nullsend
How it works Features Pricing Enterprise Security
Sign in Get started
nullsend
How it works Features Pricing Enterprise Security
Sign in Get started
Legal

Privacy Notice

Last updated: 2 June 2026

This notice explains what personal data Nullsend collects, why, how we protect it, and the rights you have over it. We have written it in plain language rather than legal jargon, because a privacy product should be able to explain itself clearly.

Nullsend Ltd is a company registered in England & Wales with company number 17266592. References to "Nullsend", "we", "us" and "our" mean Nullsend Ltd.

Who we are

Nullsend provides encrypted file transfer. Files are encrypted in your browser before they leave your device, which means our systems only ever hold scrambled data. We cannot read the contents of the files you send. This is not a policy choice we could quietly reverse later; it is how the product is built.

For any privacy question, or to exercise your rights, contact us at privacy@nullsend.io.

The data controller is Nullsend Ltd, a company registered in England & Wales with company number 17266592.

What we collect, and why

We collect as little as we can. Here is the full picture.

Account and workspace information. When you create an account we collect your email address, a password (which we never store in readable form; it is hashed using Argon2id), your company or workspace name, and the subdomain you choose. We need this to create and secure your account and to provide the service. Lawful basis: performance of our contract with you.

Billing information. Payments are handled by Stripe. We do not see or store your card number. We hold a record that an account is subscribed to a particular plan, and the billing identifiers Stripe gives us. Lawful basis: performance of our contract with you, and our legitimate interest in being paid.

The files you send. We hold your files only as ciphertext. They are encrypted on your device before upload, and the key needed to decrypt them lives in the share link, in the part after the "#", which by web standards is not sent to our servers in normal use. We therefore cannot read, scan, index, or otherwise access the contents of your files, and neither can anyone we work with. One exception, stated plainly: if you choose to have us email a transfer link for you, that link contains the key by necessity (otherwise the recipient could not open it), so it passes through our email system and is held only long enough to send the message. Even then, we cannot read your files. Lawful basis: performance of our contract with you.

Transfer metadata. To run the service we keep records about transfers: file sizes, dates, how many times a file has been downloaded, and the recipient email addresses that a sender enters so we can notify them. We also keep audit logs of who sent what, meaning the fact that a transfer happened and between whom, never the contents. Lawful basis: performance of our contract with you, and our legitimate interest in operating and securing the service.

Security logs, including IP addresses. We log IP addresses only for security and abuse prevention. These are retained for 30 days and then deleted. We do not use IP addresses for tracking, profiling, advertising, or analytics. Lawful basis: our legitimate interest in keeping the service and its users secure.

Bot protection. We use Cloudflare Turnstile to tell humans from automated abuse at login and signup. This involves a check performed by Cloudflare. Lawful basis: our legitimate interest in protecting the service from abuse.

Mobile-app waitlist. If you ask to be notified when our mobile apps launch, we store the email address you give us, plus the date and where you signed up. We use it only to send that one launch notification, nothing else. You can ask us to remove you at any time. Lawful basis: your consent.

What we do not do

We think it is worth being explicit about what we do not collect or do, because for a privacy product the absences matter as much as the presences.

  • We do not use Google Analytics or any third-party analytics.
  • We do not use tracking pixels or advertising trackers.
  • We do not sell, rent, or share your personal data for marketing or advertising.
  • We do not, and cannot, read the contents of the files you send.
  • We do not use your data to train artificial intelligence or machine learning models.

Who we share data with

We do not sell your data. We use a small number of trusted service providers (sub-processors) to run the service. Each only receives what it needs to do its job.

ProviderPurposeLocation
HetznerHosting and infrastructureEuropean Union (Finland)
Backblaze B2Encrypted file storageEuropean Union
StripePayment processingUnited States
PostmarkSending transactional emailUnited States
CloudflareDNS and bot protection (Turnstile)Global network
AnthropicAI onboarding assistant (signup conversation only; never file contents or recipient data)United States

Your account information and the encrypted files are stored in the European Union. Stripe, Postmark, and Anthropic are based in the United States; where personal data reaches them, it is protected by the safeguards those providers maintain for international transfers under UK and EU data protection law (such as Standard Contractual Clauses and applicable data transfer frameworks). The files themselves remain ciphertext throughout, so even our storage and infrastructure providers cannot read them.

We may also disclose data where we are legally required to, for example in response to a valid legal order. Because we hold files only as ciphertext, we cannot produce readable file contents even if compelled to; we can only provide what we actually hold, which is metadata and account information. For how to report a child in danger or child sexual abuse material, and how we act on reports of misuse, see our Child Safety page.

How long we keep it

We keep personal data only as long as we need it.

  • Files are deleted automatically when they expire, on the schedule you set when sending them, or on first download if you choose that option. We do not keep copies after expiry.
  • Account information is kept while your account is active. If you close your account, or ask us to erase your data, we delete it (see your rights below).
  • Security logs containing IP addresses are kept for 30 days, then deleted.
  • Mobile-app waitlist entries are kept until the apps launch and we have notified you, or until you ask us to remove you, whichever comes first. They are erased on request.
  • Backups of our systems are encrypted and held for a limited period for disaster recovery, then rotated out. Data you have erased is removed from active systems immediately and falls out of backups as they rotate.

Your rights

Under UK and EU data protection law you have the right to:

  • Access the personal data we hold about you.
  • Erasure of your personal data. We have built this into the product, you can request deletion, and your data is removed from our active systems.
  • Rectification of inaccurate data.
  • Portability, to receive your data in a usable format.
  • Object to or restrict certain processing.
  • Withdraw consent, where we rely on consent.

To exercise any of these, email privacy@nullsend.io. We will respond within the timeframes required by law (normally within one month).

If you believe we have handled your data improperly, you have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk, or to your local data protection authority in the EU. We would always prefer you contact us first so we can put things right.

Cookies

We use only the cookies necessary to make the service work, such as keeping you logged in and remembering your light or dark theme preference. We do not use advertising or third-party tracking cookies.

Changes to this notice

If we change how we handle your data, we will update this notice and change the date at the top. For significant changes affecting your rights, we will take reasonable steps to let you know.

Contact

Questions about this notice or your data: privacy@nullsend.io

Nullsend Ltd

nullsend

Privacy-first file transfer for business. Built in the UK. Servers in the EU. Files encrypted in your browser.

Product

  • How it works
  • Features
  • Pricing
  • Enterprise
  • Security

Legal

  • Privacy notice
  • Terms
  • DPA
  • Sub-processors
  • Child safety
  • Report abuse
  • security.txt
© 2026 Nullsend Ltd. Registered in England & Wales, company number 17266592.
hello@nullsend.io