Skip to main content

Privacy Policy

End-to-end encrypted file transfer.

Last updated: May 12, 2026

1. Introduction

Tessil ("we", "our", "us") is an end-to-end encrypted file transfer service. This page explains what data we handle when you use the service at tessil.app.

Your files are unreadable to us by design. They're encrypted in your browser before upload, and the decryption key lives in the share link's URL fragment - the fragment never reaches our servers.

You can use Tessil anonymously or with an account. An account adds management features for the transfers you create - it doesn't change how files are encrypted.

2. Data We Collect

2.1 Transfer Data (Encrypted)

When you upload files, they are encrypted in your browser before being sent to our servers. We store:

  • Encrypted file data (we cannot decrypt this)
  • Encrypted file names (we cannot decrypt this)
  • File size, MIME type, and upload timestamp
  • Expiration date you selected
  • Download counter and optional password hash (if you set one)

The encryption key is generated in your browser and lives only in the share link's URL fragment. We never receive or store the key. We cannot decrypt your files.

2.2 Account Data (Only If You Sign In)

Accounts are optional. If you choose to sign in, we collect the following:

  • Email address. Used as the sign-in identifier. Stored in lowercase, indexed for uniqueness, and used to send you a one-time sign-in link.
  • Sign-in records. Hashed sign-in tokens (we store only the SHA-256 hash, never the token itself), the IP address and browser user-agent of each sign-in attempt and active session, and session expiry timestamps.
  • Account tier. Currently always free.
  • Ownership link on transfers. Transfers you create while signed in are tagged with your account ID so they appear on your dashboard. Anonymous transfers carry no such link.

Signing in doesn't change how files are encrypted. Your encryption key never reaches our servers - signed in or not.

2.3 Security and Audit Data

To operate the service, prevent abuse, and meet legal recordkeeping needs, we process:

  • IP addresses (for rate limiting and abuse prevention)
  • Authentication audit events (sign-in requests, sign-in successes, session revocations, transfer deletions, and account deletions) - stored for up to 90 days
  • Basic server request logs (retained for up to 7 days for security purposes)
  • Aggregated lifecycle counters per transfer (file count, total bytes, completion / expiry events) - kept indefinitely with no user attribution and used only for service statistics

2.4 Data We Do NOT Collect

  • We don't collect your email address unless you create an account
  • We don't use tracking cookies, analytics scripts, or marketing pixels
  • We don't sell or share data with third parties for advertising
  • We have no access to the contents or names of your files

3. How We Use Your Data

We use this data to:

  • Provide the file transfer service
  • Send one-time sign-in links and account-related notifications (e.g. confirming an account deletion)
  • Keep your dashboard in sync with the transfers you own
  • Enforce rate limits to ensure fair usage
  • Protect against abuse and maintain service security
  • Automatically delete files after expiration

We do not use your data for advertising, profiling, or any form of automated decision-making with legal or similarly significant effects.

4. Data Storage & Security

Encrypted files are stored on Cloudflare R2 within the European Union. Account metadata and audit records are stored in a PostgreSQL database within the European Union. Security measures:

  • End-to-end encryption (AES-256-GCM) for all file contents and filenames
  • TLS/HTTPS for all data in transit
  • Automatic file deletion after 1, 6, 12, 24, or 72 hours (based on your selection)
  • Sign-in tokens stored only as SHA-256 hashes (we cannot recover the original token)
  • Server-side session cookies marked HttpOnly, Secure, and SameSite
  • No permanent storage of file contents

5. Data Retention

  • Uploaded files: Automatically deleted after 1, 6, 12, 24, or 72 hours (your choice)
  • Account record: Retained as long as your account exists. Deleted immediately and irreversibly when you delete your account from the dashboard.
  • Sign-in tokens (magic links): Valid for 15 minutes, single-use, then deleted.
  • Active sessions: Up to 30 days of inactivity (sliding) and a 90-day hard cap from first sign-in. Revoked sessions are deleted on next cleanup.
  • Authentication audit events: Retained for 90 days, then automatically deleted.
  • Rate limit data: Automatically expires after the rate limit window (up to 30 days)
  • Server logs: Retained for up to 7 days, then automatically deleted
  • Aggregated lifecycle counters: Retained indefinitely. They contain no personal data and no user attribution.

6. Your Rights (GDPR)

Under the General Data Protection Regulation (GDPR), you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate personal data
  • Request deletion of your data ("right to erasure")
  • Object to or restrict certain processing of your data
  • Receive a copy of your data in a portable format
  • Lodge a complaint with your local data protection supervisory authority

Self-service deletion. If you have an account, you can delete it at any time from Settings → Danger zone. Deletion is immediate and permanent: your account, all transfers you own, every active session, and any pending sign-in links are erased, and the email column on historical audit records is scrubbed. We send a confirmation email to your former address once the deletion completes.

Self-service data export. You can download a JSON copy of your account record, recent sign-in activity, and the metadata of the transfers you own from Settings → Your data. The export does not contain the contents of your files - they are encrypted in your browser with a key we never receive.

Anonymous transfers are not tied to an account. The only way to remove them before their expiry is to wait for them to expire automatically, or to email us with the transfer ID at the contact address below.

For any other GDPR request, contact us at the address in section 9. We respond within one month, as required by Article 12(3).

7. Processors and Where Data Is Held

These are every third party that processes data on our behalf, what each one receives, and where it sits.

  • Hetzner (Germany): Runs the application server and its logs. Sees requests to the service. EU company, EU data centre.
  • Scaleway Managed PostgreSQL (Amsterdam, Netherlands): The database holding account records, sessions, and transfer metadata. EU company, EU data centre.
  • Scaleway Transactional Email (France): Sends one-time sign-in links and account notifications. Receives your email address and the message contents. Transactional mail only, never marketing.
  • Cloudflare: Encrypted file storage (R2, restricted to the EU jurisdiction so objects stay in EU data centres), plus CDN and DDoS protection in front of the site. R2 only ever holds ciphertext. Because Cloudflare terminates TLS at its edge, it can see request metadata and your session cookie, but never your decryption key, which stays in the link fragment and is never transmitted.

Cloudflare Inc. is headquartered in the United States, so we do not claim to be beyond the reach of US law. We claim something narrower: your file contents are encrypted in your browser before upload and the key never reaches any server, ours or Cloudflare's. A legal order served on Cloudflare produces encrypted data and metadata, not your files. This transfer relies on Cloudflare's standard data processing terms and its EU data localisation options.

8. Changes to This Policy

We may update this policy. Material changes are reflected in the "Last updated" date at the top of this page.

9. Contact

Questions about this policy or our data practices:

[email protected]