Security & privacy

How TeraSender protects your files

Encryption in transit and at rest, password-protected links, mandatory expiry, and a commitment that your files are never used to train AI models.

The short answer

TeraSender encrypts files in transit and at rest, lets you lock any download link behind a bcrypt-hashed password, requires an expiry date on every transfer, and permanently deletes files once that date passes. Download URLs are long random tokens excluded from search indexing, transfers can be revoked at any time, and customer files are never used to train AI models.

Security practices

Encrypted in transit and at rest

Transfers travel over TLS and files are encrypted in storage. Chunks are assembled server-side and the temporary chunk files are removed once the upload completes.

Password-protected links

Add a password to any transfer. TeraSender stores a bcrypt hash, never the password. Recipients must enter it before the download starts.

Every link expires

Expiry is mandatory, not optional. You choose the date; the default is 7 days. On expiry the files are deleted from storage and the link stops resolving.

Revoke at any time

Change your mind after sending? Revoke the transfer from your dashboard and the link dies immediately.

Tokenised, unguessable URLs

Download links use long random tokens and are excluded from search indexing in robots.txt, so a transfer is only reachable by someone you gave the link to.

No AI training on your data

Customer files are not used to train AI models and are not shared with third parties for that purpose.

Download visibility

Enable notifications and TeraSender emails you when a recipient downloads, so you know if a link has been used more than you expected.

Guest uploads without accounts

Vouchers let outside parties send you files without credentials, so you never share a login to collect a delivery.

What we store, and for how long

DataWhy it existsRetention
Uploaded filesTo deliver the transfer to your recipientDeleted when the transfer expires
Transfer metadataFilenames, sizes and download counts shown in your dashboardRetained with your account for the audit trail
Link passwordTo gate the downloadStored only as a one-way bcrypt hash
Account detailsSign-in, notifications and billingUntil you delete your account

Frequently asked questions

Is TeraSender secure?

Yes. TeraSender encrypts files in transit and at rest, supports bcrypt-hashed passwords on download links, enforces an expiry date on every transfer, and permanently deletes files once a transfer expires. Files are never used to train AI models.

Does TeraSender use my files to train AI?

No. TeraSender does not use customer files, filenames, or transfer metadata to train AI models, and does not sell or share them with third parties for that purpose.

How does password protection work on a TeraSender link?

When you enable encryption on a transfer you set a password. TeraSender stores only a bcrypt hash of it, never the password itself, and the recipient must enter it before the download begins. Because the hash is one-way, a lost password cannot be recovered — you would create a new transfer.

How long does TeraSender keep my files?

Only until the expiry date you set, which defaults to 7 days. After a transfer expires, TeraSender removes the files from storage and the download link stops working. Expired directories are cleaned up on a schedule.

Can I revoke a TeraSender link after sending it?

Yes. Open the transfer in your dashboard and revoke it. The download link stops working immediately, even if the expiry date has not been reached.

Is TeraSender GDPR compliant?

TeraSender is built around GDPR-aligned practices: data minimisation, a defined retention period tied to transfer expiry, deletion on expiry, and account deletion on request. See the privacy policy for the full detail.

For the full legal detail see the privacy policy and terms and conditions. Questions about a specific compliance requirement? Contact us.