What we know about you, and for how long.
Last updated 17 September 2026
Who is responsible
FileShare is run by Martin Nielsen, Att: mtnielsen, Hovedvejen 158, 4. 27, 2600 Glostrup, Denmark, DK. Questions and requests: contact@mtnielsen.dk.
Your files
Files never touch this server. They travel over an encrypted WebRTC channel straight between the two browsers. We cannot see them, and we do not store anything about them: not names, not sizes, not counts.
Connecting the two devices
While a share link is open, the server relays a handful of connection messages between the two browsers so they can find each other. Those messages contain IP addresses and browser-generated connection descriptions. They live in memory only while the link is in use and are gone when it closes.
On the Relay plan, when a direct connection fails, the TURN relay forwards the encrypted stream between the two devices. It sees IP addresses and encrypted packets it cannot read. It keeps no record of what passed through.
Payments
Relay subscriptions are handled by Stripe. Stripe collects and stores your payment details, email address and billing address under its own privacy policy, acting as an independent controller for that data. We never see your card number.
What we keep is small: the Stripe customer id and subscription id, stored in a signed cookie on each device you activate Relay on and in a short-lived cache on the server so we can check that the subscription is still active. When you use Log in, the email you enter is sent to Stripe to find your subscription and, if one exists, receives a single-use link from our mailbox; we do not store the address. That cookie is strictly necessary for the service you bought, so it needs no consent banner. The only other cookie is a security token that protects the buttons on this site from cross-site abuse; it is strictly necessary and stores nothing about you.
Server and firewall logs
Like every web server, ours logs request and connection metadata: IP address, time, path, browser type. The firewall logs connection attempts it blocks. We keep these logs as long as we need them to rule out a security incident or a legal issue, then delete them.
Where it runs
Everything runs on one virtual server hosted in the EU (Germany). Our processors are Stripe (payments) and the hosting provider (the server itself). No analytics, no tracking, no third-party scripts apart from Stripe's checkout, which loads on Stripe's own domain.
Legal basis and your rights
We handle subscription data to fulfil the contract with you, and logs and connection metadata under our legitimate interest in keeping the service running and secure. Under the GDPR you can ask for access to, correction of, or deletion of your data, including deletion of your Stripe customer record once the subscription has ended. If you are unhappy with how we handle it, you can complain to Datatilsynet, the Danish data protection authority.