Privacy Policy
Last updated: September 19, 2026
1. What we collect
Quably collects the minimum data necessary to operate the service.
- Quably Drop: We store the files and text you upload, along with your chosen expiry time and a hashed version of your IP address for rate-limiting purposes. We do not store your raw IP address.
- Quably Tools: Most tools run entirely in your browser. No input data is sent to or stored on our servers.
- Server logs: Standard web server logs (request path, timestamp, hashed IP, HTTP status code) are retained for up to 7 days for security and debugging purposes.
2. How we use your data
- To deliver the drop you created to the recipient
- To enforce rate limits and prevent abuse
- To diagnose and fix technical errors
We do not sell, share, or monetise your data. We have no advertising partners.
3. Data retention
Drop content (files and text) is automatically and permanently deleted when the drop expires. Expired drops are purged from our servers on a regular automated schedule.
Rate-limit records are deleted after their time window (1 hour) closes.
4. Cookies and tracking
Quably uses a single session cookie to manage CSRF protection (form security). It is a functional cookie and does not track you across websites. We do not use advertising cookies, third-party tracking scripts, or analytics beacons.
5. Security
Uploaded files are stored in a non-public directory with PHP execution disabled. Downloads are served through an authenticated PHP handler, not as direct file URLs. All database queries use parameterised statements to prevent SQL injection.
6. Your rights
Because we do not require an account, we cannot identify which drop belongs to which person after the fact. If you created a drop and need it deleted early, contact us with the drop code and we can delete it manually.
7. Contact
For any privacy-related questions, email privacy@quably.in.