Legal

Privacy Policy

Last updated: 5 October 2026

The short version: your files are encrypted in your browser and travel directly to the recipient. We never upload, store or read them. This page explains the small amount of account and technical data we do handle.

1. Who we are

P2P Streamer (“we”, “us”) is a browser-based service, operated under the Qovox brand, that lets you send files directly from your device to another person’s device. This policy explains what personal data we handle, why, and what your choices are.

Questions or requests about your data: qovox222@gmail.com.

2. Your files: what we never see

Files are not uploaded to our servers. When you send a file, your browser encrypts it in small chunks with AES-256-GCM using a random key generated on your device, and streams the encrypted chunks straight to the recipient over a WebRTC connection.

Anyone who has the complete link (including the part after the #) can receive the file, so share it only with the intended recipient.

3. Data we do collect

DataWhy we need itKept for
Account data: name, username, email address, sign-in method (email/password, Google, GitHub or Apple), account ID, whether your email is verifiedTo create and secure your account, let you sign in, and show your dashboardUntil you delete your account
PasswordHandled by Firebase Authentication; we never see or store your password in readable formUntil you delete your account
Verification codes (5-digit email codes)To confirm your email address. Stored only as a keyed hashMinutes; deleted after use or expiry
Plan and usage data: plan, token balance, transfers used today, subscription statusTo apply plan limits and billingWhile your account exists
Transfer session data: random session ID, declared file size, status, timestamps, optional custom link nameTo set up the connection and enforce limits. Contains no file name, content or keySession deleted within about 24 hours (about 10 minutes after a transfer ends)
Connection signalling: WebRTC offers, answers and network candidatesTo connect the two devices. These contain IP addresses and network detailsDeleted with the session
Delivery logs: session ID, size transferred, duration, outcome (completed / failed / cancelled)To show you your delivery history. No file names or contentsWhile your account exists
Technical data: IP address, browser type, request logsSecurity, abuse prevention and diagnostics, processed by our hosting and cloud providersPer provider log policies (typically short-lived)

Receivers do not need an account. They are signed in with an anonymous Firebase identity solely to take part in one transfer; no name or email is collected from them.

4. Peer-to-peer connections and IP addresses

Because files travel directly between devices, the sender and the receiver can see each other’s IP address through the WebRTC connection (this is inherent to peer-to-peer technology). If a direct connection is not possible, traffic is relayed through a TURN server that sees only encrypted data. We use STUN/TURN servers to help devices find each other; the STUN servers we configure are operated by Google and Cloudflare.

If you do not want to reveal your IP address to the recipient, do not use the service, or use a trusted VPN.

5. Service providers we use

We share data only with providers that help us run the service, under their own terms and privacy policies:

We do not sell your personal data and we do not use it for advertising.

6. Cookies and local storage

We do not use advertising or tracking cookies. Firebase Authentication stores a sign-in token in your browser’s storage (such as IndexedDB or local storage) so you stay signed in. Our pages may also remember a few small preferences (for example, a theme choice). Payment pages operated by Paddle may set their own cookies. You can clear this data in your browser at any time; you will then be signed out.

Where data-protection law such as the GDPR applies, we rely on: contract (providing the service you signed up for), legitimate interests (security, fraud and abuse prevention, service reliability), legal obligation (tax and accounting, handled mainly by Paddle) and consent where we ask for it.

8. How long we keep data

Transfer sessions and signalling data are deleted automatically within about a day. Account, plan and delivery-log data are kept while your account is active. When you delete your account we delete or anonymise your profile and delivery logs, except where we must keep records longer by law (for example invoices held by Paddle).

9. Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict certain processing, to withdraw consent, and to complain to your local data-protection authority. To exercise these rights email qovox222@gmail.com from the address on your account. We may need to verify your identity first and will reply within the time required by law.

10. Security

Files are end-to-end encrypted in your browser. Our site uses HTTPS with HSTS, a strict content-security policy, and access rules that keep each user’s records private. Receivers must prove they hold the key before any data is sent, and every chunk is authenticated so tampering or truncation is detected. No system is perfectly secure; please protect your account with a strong, unique password and keep your links private.

11. International transfers

Our providers operate globally, so your data may be processed in countries other than your own, including the United States. Where required, transfers rely on safeguards such as standard contractual clauses or the providers’ certified frameworks.

12. Children

The service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has created an account, contact us and we will delete it.

13. Changes to this policy

We may update this policy as the service evolves. We will change the “Last updated” date above and, for material changes, notify you by email or in the app. Contact us any time at qovox222@gmail.com.