Privacy

Last updated 1 September 2026

What we store, what we deliberately do not, and who else processes it.

What we store

What we deliberately never store

Because every recipient verifies their email, we do not need to infer identity from an IP address the way link-based tools do.

Cookies

We set four cookies and every one of them is strictly functional. None is used for advertising, none is shared with anyone, and none tracks you across other sites — so there is no banner here asking you to consent to something, because there is nothing to consent to.

All four are HttpOnly and Secure, meaning no script on the page can read them and they are never sent over an unencrypted connection. This marketing site sets no cookies at all.

Retention

Deleting an artifact ends access immediately and removes it from your library. The stored copy — every version, the original and the converted pages — is removed within 30 days of deletion.

On the free plan, an artifact is scheduled for removal 180 days after its last upload, and removed within 30 days of that date. Uploading a new version starts the 180 days again; opening the document does not. On a paid plan there is no such window — content is kept until you delete it or close the account.

Viewing records — who opened a document, when, and which pages — are kept for 12 months and then deleted.

Closing your account ends access immediately and starts a 30-day window, after which the organization and its content are removed. Within that window it can be reopened.

A file you check without an account, at app.getsendframe.com/check, is stored in a holding area from which nothing can be sent, and the file and its report are deleted within two days. If you sign in and copy it into your workspace, the copy follows the rules above.

Revoking a share or letting it expire ends access immediately and does not touch the content behind it.

What survives an account being removed, and why

Two records are kept deliberately and are not tied to your organization:

Who else processes your data

SubprocessorWhat it does
CloudflareHosting, storage, bot protection, and the city-level geo used for viewing records
NeonThe Postgres database
RailwayDocument conversion and malware scanning
ResendTransactional email — invitations, alerts, sign-in
SentryError reports from our servers, allowlisted so document content is not included
StripePayments and subscription billing

There is no third-party geolocation vendor — location comes from the request itself — and no file is ever sent to an external scanning service.

Viewers are told

Anyone opening a document sees a disclosure before any viewing is recorded, and a persistent indicator for the whole session. It is not removable.

Your requests

Write to support@getsendframe.com for a copy of your data, a correction, or removal. A recipient who wants their viewing records removed can write to us directly.

Questions, or a data request: support@getsendframe.com.