Last updated: 7 August 2026
This policy covers snap-drop.net, operated by lilac. It describes this instance
specifically. If you are using a self-hosted copy of SnapDrop, this policy does not apply to
you — ask whoever runs it.
Files you send never reach our server. They go directly from one device to the other, encrypted by your browser. We have no copy, no log of what you sent, and no way to recover it. The server exists to introduce two devices to each other, and that introduction is the only thing it handles. How it works explains the mechanics.
This site does show advertising, which does involve third-party cookies. That part is set out in full below.
Nothing in that list is written to persistent storage by the application. Restarting the server discards all of it.
This instance runs no TURN relay and no WebSocket transfer fallback, so there is no configuration in which transferred data passes through infrastructure we operate. If a direct connection cannot be made, the transfer fails instead.
SnapDrop itself sets no cookies. It uses your browser's local storage, session storage, and
IndexedDB to hold your device identifier, your preferences, pairing secrets, and files handed
to it by the system share sheet. This data stays on your device. Clearing site data for
snap-drop.net removes all of it and unpairs your devices.
stun.l.google.com. This reveals your IP address to Google. It carries no
file data and no information about what you are transferring.
This site uses Google AdSense to fund its running costs. When advertising is active, the AdSense script loads on the application page and the cookies described below may be set.
Ad units are placed outside the transfer area and file data is never passed to them. We should be precise rather than reassuring here: ad code is a third-party script running in the same page as the application, so it has the access that any script in a page has. What we can say concretely is that files are never uploaded, never written to a server, and never handed to advertising code by the application.
If you are in the EEA, the UK, or Switzerland, personalised advertising requires consent collected through a Google-certified consent management platform. That platform is not yet in place on this site, and until it is, no personalised advertising is served to you.
This service is not directed at children under 13, and we do not knowingly collect information from them. Since there are no accounts, we hold nothing that would identify a user's age.
Because we hold no persistent personal data and no accounts, there is generally nothing to export or delete on our side — anything relating to you lives in your own browser, and clearing site data removes it. If you have a question or a request about your data, write to [email protected].
Material changes to this policy will be reflected in the "last updated" date above. Because this page is served fresh rather than cached offline, you always see the current version.