Back to Home

Privacy Policy — Zero Cloud Data Retention

Last updated: August 2026

Summary of Our Zero-Retention Commitment

Textunnel was engineered from inception with privacy as a foundational constraint. We do not store your files on any cloud servers, we do not monitor or log your clipboard contents, and we do not require account registration or passwords. All file transfers occur directly peer-to-peer (P2P) between your devices over encrypted WebRTC DataChannels.

1. Peer-to-Peer Data Architecture

Textunnel operates strictly as a client-side peer-to-peer utility. When transferring files, photos, 4K videos, or clipboard text between devices on the same local network (Wi-Fi/LAN) or across the internet, payloads stream directly from device A to device B via WebRTC DataChannels.

Your payload data never touches our disks or database systems. It moves directly through ephemeral memory buffers allocated in your device's web browser.

2. Cryptographic Data Encryption

All communications between connected peers are encrypted end-to-end by default using Datagram Transport Layer Security (DTLS 1.2 / DTLS 1.3) and AES-GCM cipher suites.

Cryptographic keys are generated locally within the web browser sandbox of the sender and receiver. Neither Textunnel maintainers nor any intermediate network provider can inspect, decrypt, or tamper with the contents of your transfer.

3. Zero Cloud Storage & Zero File Retention

We operate no cloud file hosting infrastructure, no user file caches, and no historical paste archives. The moment you close the browser tab or terminate a transfer session, all session tokens, ephemeral room identifiers, and in-flight memory buffers are instantly purged from memory.

4. Signaling Server Operations & Metadata

To establish initial WebRTC peer connections (the initial handshake), a lightweight signaling server facilitates the exchange of session metadata (specifically Session Description Protocol / SDP packets and ICE connection candidates).

This signaling exchange is strictly ephemeral and carries only routing parameters. The signaling server never receives, parses, or processes the actual file binary or clipboard payload.

5. Third-Party Advertising and Cookies (Google AdSense Compliance)

We partner with third-party advertising companies, including Google AdSense, to display non-intrusive advertisements that fund our free open-source infrastructure. These advertising partners may use cookies and web beacons to collect non-personally identifiable information:

  • Third-party vendors, including Google, use cookies to serve ads based on a user's prior visits to this website or other websites.
  • Google's use of advertising cookies enables it and its partners to serve relevant ads to users based on their visits to our site and/or other sites across the web.
  • Users may opt out of personalized advertising by visiting Google's My Ad Center.
  • Alternatively, you can opt out of third-party vendor cookies for personalized advertising through the Digital Advertising Alliance (DAA) or the Your Online Choices portal.

6. GDPR & CCPA Compliance Rights

Under the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA), users are entitled to know what personal data is collected and processed. Because Textunnel enforces a zero-account architecture and retains zero user profiles, email lists, or IP access logs, we hold no personal data to disclose, sell, or modify.

7. Privacy Inquiries & Contact

If you have questions, feedback, or security inquiries regarding this Privacy Policy, please contact our team at hello@textunnel.com or visit our Contact Page.

Frequently Asked Privacy Questions

Does Textunnel retain my transferred files on any server?

No. Textunnel utilizes pure WebRTC DataChannels where files stream in transient memory buffers directly between devices. Zero bytes are ever stored or cached on remote hard drives.

Are clipboard text synchronization payloads readable by anyone?

No. All text payloads are encrypted end-to-end using DTLS 1.3 before leaving your browser. Only the paired device possessing the matching ephemeral cryptographic key can decrypt the data.

How does Textunnel comply with GDPR and CCPA?

Under GDPR and CCPA, Textunnel maintains zero user accounts, personal profile databases, or tracking logs. Because we collect and hold no personal identity data, there is zero risk of personal data leakage.

How can I opt out of personalized third-party advertising?

You can manage or opt out of personalized Google advertising anytime via Google My Ad Center (https://myadcenter.google.com/) or the Digital Advertising Alliance choices portal.

100,000+ Files Transferred
0 Server Storage
100% WebRTC Encrypted
Open Source & Free