Skip to content

Privacy Policy for Sorola File Sharing

Effective Date: September 2026

Common privacy notice

This tool-specific layer supplements the Sorola controller privacy notice, which identifies the controller and explains legal bases, common technical data, recipients, transfers, retention and your rights.

1. Introduction

Sorola File Sharing ("the Service") is a temporary file sharing service committed to protecting user privacy. This privacy policy explains how the Service handles your data.

2. Data Collection and Usage

When you upload a file, it is stored on the server only while the share is active. A file that reaches its download limit is deleted after that download. An hourly automated sweep permanently removes an expired file, its metadata, and any encryption-key hash no later than one hour after expiry.

  • No Account Required: No registration or personal identification is required to use the Service.
  • Browser-encryption trust model: The browser creates the raw AES key and encrypts and decrypts the file locally. The server stores the ciphertext and a SHA-256 verifier. On download the server receives only that verifier in an HTTPS header, not the raw key. The verifier is not added to URLs, analytics or application logs. A browser extension, malware or another person using the device may still see a key entered in the browser.
  • Service data: File contents and decryption keys are not added to analytics. Optional consent-gated site analytics are described below.
  • Temporary Storage: Files are stored temporarily. The automated sweep removes expired files with a maximum delay of one hour.

3. Data Sharing and Third Parties

We do not sell, trade, or rent user data or uploaded files to any third parties. The Service does not contain third-party tracking codes or advertisements.

4. Security

All communication with the Service is conducted via secure, encrypted HTTPS protocols. Files are accessible to anyone who has the share link. Do not share sensitive files without appropriate precautions.

5. Contact

If you have any questions regarding this privacy policy, you can contact us at: [email protected]

Optional site analytics

Sorola does not load Google Tag Manager or Plausible Analytics before you accept optional analytics. After acceptance, measurement may process the page URL, title and referrer, browser and device information, and form, outbound-link, and file-download event metadata. Identifier-free performance measurement additionally reports only the product, a coarse page class, rounded Core Web Vitals, and a count of at most ten errors; it does not report the path, user, processed content, or error details. Content you process in a tool is not intentionally added to analytics. Rejecting does not limit the service. The choice is stored in local browser storage and a first-party preference cookie for up to one year. You can change your choice at any time with the persistent “Privacy settings” button.

« Back to home page