MyRealm Vault

Privacy Policy

How we handle your data, and what we do not do with it.

What we collect

Your email address and a hash of your password, so you can sign in. We never store the password itself.

The files you upload, their names, sizes and content types, and a cryptographic hash of their contents.

A record of each download of your links: when it happened, roughly where from, and how many bytes were served.

What we do not collect

We do not store IP addresses. Where we need to distinguish one visitor from another, we store a salted hash of the address rather than the address itself, and the hash cannot be reversed to recover it.

There are no third-party analytics, advertising or tracking scripts on this site. Nothing about your files is shared with an advertiser, because we do not have advertisers.

Why we collect it

To run the service: to let you sign in, store your files, serve your links, count downloads against a limit you set, and bill you if you are on a paid plan.

To keep the service safe: to scan uploads for malware, and to act on abuse reports.

Who else sees it

Our infrastructure and payment providers, only to the extent they need to in order to provide their part of the service. Our payment gateway receives what it needs to process a payment; we receive back a record of the payment, never your card number.

Law enforcement, where we are legally required to disclose. We do not sell personal data, and there is no arrangement under which anyone pays us for it.

Malware scanning, and what leaves our systems

Every file uploaded here is scanned for malware before it can be downloaded. The scan runs on our own infrastructure.

We may send a file’s SHA-256 hash — a fixed-length fingerprint of its contents — to a third-party reputation service to ask whether that exact file is already known to be malicious. A hash cannot be reversed into the file it came from, and reveals nothing about what the file contains.

We do not send your files to any third-party scanning service. Not the contents, not the filename, not any part of them. The distinction between sending a fingerprint and sending the file is the whole reason the scanning works this way.

We keep the result of a scan, and the date of it, even after the file is deleted — so that if the file is reported later we can say what we checked and when.

How long we keep it

Files, until you delete them; the stored copy is removed 7 days after that.

Sign-in sessions expire after 30 days.

Download records are kept for 90 days, then reduced to counts that identify nobody.

Records of payments are kept for as long as tax and accounting law requires.

Your choices

You can download or delete your files at any time from your dashboard, and you can ask us to close your account and delete your data by writing to support@myrealm.online.

You can ask what we hold about you, ask us to correct it, or object to how we use it.

Security

Traffic is encrypted in transit. Passwords are hashed with Argon2id. Files are stored on infrastructure that encrypts them at rest.

No service is perfectly secure, and we will tell you promptly if something happens to your data.