Last updated 1 September 2026
What we store, what we deliberately do not, and who else processes it.
Because every recipient verifies their email, we do not need to infer identity from an IP address the way link-based tools do.
We set four cookies and every one of them is strictly functional. None is used for advertising, none is shared with anyone, and none tracks you across other sites — so there is no banner here asking you to consent to something, because there is nothing to consent to.
sf_session — keeps you signed in to the app for 30 days.sf_verified — on the document domain, remembers for 30 days
that you proved your email address, so you are not asked for a code
every time you open a document, and so sendframe.app can
show you the documents currently shared with that address. Signing out
there deletes the record behind it.sf_oauth_next and sf_oauth_consent — live for
15 minutes while you connect an AI assistant, and are deleted the moment
the connection completes.All four are HttpOnly and Secure, meaning no
script on the page can read them and they are never sent over an unencrypted
connection. This marketing site sets no cookies at all.
Deleting an artifact ends access immediately and removes it from your library. The stored copy — every version, the original and the converted pages — is removed within 30 days of deletion.
On the free plan, an artifact is scheduled for removal 180 days after its last upload, and removed within 30 days of that date. Uploading a new version starts the 180 days again; opening the document does not. On a paid plan there is no such window — content is kept until you delete it or close the account.
Viewing records — who opened a document, when, and which pages — are kept for 12 months and then deleted.
Closing your account ends access immediately and starts a 30-day window, after which the organization and its content are removed. Within that window it can be reopened.
A file you check without an account, at app.getsendframe.com/check,
is stored in a holding area from which nothing can be sent, and the file
and its report are deleted within two days. If you sign in
and copy it into your workspace, the copy follows the rules above.
Revoking a share or letting it expire ends access immediately and does not touch the content behind it.
Two records are kept deliberately and are not tied to your organization:
| Subprocessor | What it does |
|---|---|
| Cloudflare | Hosting, storage, bot protection, and the city-level geo used for viewing records |
| Neon | The Postgres database |
| Railway | Document conversion and malware scanning |
| Resend | Transactional email — invitations, alerts, sign-in |
| Sentry | Error reports from our servers, allowlisted so document content is not included |
| Stripe | Payments and subscription billing |
There is no third-party geolocation vendor — location comes from the request itself — and no file is ever sent to an external scanning service.
Anyone opening a document sees a disclosure before any viewing is recorded, and a persistent indicator for the whole session. It is not removable.
Write to support@getsendframe.com for a copy of your data, a correction, or removal. A recipient who wants their viewing records removed can write to us directly.
Questions, or a data request: support@getsendframe.com.