We do not host your files.

MirrorUploadX is a transfer and link-management service. Files pass through a temporary staging area, are distributed to the third-party hosts you choose, and the staging copy is deleted afterwards. Your files live on those third-party hosts, not with us.

Privacy Policy

Last updated: 2026-08-01

This Policy explains what personal data MirrorUploadX collects, why, and your rights. A central point: we do not retain your files — they pass through transient staging and are deleted after distribution.

1. Who we are

MirrorUploadX operates this transfer and link-management service and is the controller of the personal data described here. Contact us at [email protected].

2. Data we collect

Account data: your email address, authentication data (password hashes, 2FA settings), and roles.

Upload metadata: file name, size, MIME type, scan result, chosen providers, job and share status, and timestamps. This is metadata about the transfer — not the file contents kept long-term.

Technical data: a hashed form of your IP address for sign-in and abuse signals, request logs, and security events. For uploads we additionally record the uploader IP address, browser user agent and country, in a non-hashed form, so that we can act on abuse and copyright complaints. The uploader IP address is cleared automatically after the period stated in Retention below; the country code and browser user agent stay with the upload record for as long as the upload exists in your account, and deleting your account deletes them with it.

Connection data: if you connect a provider, we store your provider API key encrypted (AES-256-GCM); it is never displayed back to you.

3. How we handle your files

Your file is placed in a temporary staging area only for as long as needed to distribute it to your chosen providers — and, where virus scanning is enabled, to scan it first. After distribution completes (or fails past retry), the staging copy is deleted under our retention policy.

We do not keep a durable copy of your file, we do not read its contents beyond automated virus scanning where that is enabled, and we do not use it to train models or for advertising.

4. How we use data

To provide the service (staging, scanning, distribution, share pages), to secure it (abuse prevention, rate limiting, fraud), to communicate with you (verification, security, service notices), and to meet legal obligations.

We do not sell your personal data.

5. Legal bases (GDPR/UK GDPR)

We rely on: performance of our contract with you (to run the service, including the notifications about your own transfers, which you can switch off); our legitimate interests (security, abuse prevention, improving the service); and legal obligation (responding to lawful requests and copyright notices).

We do not rely on consent, because we set no non-essential cookies and send no marketing email. If we ever need consent for something, we will ask for it separately and you will be able to withdraw it.

6. Sharing and sub-processors

We use vetted sub-processors for hosting infrastructure, transactional email, and object storage. They act on our instructions under data-processing terms. A current list is available on request.

The third-party file hosts you choose are independent controllers of the file copies you send them; their handling is governed by their own policies.

We may disclose data where required by law or to protect rights, safety, and the integrity of the service.

7. International transfers

Where data is transferred across borders, we use appropriate safeguards such as standard contractual clauses.

8. Your rights

Subject to law, you may access, correct, export, or delete your data, object to or restrict certain processing, and withdraw consent. You can export your data and delete your account from the Security page in your dashboard.

You also have the right to complain to your local data-protection authority.

9. Retention

Staging file copies: deleted 24 hours after the distribution job reaches a final state (completed, partially completed, failed, or quarantined). A cleanup job runs every 6 hours.

Uploader IP address: cleared 90 days after the upload. We keep it unhashed until then only so that we can act on abuse and copyright complaints. After it is cleared, the country code and browser user agent remain — on their own they do not identify you.

Request log: when a request fails or is unusually slow, we store one line about it — the endpoint, the status, how long it took, the error code, your IP address and country. The default retention is 14 days and it is configurable by the operator; when it lapses the whole line is deleted, IP included. We added this because when a request failed we previously had no way to see why, which meant we could not fix it either.

Visit counts: for every request we add one to a daily counter, keyed by the endpoint pattern, the referring site name, and your country. No IP address, no session or visitor identifier, and no page addresses are kept, so these counts cannot be traced back to a person and we cannot tell how many distinct people visited — only how many requests arrived. We added this because after a launch we could not answer the simplest question: did anyone actually come.

Account and metadata: kept while your account is active and for a limited period afterwards as needed for legal, security, and accounting purposes, then deleted or anonymized. Deleting your account deletes your upload records with it.

10. Security

We use encryption in transit, encryption of stored provider credentials, access controls, and audit logging. No system is perfectly secure, but we work to protect your data and to notify you of incidents where required.

11. Data breaches

If a personal data breach occurs, we assess it without undue delay. Where the breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware of it, as required by Article 33 GDPR.

Where the breach is likely to result in a high risk to you, we also inform you directly and without undue delay, describing what happened, what data was involved, what we are doing about it, and what you can do (Article 34 GDPR).

We keep an internal record of breaches, including those we are not required to report.

12. Children

The service is not directed to children below the age of digital consent, and we do not knowingly collect their data.

13. Changes and contact

We may update this Policy; material changes will be signposted.

Contact [email protected] for privacy requests or to reach our data-protection contact.