Our Privacy Promise
We built BurritoShare with one core principle: Your files are none of our business.
This isn't just a tagline - it's architected into how our service works. Files transfer directly between users, never touching our servers. We couldn't spy on your files even if we wanted to (and we don't).
1. Information We Don't Collect
Let's start with what we DON'T have access to:
- The contents of your files
- File names or file types
- Personal information about file recipients
- Your email address (no account needed!)
- Your real name or identity
- Payment information (it's free!)
2. Information We Do Collect
To make the service work, we collect minimal metadata:
- Bundle creation timestamp
- Bundle name (what you choose to call it)
- Total bundle size
- Transfer completion status
- Basic analytics (page views, not tied to individuals)
3. How Peer-to-Peer Protects Your Privacy
BurritoShare uses WebRTC technology to create direct connections between browsers:
- Files travel directly from sender to receiver
- Data is encrypted end-to-end during transfer
- Our servers only help establish the initial connection
- Once connected, we're completely out of the loop
4. Cookies and Tracking
We use minimal cookies:
- Session cookies to maintain transfer state
- No third-party tracking cookies
- No advertising networks
- No social media pixels
- Analytics via Mixpanel to improve the service (see below)
Analytics Tracking
We use Mixpanel to collect anonymous usage analytics. We track:
- Page views and navigation patterns
- When share links are created (not the file names)
- Transfer initiation and completion events
- Transfer performance metrics (speed, duration)
- File sizes and types (e.g., "PDF", not the actual content)
We never track: file names, file contents, user identities, or any personal information.
5. Data Retention
We keep minimal data for minimal time:
- Bundle metadata (name, size, timestamps): Automatically deleted after 4 hours
- No file contents are ever stored
6. Third-Party Services
We use these services to operate:
- STUN/TURN servers: Help establish peer connections (can't see file contents)
- Web hosting: Serves the website (doesn't touch your files)
- Mixpanel: Anonymous usage statistics - their privacy policy
7. Security Measures
- HTTPS encryption for all web traffic
- Secure WebSocket connections for signaling
- No file data to protect (by design!)
- Regular security updates and monitoring
8. Your Rights
Since we don't know who you are, there's no account to delete, no personal data to export, and no profile to correct. Complete anonymity by default.
9. Children's Privacy
BurritoShare doesn't knowingly collect data from anyone, including children. Since we don't collect personal information, we can't determine users' ages.
10. International Users
BurritoShare works globally. Since files transfer directly between users and we don't store data, there are no complex international data transfer issues.
11. Law Enforcement
If law enforcement contacts us, we can only provide the minimal metadata we have. We cannot provide file contents (we never have them) or identify users (no accounts).
12. Policy Changes
If we update this policy, we'll post changes here with a new date. We'll keep the same privacy-first principles and never start collecting file contents.
13. Contact
Questions about privacy? Contact us through our website.
Quick Summary
- ✅ We see: Bundle name, size, and timestamp
- ✅ We don't see: Your files, your identity, anything private
- ✅ Data retention: 4 hours, then deleted
- ✅ Who we share with: Nobody