toss-it

privacy

last updated: 30 August 2026.

what we don't store

files sent through a toss-it link are streamed directly into the recipient's connected Google Drive. toss-it does not keep a permanent copy of file contents on its own servers at any point in that process.

what we do store
  • account information: your email, name, and a password hash (if you use a password) or a Google account identifier (if you sign in with Google).
  • Google Drive OAuth credentials for accounts you explicitly connect, encrypted at rest, used only to create upload sessions in the folder you choose.
  • upload request metadata: destination folder name, private internal note, sender instructions, expiry, pause state, size limits, optional file-naming template, a one-way authentication digest, and an encrypted copy of an active request token so workspace members can recover or replace the URL.
  • transfer metadata: file names, sizes, status, and timestamps for links you've created, so you can see what was sent to you.
  • security and activity logs (e.g. sign-in attempts, link actions) — see retention below for how long these are kept.
why we process this data

we process account and link metadata because it's necessary to provide the service you asked for — creating links, delivering files to your storage, and letting you manage what you've created. we process security and activity logs based on our legitimate interest in keeping the service safe from abuse. we never process this data to build an advertising profile.

subprocessors

toss-it relies on a small number of third parties to operate: Google (your connected storage and, optionally, sign-in), Vercel and Fly.io (hosting), Neon (our database), Resend (account emails), and the Have I Been Pwned breach-check API. the full list, and exactly what each one can access, is on the security page.

password safety checks

when you create or change a password, toss-it checks it against the Have I Been Pwned Pwned Passwords service using its padded k-anonymity API. only the first five characters of a SHA-1 digest are sent. your password, complete digest, email, and account identity are not sent to that service.

cookies and tracking

toss-it sets one essential, HTTP-only session cookie to keep you signed in — nothing else. there is no analytics, advertising, or cross-site tracking script anywhere on toss-it, so there's no cookie consent banner, because there's nothing non-essential to consent to.

retention
  • file contents: never retained, at any point.
  • security and activity logs: kept for 180 days, then automatically deleted.
  • account, link, and transfer metadata: kept for as long as your account exists, or until you delete a specific link.
who can see what

anyone sending a file through your link never sees your Google Drive contents, your OAuth credentials, or any other data about your account — they can only push a file into the one folder you selected for that link.

your rights and controls
  • revoke any upload link permanently, or pause it temporarily, at any time from your dashboard.
  • disconnect your Google Drive connection at any time — toss-it immediately stops being able to write to it.
  • permanently delete your account from your account settings. this is a real deletion, not a deactivation: it removes your upload links, transfer records, and connected-storage credentials from our database immediately.
  • ask us anything about the data we hold on you, or request a copy of it, by emailing support@toss-it.online.
international data

toss-it's infrastructure is primarily hosted in the United States. if you use toss-it from elsewhere, your data will be transferred to and processed in the United States as part of providing the service.

children's privacy

toss-it is not directed at children and we don't knowingly collect data from anyone under 13 (or the relevant minimum age where you live). if you believe a child has created an account, contact us and we'll remove it.

changes to this policy

we may update this policy as the service changes. the “last updated” date at the top of this page always reflects the current version.

questions

email support@toss-it.online for anything not covered here, or security@toss-it.online to report a security issue.