Privacy policy.
FileCamel is built so that sending a file does not require telling us who you are. This page is the whole of what we hold, and what happens to it.
Last updated 2 September 2026
- Sending a file needs no account, and we do not ask for one.
- We do not open your files, and we do not sell anything to anyone.
- There are no advertising or analytics trackers on this site.
- Files are deleted when the link expires. There is no backup.
- The management code is sent to us when you use it — see below.
FileCamel operates the file-sharing service at filecamel.com. For anything about this policy, or to ask what we hold about you, write to [email protected]. A complaint about how data is handled goes to [email protected]: acknowledged within 24 hours, resolved within 15 days.
No account is involved, so there is no name or address attached to an upload. What is recorded against the link itself is:
- The IP address that created the link, and the time.
- File names, sizes and types.
- A SHA-256 fingerprint of each file — see the malware check below.
- How many times the link was opened, and when it was last opened.
- The expiry you chose, and any abuse reports made against it.
The IP address is kept because it is the only thing that lets a link be traced back after a takedown notice, and because uploads and downloads are rate-limited per address. It is never shown to anyone downloading your files.
An account adds your email address, and a list of the links you have made — their names, sizes, expiry, and how often each was opened. Passwords are stored hashed by our authentication provider; we never see them.
The list is the links, not their keys. The management code that lets a link be renamed or deleted early is never written to your account — see below for where it does go.
The code shown once when you make a link is stored in your own browser, and we never write it to your account. It is sent to us over HTTPS whenever you use it — deleting a link, renaming one, setting or changing its password, checking its statistics, or finishing an upload — because that is what proves the link is yours to change.
What the server keeps is not the code: it is a scrypt hash of it, salted per link, which cannot be turned back into the code. A submitted code is compared against that hash and then discarded. It is never written to a log, never put in a URL, and never sent to anyone else. Lose it and no one can recover it for you — that is the cost of it not being kept.
We do not read, index or analyse the contents of what you upload, and we do not use it to train anything. Nothing classifies a file by what is in it, and nothing looks at an image. Files sit in object storage and are handed back to whoever holds the link.
Two things about a file are looked at, and neither is its contents: the name's extension, which is checked against a list of types this site does not accept, and the SHA-256 fingerprint described below. Both happen without the file being opened.
After an upload we calculate a SHA-256 fingerprint of each file and ask VirusTotal whether it has seen that fingerprint before. Only the fingerprint is sent — never the file, never its name, and never anything identifying you. A fingerprint cannot be turned back into a file. If VirusTotal has not seen it, the answer is simply that it does not know it, and nothing is uploaded to them.
Card payments go through Dodo Payments, who act as the merchant of record. Card details are entered on their systems and never reach ours — we receive only a confirmation that a subscription started, renewed or ended, tied to your account.
Cryptocurrency payments go through NOWPayments. They tell us which order was paid and whether it settled; we do not receive a wallet address, and there is nothing to charge again, so a crypto purchase runs for what it bought and then stops. Both providers are outside India, so a payment involves your data crossing a border — that is what paying online through a processor means, and it is the only part of this service where it happens.
Payments are not refundable. That is a term of sale rather than a privacy matter, and it is set out in full in the terms and conditions.
There is one kind: the cookie that keeps you signed in. It is set only once you sign in, and cleared when you sign out. There are no advertising cookies, no analytics cookies, and nothing shared with a third party for tracking — which is why this site has never shown you a consent banner.
Your browser also keeps your own upload history and management codes in local storage on your device. We cannot reach into that store — nothing on this site reads it, and it is not sent anywhere on its own.
If you have an account we send you: a confirmation link when you sign up, a welcome message when you confirm it, a note when you use up an allowance on the free plan, and a note when you buy Premium. Each is sent once. We do not send marketing email, and there is no mailing list to be on.
- Files — deleted when the link expires, or immediately if you delete the link yourself. Once deleted they are gone; there is no backup to restore them from.
- The record of a link — its code, sizes, expiry and the IP that made it outlive the files briefly, so the page can say the link expired rather than simply breaking.
- Your account — until you ask us to delete it.
- Abuse reports and takedown correspondence — for as long as we may need to show why something was removed.
- Payment records — kept by the payment provider on their own schedule, and by us for as long as tax and accounting law requires. These are not deleted on request.
- Server logs — request logs rotate on the server and are not kept as a long-term record.
One exception, and it is real. Where the law requires something to be preserved — a police or court order, or a statutory preservation duty attached to material we have removed — that record is held for as long as the requirement lasts, even if the link has expired or the account has been closed. It is kept apart, it is not used for anything else, and it does not extend the life of anything the request does not cover. Deleted files are the one thing no order can reach after the fact: they are already gone, and there is no copy.
Only the companies that run the infrastructure this site is built on, each doing one job: a hosting provider for the server, a storage and network provider for the files, a database and sign-in provider for accounts, an email provider for the messages listed above, a payment provider for Premium, and a malware-lookup service for the fingerprint check described above. None of them are given the data for their own purposes.
We do not sell personal data, and we do not share it for advertising. We will hand over what we hold where we are legally required to — the abuse page sets out what that amounts to in practice, which is less than most people expect, because there is no identity attached to an upload.
Write to [email protected] and you can ask for a copy of what your account holds, ask for it to be corrected, or ask for the account and everything on it to be deleted. You can delete any individual link yourself at any time, without asking us.
An anonymous upload is harder: with no account, nothing ties it to you, so we cannot confirm from an email alone that a link is yours. If you still hold the link, you can delete it yourself from the browser that made it.
FileCamel is not intended for anyone under 13, and accounts are not knowingly created for them.
If this policy changes, the date at the top changes with it.
Abuse, copyright and law-enforcement requests go to [email protected] — see the abuse page. Everything else goes to [email protected].