Zapload

Privacy Policy

Last updated: April 1, 2026

1. Information We Collect

When you use Zapload, we may collect the following types of information:

  • Account information: Username and hashed password when you create an account
  • File metadata: File names, sizes, MIME types, upload dates, and download counts
  • Usage data: Pages visited, features used, and general interaction patterns
  • Technical data: IP address, browser user agent, and referrer information (collected during file downloads for analytics)
  • Cookies: Authentication cookies to maintain your session

2. How We Use Your Information

  • Provide, maintain, and improve the Service
  • Authenticate users and protect accounts
  • Generate download statistics and analytics for file owners
  • Enforce rate limits and prevent abuse
  • Comply with legal obligations

3. Storage Architecture & Data Isolation

Zapload operates on a strict stateless streaming philosophy. Data is handled through a zero-knowledge, sharded delivery architecture designed to eliminate centralized points of failure or mass exposure:

  • Distributed Chunk Storage Mesh: Ingested files are split into encrypted segments and distributed across independent storage clusters. Raw, unsegmented files are never stored in a single centralized repository or on application servers.
  • Client-Side Zero-Knowledge Encryption: When encryption is active, files are encrypted via AES-256-GCM directly in your browser using the Web Cryptography API before transmission. Decryption keys remain exclusively within the URL hash fragment and never touch our servers or edge routing network.
  • Private Vaults & Self-Custody (BYOS): Users who connect private storage tokens retain 100% custody of their payload shards. In this mode, raw streams route directly into your private isolated endpoints, bypassing shared nodes entirely.
  • Ephemeral Edge Reassembly: Global edge delivery workers dynamically reassemble and stream chunks directly to the downloader on-demand, operating with zero local disk persistence.
  • Stateless Execution & Transient Verification: Application routing executes on ephemeral serverless compute with volatile in-memory caching for cryptographic session validation and abuse mitigation.

4. Data Sharing

We do not sell, rent, or trade your personal information. We do not share your data with third parties except as necessary to provide the Service (as described above) or when required by law.

5. Data Security

We implement reasonable security measures to protect your information, including hashed passwords, HTTPS encryption, and secure cookie handling. However, no method of electronic storage or transmission is completely secure. We cannot guarantee absolute security of your data.

6. Data Retention

Account data is retained for as long as your account is active. Files with expiration dates are automatically removed after the set period. Download analytics are retained indefinitely for statistical purposes. You may delete your files at any time through the dashboard.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data and account
  • Object to or restrict processing of your data

To exercise these rights, you can manage your data through the dashboard settings or contact us directly.

8. Children's Privacy

Zapload is not intended for users under the age of 13. We do not knowingly collect personal information from children. If we become aware that a child under 13 has provided us with personal information, we will take steps to delete such data.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Changes take effect immediately upon publication. We encourage you to review this page periodically. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.