隐私政策

生效日期:2026 年 10 月 1 日

一句话版本:你传输的文件不会经过我们的服务器(Pro 的中转回退除外,且中转不存储文件内容)。我们只在你注册账号、购买套餐或联系客服时,收集为完成这些事所必需的最少信息。

1. 概述

瞬传 FlashSend(以下简称「本服务」,网站 https://flashsend.uk)是一个点对点文件传输工具,由一名位于中国广州的个人开发者运营(以下称「我们」)。本政策说明我们在你使用本服务时收集哪些信息、如何使用与保存,以及你可以如何行使自己的权利。本政策应与服务条款一并阅读。

2. 我们收集的信息

我们只在特定功能下收集信息。逐项如下:

场景收集内容用途
注册 / 登录账号邮箱地址;密码的 PBKDF2-HMAC-SHA256 派生值(每账号独立随机盐)身份识别与登录验证
使用 Pro 权益套餐标识、到期时间、兑换码、开通时间发放与校验付费权益
保持登录状态会话令牌免重复登录(30 天后自动失效)
防止暴力破解登录失败次数计数(按邮箱与来源 IP 分别计数)触发限流,保护你的账号
联系客服 / 兑换码申诉你主动提供的邮箱、订单号、问题说明、截图处理你的请求
免登录使用免费额度一个不含个人身份的匿名标识统计当日传输次数以执行免费额度

我们不会要求你提供真实姓名、身份证件、住址或手机号,也不收集人脸、指纹等生物特征信息。

3. 我们不收集的信息

  • 文件内容——本服务不读取、不上传、不保存你传输的任何文件内容。
  • 文件名与文件大小——仅在传输进行中用于双方协商,传输结束即随房间状态一并销毁,不写入数据库。
  • 通讯录、短信、剪贴板、相册、摄像头——不请求这类系统权限(扫码使用相册是浏览器自身的图片选择器,照片不会上传)。
  • 我们不使用第三方统计、广告或行为追踪脚本;站内不使用 Cookie 做追踪或广告投放。

4. 你的文件如何传输

  • 直连模式:双方通过 WebRTC 建立端到端加密(DTLS)的点对点通道,文件数据在两台设备之间直接流动,不经过我们的服务器。
  • 中转回退模式(Pro 专属):当两端网络无法直连时,数据经 Cloudflare Realtime TURN 服务以加密形式转发。中转只负责转发,不存储文件内容,转发结束不留副本。
  • 我们的信令服务器只转发连接协商信息(SDP / ICE)与传输控制消息(如进度、分片确认),这些内容不包含你的文件数据。

5. 信息如何共享

我们不出售、不出租你的个人信息。仅在以下情形与第三方共享:

第三方角色涉及信息
Cloudflare, Inc.网站托管、信令服务、数据库(Durable Objects)、TURN 中转账号数据存储于其基础设施;中转模式下转发加密数据
Creem支付服务商(记录商户 / Merchant of Record)你购买 Pro 时的姓名、邮箱与支付信息由 Creem 直接收集并处理——我们不接触、不存储你的银行卡号
依法配合法律要求仅在收到合法有效的要求时,按最小必要范围提供

6. 数据保留

数据保留期限
账号信息(邮箱、密码派生值、套餐状态)至你申请注销账号为止
会话令牌30 天,或在你登出、修改密码时立即失效
登录失败计数限流窗口结束后自动过期(最长 15 分钟)
房间与传输状态仅存于内存,房间关闭即销毁
客服往来记录处理完毕后保留 12 个月

7. 设备本地存储

为提升使用体验,本服务会在你的浏览器本地(localStorage)保存以下内容。这些数据存在你自己的设备上,不会随每次请求发送给我们:

键名内容
flashsend.identity.v1本设备的身份密钥对,用于生成安全校验码
flashsend.trusted.v1你标记为「可信」的设备列表
flashsend.token.v1登录会话令牌
flashsend.email.v1上次登录使用的邮箱(仅用于回填输入框)
flashsend.anon.v1免费额度的匿名标识
flashsend.lang.v1界面语言偏好

清除浏览器数据即可删除以上全部内容。

8. 你的权利

你可以随时通过下方邮箱联系我们,行使以下权利:

  • 查询我们持有的与你相关的信息
  • 更正不准确的信息
  • 注销账号并删除账号数据
  • 撤回此前的同意

我们会在收到请求后 15 个工作日内处理并回复。

9. 未成年人

本服务不面向 13 周岁以下儿童。若你未满 18 周岁,请在监护人同意与指导下使用本服务。

10. 政策变更

本政策如有变更,我们会更新本页顶部的生效日期;涉及权利范围的重大变更,我们会在站内显著位置提示。

11. 联系我们

  • 支持邮箱:support@flashsend.uk
  • 运营主体:个人开发者(中国广州)
  • 所在地:中国广东省广州市

Privacy Policy

Effective date: October 1, 2026

The short version: the files you transfer never pass through our servers (the only exception is Pro's relay fallback, and even then the relay does not store file contents). We only collect the minimum information needed when you register an account, purchase a plan, or contact support.

1. Overview

FlashSend (the "Service", https://flashsend.uk) is a peer-to-peer file transfer tool operated by an individual developer based in Guangzhou, China ("we", "us", "our"). This policy explains what information we collect when you use the Service, how we use and retain it, and how you can exercise your rights. Please read it together with our Terms of Service.

2. Information we collect

We collect information only for the specific features listed below:

WhenWhat we collectWhy
Creating / signing in to an accountYour email address; a PBKDF2-HMAC-SHA256 derived value of your password (with a unique random salt per account)Identity and sign-in verification
Using Pro benefitsPlan ID, expiry date, redemption code, activation timeGranting and validating paid benefits
Staying signed inSession tokenAvoiding repeated sign-in (expires automatically after 30 days)
Brute-force protectionFailed sign-in counters (counted separately by email and by originating IP)Rate limiting to protect your account
Contacting support / redeeming a codeThe email, order number, description and screenshots you choose to send usHandling your request
Using the free allowance without an accountAn anonymous identifier that contains no personal identityCounting daily transfers to enforce the free allowance

We do not ask for your real name, identity documents, home address or phone number, and we do not collect biometric data such as face or fingerprint data.

3. What we do not collect

  • File contents — we do not read, upload or store the contents of any file you transfer.
  • File names and sizes — used only transiently during an active transfer so the two peers can negotiate; destroyed with the room state when the transfer ends, never written to our database.
  • Contacts, SMS, clipboard, photo library, camera — we do not request these permissions. (Scanning a QR code uses your browser's own image picker; the image is not uploaded.)
  • We do not use third-party analytics, advertising or behavioural tracking scripts, and we use no cookies for tracking or advertising.

4. How your files travel

  • Direct mode — both sides establish an end-to-end encrypted (DTLS) peer-to-peer WebRTC channel. File data flows directly between your two devices and never passes through our servers.
  • Relay fallback (Pro only) — when the two networks cannot connect directly, data is relayed in encrypted form through Cloudflare Realtime TURN. The relay only forwards traffic; it does not store file contents and keeps no copy after forwarding.
  • Our signalling server only relays connection negotiation data (SDP / ICE) and transfer control messages (such as progress and chunk acknowledgements). None of that contains your file data.

5. How we share information

We do not sell or rent your personal information. We share it with third parties only as follows:

Third partyRoleInformation involved
Cloudflare, Inc.Website hosting, signalling service, database (Durable Objects), TURN relayAccount data is stored on their infrastructure; encrypted data is forwarded when the relay is used
CreemPayment provider (Merchant of Record)When you purchase Pro, your name, email and payment details are collected and processed directly by Creem — we never receive or store your card details
Legal requirementsComplianceOnly in response to a valid, lawful request, limited to the minimum necessary

6. Data retention

DataRetention period
Account information (email, password derivative, plan status)Until you request account deletion
Session tokens30 days, or immediately upon sign-out or password change
Failed sign-in countersExpire automatically after the rate-limit window (15 minutes maximum)
Room and transfer stateHeld in memory only; destroyed when the room closes
Support correspondence12 months after your request is resolved

7. Local storage on your device

To improve your experience, the Service stores the following in your browser's local storage. This data lives on your own device and is not sent to us with every request:

KeyContents
flashsend.identity.v1This device's identity key pair, used to derive the on-screen safety code
flashsend.trusted.v1The list of devices you marked as trusted
flashsend.token.v1Your sign-in session token
flashsend.email.v1The email last used to sign in (only to pre-fill the field)
flashsend.anon.v1Anonymous identifier for the free allowance
flashsend.lang.v1Your interface language preference

Clearing your browser data removes all of the above.

8. Your rights

You may contact us at any time using the email below to:

  • Request a copy of the information we hold about you
  • Correct inaccurate information
  • Delete your account and its data
  • Withdraw a previously given consent

We will respond within 15 business days of receiving your request.

9. Children

The Service is not intended for children under 13. If you are under 18, please use the Service with the consent and guidance of a parent or guardian.

10. Changes to this policy

If this policy changes, we will update the effective date at the top of this page. For material changes affecting your rights, we will post a prominent notice on the site.

11. Contact us

  • Support email: support@flashsend.uk
  • Operator: an individual developer (Guangzhou, China)
  • Location: Guangzhou, Guangdong, China