Privacy Policy

This policy explains what information is and is not processed when using StreamSnatcher, a peer‑to‑peer file transfer service that keeps files off servers and enables encrypted, direct connections between participants.

Last updated: 8 Feb 2026 14 sections

Overview

StreamSnatcher is designed for privacy by default: files are shared directly between devices over encrypted WebRTC data channels, and the service does not upload or store transferred files on servers.

Only minimal, temporary technical data necessary to establish and maintain a session may be processed during active connections, and it is discarded when the session ends or shortly thereafter.

This policy applies to the website and related features available through the StreamSnatcher interface.

Last updated: 8 February 2026.

Scope

This policy covers information processed through the website’s peer‑to‑peer transfer features, support forms, and analytics or advertising integrations used to operate and improve the service.

It does not cover third‑party websites or services that may be linked from the interface, which are governed by their own policies.

What we do not collect

  • Files transferred through StreamSnatcher are not uploaded to or stored on servers.
  • No content of your files is inspected or indexed by the platform. This is a property of how the service works, not a policy choice: file data travels encrypted, directly between the two devices, and never passes through a server we could read it from.
  • No account is required to transfer files. Free use stays anonymous — we do not ask who you are to move a file.

Accounts exist only for the paid Pro tier, and only because paying customers need billing records, receipts, and a way to recover access. What that involves is set out in full below.

Pro accounts (paid tier only)

If you buy Pro, you create an account. Free use is unaffected and requires nothing. Authentication and account data are handled using Google Firebase (Firebase Authentication and Cloud Firestore), acting as our processor.

What is stored against a Pro account:

  • Identity: your email address, and your name and profile picture if you chose to sign in with Google. Passwords are handled entirely by Firebase Authentication — we never see or store them.
  • Billing records: what you were charged, in what currency, when, which plan, and the payment provider's reference. We do not receive or store card numbers; the payment provider handles payment details as merchant of record.
  • Licence and subscription state: which licences your account holds, their plan, expiry, and whether access has been revoked.
  • Sign-in history: the time, sign-in method, IP address, and browser/device string for recent sign-ins, so you can spot access you don't recognise. Visible to you under Security in your dashboard.
  • Transfer history (metadata only): file names, sizes, direction, and timestamps for transfers made while signed in.

We want to be explicit about that last item rather than bury it. Saved transfer history means file names are stored on our infrastructure (and therefore with Google, as our processor). File contents are still never uploaded, transmitted through, or readable by any server — that does not change. But a filename can itself be revealing, so: it is stored only for signed-in Pro accounts, it is shown to you at Dashboard › Transfer history, and you can erase all of it there at any time with one action. If you would rather we held none of it, don't sign in while transferring — the transfer works identically either way.

Deleting your account (Dashboard › Settings) removes your profile, licences, billing records, sign-in history, and saved transfer history, and deletes your sign-in credentials. Cancel any active subscription with the payment provider separately — deleting your account here does not stop their billing.

Information we may process

To establish and maintain a connection, participating browsers exchange technical details such as session descriptions and ICE candidates to negotiate network paths.

  • Session metadata: ephemeral identifiers, room codes, and timing signals for live sessions.
  • Connectivity data: IP candidates and transport details used for NAT traversal and reliable delivery.
  • Diagnostics: limited, short‑lived error or performance indicators to improve stability and support.
  • Usage analytics: aggregated, non‑content metrics to understand feature usage and quality.

These elements exist to provide the service and are not used to build personal profiles.

Cookies and local storage

StreamSnatcher uses cookies and similar technologies for core functionality, preferences, performance measurement, and to support advertising where enabled.

  • Essential: session continuity, room state, and security features that keep transfers working.
  • Preferences: UI choices such as theme or recent settings to improve usability.
  • Analytics: anonymized metrics to understand reliability and guide improvements.
  • Advertising: signals required to measure and display ads in compliance with user consent.

Consent preferences can be managed through the on‑site banner or your browser settings, and ads or analytics in applicable regions will respect those choices.

How we use information

  • Provide the service: set up secure sessions and move data between peers.
  • Reliability and performance: diagnose connectivity issues and optimize chunking and transport.
  • Safety and integrity: detect misuse patterns to protect participants and the platform.
  • Measurement: understand feature adoption and improve usability without reading file contents.

Sharing and third parties

Peer‑to‑peer connections rely on standard WebRTC signaling and STUN/TURN services to negotiate secure paths; these services see limited technical metadata necessary for connectivity, not the contents of files.

Where analytics or advertising are integrated, participating vendors may process limited identifiers and events to measure usage or deliver ads, subject to consent in applicable regions.

For Pro accounts, Google Firebase processes authentication and account data (identity, billing records, licence state, sign-in history, and saved transfer metadata) on our behalf, and the payment provider processes your purchase as merchant of record and issues your receipt. Neither receives file contents, because no server does.

StreamSnatcher does not sell personal information and does not share file contents with third parties.

Data retention and deletion

Session‑level technical data exists only for the duration of active connections and is discarded when the session ends.

Limited diagnostics and analytics may be retained for short periods to improve stability, detect abuse, and meet operational needs, after which they are automatically deleted or de‑identified.

Pro account data is different in kind, and we won't pretend otherwise: it is kept until you remove it. Saved transfer history stays until you clear it or delete your account. Profile, licence, and sign-in history are deleted when you delete your account. Billing records are the one exception — a record that a payment occurred may be retained where tax or accounting law requires it, even after account deletion, because we are not permitted to destroy it on request.

Your choices and controls

  • Browser controls: block or clear cookies and site data using your browser’s privacy settings.
  • Consent management: adjust ad and analytics preferences via the on‑site consent banner where required.
  • Session control: closing the page ends connections and clears session‑tied data.
  • Stay anonymous: don't sign in. Transfers behave identically signed out, and nothing is recorded against you — signing in is only needed to manage a Pro subscription.
  • Pro accounts: view everything held about you, wipe saved transfer history, sign out of all devices, or delete your account outright from your dashboard. No email to us required.
  • Questions: visit the Contact page for assistance or requests related to this policy.

Children's use

The service is intended for users aged 13 and older and does not knowingly allow younger users to create sessions.

Security

🔐

Encryption in transit

Transfers occur over DTLS‑encrypted WebRTC data channels to help protect contents from interception.

🗄️

No server file storage

Files remain device‑to‑device and are not stored by the platform.

🧯

Minimal operational data

Only the least amount of technical metadata required to establish and maintain sessions is used.

No security measure is perfect, but the architecture minimizes exposure by avoiding server‑side file storage and limiting data collection.

International processing

Third‑party services used for connectivity, analytics, or advertising may process limited data across regions; appropriate safeguards and consent controls are applied where required.

Changes to this policy

This policy may be updated to reflect product or regulatory changes, and a revised date will be posted when updates occur.

Contact

For privacy questions or requests, please visit the Contact page.