totals. Neither count carries a name, an email address or any identifier of its own, and neither creates anything in your browser: no cookie is set and no storage entry is made for them. No click-identifier value and no page address is collected on either path, nothing about either is recorded against you or your account, and nothing is sent to Google or to any other analytics or advertising provider. The totals are counts and nothing else: they are not used to single you out, and they are never used to build a profile, to target advertising, or to make a decision about you. We will not claim more than that: the acquisition category travels beside your session token as described above, and at very low traffic a banner count and the abuse-limit row described next could in principle fall in the same minute - and, likewise, at very low traffic the minute a channel total moves could in principle be put beside the minute an account was created - which is why that row is deliberately keyed to a network rather than a device: it cannot name a machine, and on its own it cannot name a person.
Your IP address. Like every request to any website, these requests arrive carrying your IP address - the internet does not work otherwise. It is not stored in the clear anywhere on this path and never beside what was counted; ordinary server logs, where kept, are described in Section 7. Where a count arrives as a request of its own, the address is used only to enforce an abuse limit on that endpoint: it is first reduced to the network it belongs to rather than to your individual device, then turned into a keyed one-way hash, and only that hash is kept, next to a request count and a time recorded no more precisely than to the minute. That row records nothing about what you answered or where you came from. It is needed only while the limit's window runs - currently one hour - and a routine sweep removes it afterwards. The sweep works through spent rows at a bounded pace shared with every other protected part of the Service, so a spent row can persist beyond its window - under sustained traffic, considerably longer - until its turn comes; it is not read again in the meantime.
Legal basis. The totals themselves are aggregate statistics and are not personal data, so keeping them needs neither a legal basis nor your consent (GDPR Art. 4(1) and Recital 26). Getting to them does involve personal data: your IP address arrives with every request and, where a count arrives as a request of its own, is used to enforce the abuse limit described above; and the acquisition category travels beside your session token. For both of those we rely on our legitimate interests (GDPR Art. 6(1)(f)) in knowing whether our own measurements are representative and in keeping an endpoint anyone can call usable, weighed against the fact that the address is reduced to a network and hashed before anything is written, and is never stored beside what was counted. You can object to processing based on our legitimate interests at any time - see Section 8; because the totals carry no identifier, we can act on an objection going forward but cannot pick a count already made back out of them.
12. Children
The Service is not directed at children under the age of 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us at support@transferify.ro and we will take appropriate steps to delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you through the Service. We encourage you to review this page periodically.
14. How to contact us
For any questions about this policy or your personal data, contact EchoStream SRL at support@transferify.ro, or by writing to our registered office at Str. Soporului nr. 8, bl. C, sc. 1, ap. 8, 400482 Cluj-Napoca, Romania.