Privacy policy
This policy describes what data Calderbin (the Service) collects, what it is needed for and how long it is kept.
1. What we collect
1.1. Email address — given at registration and used as the login.
1.2. Password — stored only as a cryptographic hash. The original is unavailable to anyone, including us; it can be replaced but not recovered.
1.3. Uploaded files and their metadata — file name, size, upload date, retention deadline.
1.4. Technical request data — the IP address, used to limit the rate of registrations and support messages.
1.5. Support messages and the reply address given in them.
1.6. We do not ask for your name, phone number or payment details, and we do not link accounts to profiles on other services.
2. Why we need it
2.1. Address and password hash — to sign you in and restore access.
2.2. File metadata — to show your file list, count the space used and delete files automatically when their time is up.
2.3. IP address — to resist automated registration and message floods. It is not used to build a profile of a visitor.
3. Who we share it with
3.1. We do not pass data to third parties, do not sell it and do not provide it for advertising purposes.
3.2. The exception is a lawful request from an authorised body, as provided for by law.
4. Advertising and analytics
4.1. There are no advertising slots anywhere on the Service.
4.2. We embed no third-party analytics or counters. Pages load no resources from outside domains.
5. Cookies and local storage
5.1. One technical cookie is used: it carries a signed session identifier so you stay signed in.
5.2. Browser local storage remembers that you dismissed the cookie notice, and which language you chose.
5.3. The Service sets no advertising or tracking cookies.
6. How long data is kept
6.1. Files — 14 days from upload, then deleted automatically along with their metadata.
6.2. Links — 24 hours, after which they stop working and are removed.
6.3. Account data — until the User deletes the account.
6.4. Support messages — up to a year after a reply is sent.
7. Your rights
7.1. You can delete any of your files at any time, and revoke the links to a file by deleting it.
7.2. You can delete your whole account from account settings. The account, its files and its links are removed immediately and cannot be restored.
7.3. You can ask what data we hold about you through the support form.
8. Keeping data safe
8.1. A file is reachable only by its owner and by whoever holds a valid Link. The Service has no shared file catalogue.
8.2. Links carry a random identifier long enough that guessing one is not practical.
8.3. Passwords are hashed with an algorithm designed to resist brute force.
9. Changes to this policy
9.1. The current revision is always published on this page with its date.
10. Contact
10.1. Send questions about data handling through the support form on the site, leaving an address we can reply to.
10.2. The rules for using the Service are in the Terms of use.