Privacy
Last updated 31 July 2026
The short version: we collect what the service needs to work and nothing else. There are no advertising trackers, no analytics scripts and no third-party pixels on this site, and we do not sell or share personal data.
What we hold
- · Your documents — the HTML you upload, its title, the sender name you type, and how many times the link has been opened.
- · Your email address — only if you subscribe or buy a single document. It comes from Stripe at checkout, or from you when you request a sign-in link. Creating documents on the free plan needs no email at all.
- · Subscription status — your plan, whether it is active, and when the current period ends. Your Stripe customer id, so the billing portal can find you.
- · Your IP address — used to count requests for rate limiting. We store a counter against it for up to a day; we do not build a profile from it or log your browsing.
We never see your card details. Payment pages are hosted by Stripe and card data goes directly to them.
Cookies
All four are strictly necessary — they make the product work and nothing else. There are no advertising or analytics cookies, so there is no consent banner to click away.
- ·
sp_creator— An anonymous id for your browser, set when you create your first document, so your documents can be collected under your account if you subscribe later. - ·
sp_session— Keeps you signed in after you subscribe. Set only if you pay or use a sign-in link. - ·
sp_monthly— Counts how many free documents this browser has made this month. - ·
sp_view_…— Records that you entered the correct password for one particular protected document.
Where it lives
Documents, exports and previews are stored in Amazon Web Services in Singapore (region ap-southeast-1). The people we rely on to run the service are Amazon Web Services (hosting, storage, email delivery) and Stripe (payments). They process data on our instructions; nobody else receives it.
How we protect it
No system is perfectly secure, so rather than promise that, here is what actually protects your data:
- · Everything travels over HTTPS, and documents, exports and previews are encrypted at rest (AES-256) in storage that blocks all public access — nothing is readable without a signed request from the application.
- · Downloads are handed out as links that expire after fifteen minutes, rather than permanent public addresses.
- · The application's own credentials can only read and write its documents and records. They cannot delete storage, reach other services, or touch anything else in our infrastructure.
- · Your document runs in an isolated sandbox with its own origin, so one document can never read another, reach your session, or reach SendPage itself.
- · Sign-in cookies are signed, marked HTTP-only and Secure so scripts cannot read them, and can all be invalidated at once if you ever need to cut off access.
- · Document passwords are stored as a hash, never as the password itself, and the cookie proving you unlocked a document is keyed to a server secret so it cannot be forged from stored data.
- · Card details never reach our servers. Stripe collects them on their own pages and we only ever see the outcome of a payment.
- · Databases have point-in-time recovery enabled and stored files are versioned, so data can be restored after a mistake or a failure.
If you find a security problem, please write to loongnian714@gmail.com before disclosing it publicly, and we will fix it as quickly as we can.
How long we keep documents
Documents stay until you ask us to remove them. SendPage does not yet have a delete button — building one is the next thing on the list — so for now, email loongnian714@gmail.com with the link and we will delete the document, its exports and its preview image. If you want your account and email address removed as well, say so and we will do that too.
Who can see your documents
Anyone with the link. Links are random and are not indexed by search engines, but they are not secret — treat one like a shared file, and set a password on anything confidential. A password-protected document is also kept out of chat previews, so its contents cannot appear in a group thread.
Your rights
You can ask us what we hold about you, ask us to correct it, or ask us to delete it. Write to loongnian714@gmail.com and we will respond within 30 days. If you subscribe, your account page shows everything we associate with your email address.
Children
SendPage is not intended for children under 13, and we do not knowingly collect their data.
Changes
If this policy changes materially we will update the date above and tell subscribers by email.