A private space to share files on the web

WebShare Space Privacy Policy

Last Updated: June 23, 2026

This Privacy Policy explains how DK Lab, LLC ("DK Lab," "we," "us," "our") handles your information when you use WebShare Space web app, related mobile apps, and services (the "Service"). The Service is available as a common, multi-tenant service at webshare.space, and as a private service on a custom domain for organizations with specific requirements. This policy covers both, noting differences where they exist.

WebShare Space is built by a small team that believes privacy is not a feature — it's the architecture. The Service encrypts your files on your device before they reach our servers. We don't require accounts, we don't collect personal information such as names, phone numbers, email addresses, and we don't have the cryptographic keys to read your content. This policy explains exactly what we collect, what we don't, and how we handle it

1. What We Collect

1.1. Information You Provide

When you use WebShare Space, the Service creates a private space for you — a temporary, encrypted container for your files and message. In the space, you upload files and a message ("Content") to share with your recipients. Your Content is always protected by an access code, which can be securely generated or manually set by you. Your space along with your Content expires and is automatically deleted at the expiration time. You can set the expiration time, or use the default.

Our servers collect the following information you provide:

Your encrypted Content — Your Content is encrypted on your device. Only encrypted Content reaches our servers.
A hash of your access code — For convenience, you can choose the access code to be in the URL fragment (the part after the "#" symbol) of the sharing link so that you only need to share the link. URL fragments are not sent to servers — they stay in the browser. Note that the access code in the sharing link may be stored in your recipients' browser history. Regardless of whether it is included in the link, the access code is never sent to our servers. It is stored in your browser session storage and is automatically deleted when you close the browser tab. Only a hash of the access code reaches our servers.
Your expiration time — Expiration time is sent to our servers, so that the Service knows when to delete the space.

1.2. Information Collected Automatically

When you use the Service, our servers may automatically collect:

IP address — used for security, abuse prevention, and rate limiting.
Basic request data, such as timestamps, request type, and file sizes (not file contents) — used for operating the Service and providing features such as upload, download, expiration, etc.
Error and performance data — to keep the Service running smoothly and troubleshoot issues.
We do not collect:
Personally identifiable information, such as names, email addresses, or account information (no account is needed).
Browser fingerprints or device identifiers for tracking purposes.
Browsing history or activity outside the Service.

2. Cookies and Tracking

We do not use cookies, tracking pixels, advertising scripts, or analytics tools that follow you across the web. We do not build a profile from your activity.

Some browsers send a "Do Not Track" (DNT) signal with your requests. Because the Service does not track your activity across websites, your experience is the same regardless of your DNT setting.

3. How We Use Your Information

We use the limited information we collect to:

Operate and improve the Service,
Protect against abuse, fraud, and security threats,
Comply with legal obligations.
We do not use your information to:
Show you ads,
Build a profile about you,
Sell or share your data with advertisers or data brokers.

4. Your Content, Encryption, and Transmission

Your Content is encrypted on your device using the XChacha20-Poly1305 algorithm with a securely generated 256-bit data encryption key (DEK). Unencrypted Content is never transmitted out of your device.

From the access code, the Service derives two values on your device using Argon2id: a 256-bit key encryption key (KEK) for encrypting the DEK, and a hash for verifying the access code. Only the hash and the encrypted DEK are transmitted to our servers.

KEK is never transmitted out of your device.

5. Security Measures

In addition to end-to-end encryption described above, we protect the Service with the following measures:

All connections to the Service are encrypted in transit using TLS 1.2 and newer.
Access to production infrastructure requires multi-factor authentication (MFA).
Production access is limited to a small operations team on a strict need-to-know basis.
Code changes go through review before deployment.
We regularly update dependencies and monitor for known security vulnerabilities.

We continuously evaluate our security practices against industry standards and will expand these measures as the Service grows.

No system is perfectly secure. If you discover a vulnerability, please contact us at the address in the Contact Us section so we can address it promptly.

6. Data Storing and Retention

Here is what the Service stores, where, and when it is deleted. We discuss the Content in separate elements, namely files, file names, expiration time, message, etc. as they are stored differently.

Provided by You (including default and auto-generated values)

WhatWhere StoredWhen Deleted / Retention
Unencrypted filesNoneN/A
Encrypted filesOn the common, multi-tenant service, files are stored in Cloudflare R2. On private services, files can be stored in the customer's choice of storage.Up to 24 hours after expiration, or immediately if manually deleted. Note that even though files may linger up to 24 hours, their encryption key is deleted immediately (see below), effectively cryptographically deleting them.
File names and messageNoneN/A
Encrypted file names and messageThe ServiceImmediately after expiration or manually deleted
Expiration timeThe ServiceImmediately after expiration or overwritten by a different value
Access codeBrowser session storage, browser history (if access code in the sharing link)Immediately when the browser tab is closed. If access code in link, when the recipients' browser histories are deleted.

Computed by the Service

WhatWhere StoredWhen Deleted / Retention
Access code hashThe ServiceImmediately after expiration or overwritten by a different value
DEKNoneN/A
Encrypted DEKThe ServiceImmediately after expiration or overwritten by a different value
KEKNoneN/A

7. Logging

The Service uses two types of logs for its operation, fault tolerance, and troubleshooting.

Debug log: store parts of the requests, such as URL and headers, but no URL fragment and no payload. The debug log is truncated every hour, and the log chunks may be kept up to 30 days before deleted.
Service ledger: store the metadata changes in the Service. It may contain encrypted file names, encrypted messages, expiration times, references to encrypted DEKs, and access code hashes. Service ledger is truncated every hour, and archived up to 6 months in the common, multi-tenant service. On private services, retention can be different, depending on the customer's requirements.

8. Data Location

On the common, multi-tenant service, your metadata Content (e.g., message) is processed and stored on servers located in the United States. Your file Content is stored in Cloudflare's Asia Pacific region and could be cached at edge servers closer to you. On private services, your Content is processed and stored on a location of your choice.

If you access the Service from outside the United States, your request data (such as your IP address and request metadata) will be transferred to and processed on servers in the United States. Because the Service never receives unencrypted Content, the most sensitive part of your data never leaves your control regardless of where you are located.

9. When We Share Information

We do not sell your information. We may share limited information only in these situations:

Legal requirements — when required by law, court order, or government request.
Safety and security — to prevent fraud, abuse, or threats to safety.
Service providers — with trusted providers who help us operate the Service (such as Cloudflare), bound by confidentiality obligations.

Even in response to a legal request, we cannot provide decrypted Content because we do not hold the encryption keys. We can only provide the encrypted data and metadata described in this policy.

10. Children's Privacy

The Service is not intended for children under 16. Since the Service does not require accounts or collect personally identifiable information, we cannot verify the age of our users. We do not knowingly collect personal information from children under 16 - or from anyone.

11. Your Choices and Rights

Since no account or personal information is required, you are in control:

Don't want data on our servers? Delete your files manually. Deleted files are removed from our servers immediately.
Don't want data lingering on our servers? Adjust the expiration. Content is automatically cryptographically deleted when the space expires.
Want extra privacy? Separate access code from the link and send the recipients the access code in a different channel. Additionally, manually set a stronger access code.

This Privacy Policy is governed by the laws of the State of Texas, United States. We respect privacy rights regardless of where you are located and intend for the Service to meet applicable privacy requirements worldwide. Most privacy rights — such as the right to access, and the right to deletion — are satisfied by design. We do not maintain personal profiles or accounts, so there is little personal information to request, correct, or transfer. If you believe you have a privacy concern not addressed here, or we are not meeting an obligation under your local privacy law, please let us know so we can address it.

12. Data Breach Notification

In the unlikely event of a security breach that affects your information, we will investigate and contain the incident promptly, and post a notice on the Service describing what happened, what information was involved, and what steps we are taking. We will notify relevant authorities as required by applicable law.

Because the Service encrypts your Content on your device and we do not hold encryption keys, a breach of our servers would not expose the contents of your files or messages.

13. Changes to This Policy

We may update this Privacy Policy by posting a new version with a new "Last updated" date. Continued use after the update means you accept the new policy.

14. Contact Us

If you have questions about this Privacy Policy, contact us at:

DK Lab, LLC

Email: [email protected]

Website: https://webshare.space