Skip to content

Privacy Policy

Just Save It has no accounts, so there is very little about you to collect in the first place. This page says exactly what is stored, where, for how long, and what is never gathered at all.

Last updated — 20 September 2026

The short version

We do not ask for your name, email address or phone number, and there is no advertising on this site. We do use Google Analytics to count visits, which sets cookies and tells Google which pages were opened. What we hold is the content you choose to upload, for as long as you choose to keep it. That content is not end-to-end encrypted, so treat the service as convenient rather than confidential.

Who is responsible

This policy covers the Just Save It website and service, operated by Just Save It. For any question about it, or to make a request about your data, write to privacy@justsaveit.online.

What we store

Only these things, and nothing else:

  • The content of a drop. The text you type and the files you upload, up to 25 MB per file. Stored on our database server so that the link works from any device.
  • A password hash, if you set one. Hashed with scrypt and a random per-drop salt. The password itself is never written to disk and cannot be recovered from the hash — if you forget it, the drop cannot be opened by anyone, including us.
  • Technical facts about the drop. Its short code, when it was created and last changed, when it expires, whether burn-after-read is on, and a count of how many times it has been opened. The view count is a number only — it records no detail about who opened it.

What we do not collect

  • No account, name, email address or phone number — there is nothing to sign up for.
  • No advertising pixels, no ad networks, and nothing sold or passed to data brokers.
  • No profile linking one drop to another, and no drop content of any kind sent to analytics.
  • Fonts are self-hosted rather than loaded from a font CDN.

IP addresses

When someone submits a password for a protected drop, the request’s IP address is used as a rate-limiting key so that passwords cannot be guessed by brute force. It is held in the server’s memory for a short window and is never written to our database, never linked to a drop’s content and never shared.

Separately, our hosting provider and database provider keep their own operational logs, which ordinarily include IP addresses, in line with their own retention policies. That is standard for any website and is outside our control.

Analytics

This site uses Google Analytics, so that we can tell whether anyone is actually using it. It records page views, the page you arrived from, your approximate location from your IP address, and broad device and browser details. Google processes this on our behalf and it is not shared with anyone else.

Two limits are worth stating. The contents of a drop — your text, your files, their names — are never sent to analytics. And because a drop’s URL is its key, any address beginning /r/ is replaced with /r/(redacted) before it is reported, so a working link to your transfer cannot reach Google through this route.

If you would rather not be counted, blocking cookies for this site, using a content blocker, or installing Google’s opt-out browser add-on will all stop it. Nothing on the site stops working if you do.

Cookies and browser storage

Three mechanisms are used: two that the service needs in order to work, and one for the analytics described above.

  • An unlock cookie. Setting the correct password on a protected drop stores one signed, httpOnly cookie scoped to that single drop, so you are not asked again on every file. It expires after 12 hours and contains no personal data.
  • Local storage in your browser. Your list of recent drops and your light/dark preference are kept in your own browser. They are never transmitted to us. Clearing your site data removes them, and we never held a copy.
  • Google Analytics cookies. Set by Google to tell repeat visits apart from new ones. They hold a randomly generated identifier rather than anything about you, and expire after up to two years. Clearing your site data or blocking cookies removes them.

How long we keep things

You set the lifetime on every drop: 1 hour, 24 hours, 7 days, 30 days, or never. Seven days is the default, and burn-after-read shortens it to ten minutes from the first time the drop is opened.

Expiry is enforced by the database itself through a time-to-live index, which removes the drop record and its file data rather than merely hiding them from the interface. Drops set to “never” are kept until you delete them or we remove them under the Terms & Conditions. Ordinary provider backups may retain a copy for a short period after deletion before rotating out.

Who else can see your content

  • Anyone with the link. That is the design. A drop is not listed anywhere and its code is not guessable, but it is not a secret either — treat the link as the key, and add a password when the content warrants one.
  • Our infrastructure providers. The service runs on third-party hosting and a third-party managed database. They process data on our behalf in order to run the service.
  • Google Analytics. Receives page views and the technical details listed under Analytics above. It never receives the contents of a drop, and drop addresses are redacted before they are reported.
  • A live-sync server, where enabled. If real-time collaboration is switched on for this deployment, drop updates pass through a separate synchronisation service. It is optional and the service works fully without it.
  • Nobody else. We do not sell or rent your content or your data, and none of it goes to advertisers or data brokers. Beyond the providers named above, nobody else receives it.

Encryption, stated plainly

Traffic between your browser and the service is encrypted in transit over HTTPS, and stored content is protected by our providers’ encryption at rest. But content is not end-to-end encrypted: it is held in a form the server can read, which is what allows a plain link to work on any device without a secret embedded in it.

A password controls who may open a drop. It is not a key that we lack. If it would genuinely harm you for the operator of a service to be able to read something, please use a tool built around end-to-end encryption instead of this one.

Your rights

Because there is no account, the fastest route is usually direct: open a drop you created and delete it, or let its expiry run out. If you need something else — access to what is held about a drop, correction, or erasure before expiry — write to privacy@justsaveit.online with the drop’s short code. Depending on where you live you may also have a right to complain to your national data-protection authority.

Please note that having no accounts cuts both ways: we usually cannot verify who created a drop, so for anything beyond deletion we may only be able to act on a request from someone who can demonstrate knowledge of the code and password.

Children

The service is not directed at children under 13, and we do not knowingly collect data from them. Since no personal data is requested from anyone, this rarely arises, but if you believe a child has uploaded personal information, tell us at privacy@justsaveit.online and we will remove it.

Changes to this policy

If this policy changes, the date at the top of the page changes with it. Material changes will be summarised here rather than slipped in quietly. Continuing to use the service after a change means you accept the updated policy.