Privacy policy.
Last updated: February 18, 2026. This policy explains what we collect, why we collect it, how long we keep it, and the controls you have.
1. Introduction
SendMe ("we", "us", "our") is operated from Delhi, India. We provide a file-transfer service at sendme.co.in. This privacy policy applies to all visitors and registered users of the service, regardless of where they are based. It explains what personal data we process, the legal bases on which we rely, the rights you have, and how to exercise them.
We've written this in plain English on purpose. If anything is unclear, write to privacy@sendme.co.in and we'll explain.
2. What we collect
For each file transfer we store:
- The file content itself, until it expires.
- Metadata: filename, size, content-type, expiry timestamp, created-at timestamp.
- An optional bcrypt hash of the password you set (we never store passwords in plain text).
- The 6-digit code we generate to identify the transfer.
For registered accounts we additionally store:
- Email address and display name.
- For email/password sign-up: a bcrypt hash of your account password.
- For Google sign-in: the Google user identifier returned to us by Google.
- For team workspaces: the mobile number you verify, the role you hold, and the workspace identifiers.
- Subscription and billing metadata (plan, status, last-renewal date). Razorpay handles all payment-card data; we never see card numbers.
We also collect minimal technical telemetry from your browser: IP address (used only for rate limiting and abuse prevention, hashed and rotated after 30 days), user-agent string, and pageview events through Google Analytics 4.
3. What we never collect
We do not sell your data. We do not run third-party advertising trackers (the only third-party tag on our site, AdSense, only loads on /blog pages, and we serve non-personalised ads to EU visitors by default). We do not browse the content of your files. We do not use your file content to train machine-learning models. We do not share data with brokers.
4. How we use the data
The data we collect is used to:
- Deliver the file from sender to receiver and authenticate the 6-digit code lookup.
- Enforce expiry, rate limits, and acceptable-use rules.
- Operate the account features you signed up for — transfer history, team workspaces, billing.
- Detect, investigate, and prevent fraud and abuse.
- Comply with legal obligations including taxation, fraud reporting, and law-enforcement orders.
- Improve the service using aggregated, non-identifying analytics.
5. Legal basis (GDPR users)
For visitors in the European Economic Area, United Kingdom, and Switzerland, we process data under the following legal bases:
- Contract (Art. 6(1)(b)) — for anything we need to do to provide the service you've signed up for.
- Legitimate interests (Art. 6(1)(f)) — for fraud prevention, security, and minimal product analytics that don't override your rights.
- Consent (Art. 6(1)(a)) — for the AdSense ads on /blog and the optional analytics cookies. You can withdraw consent anytime via the cookie banner.
- Legal obligation (Art. 6(1)(c)) — for retaining billing records as required by Indian tax law.
6. How long we keep data
Different categories of data are retained for different periods:
- File content: until the transfer expires (1 hour to 7 days), plus up to one hour for the deletion process to complete.
- Transfer metadata: anonymised after the file is purged; aggregated form retained for analytics.
- Account data: while your account is active, plus 30 days after deletion for backup rotation.
- Billing records: 8 years, as required by Indian tax law.
- Hashed IP addresses: 30 days, for abuse prevention.
- Server logs: 14 days.
7. Where we store data
File content is stored on encrypted object storage in Asia-South (Mumbai region). Database content (accounts, metadata) is stored in MongoDB Atlas, also Asia-South. Payments are processed by Razorpay in India. SMS OTPs are delivered through MSG91 in India. Google Analytics 4 data is processed by Google globally (typically routed to EU or US data centres based on your location).
Cross-border transfers to the EU and US rely on standard contractual clauses with our processors, plus our own data-minimisation practices.
8. How we secure data
Files are transferred over HTTPS (TLS 1.3) and stored with AES-256-GCM encryption at rest. Account passwords are stored as bcrypt hashes. Transfer passwords are stored as bcrypt hashes. Storage paths are non-guessable UUIDs and never exposed to receivers. Access to production systems is restricted to a small number of named employees with hardware-token authentication. We log all access for audit purposes.
For a deeper technical writeup of our security model, see /security.
9. Your rights
Depending on where you live, you have some or all of the following rights:
- Access: a copy of the personal data we hold about you.
- Rectification: correction of inaccurate or incomplete data.
- Erasure: deletion of your account and associated data ("right to be forgotten").
- Restriction: limit our processing of your data while a dispute is resolved.
- Portability: a copy of your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: at any time, for processing that relies on consent.
To exercise any of these rights, write to privacy@sendme.co.in. We respond within 30 days and don't charge a fee for reasonable requests. You also have the right to complain to your local data-protection authority.
10. Cookies and tracking
We use a small number of cookies:
- Strictly necessary — to keep you signed in (session cookie, HttpOnly).
- Analytics — Google Analytics 4 (_ga, _ga_*) to count pageviews. You can opt out via the cookie banner.
- Advertising — Google AdSense loads only on /blog pages and only after consent. Non-personalised ads by default for EU visitors.
We do not use third-party tracking pixels, marketing-attribution beacons, or session-replay tools.
11. Children's data
SendMe is not directed to children under 13. The anonymous features can technically be used by anyone with a browser, but account features (sign-up, paid plans, team workspaces) are restricted to users 18 and over. We don't knowingly collect data from children under 13 and will delete any such account on notice.
12. Changes to this policy
We may update this policy as the product or applicable laws evolve. The "Last updated" date at the top reflects the most recent change. Material changes will be flagged in-app at least 14 days before they take effect.
13. Contact us
Privacy questions, requests, and complaints all go to privacy@sendme.co.in. For postal mail, contact us through the form at /contact and we'll share an address suitable for the specific purpose.