Privacy Policy
Effective 17 August 2026.
This policy describes how the L-Share instance at share.leunos.com processes information. It applies only to this deployment, which is hosted on Vercel. The person or organization that operates this instance is the “operator” and is the controller of personal data processed here, where that concept applies.
The Terms of Service explain how the product works, including that every upload is public by link.
A service without accounts
L-Share has no user accounts, profiles, passwords, or application database. The operator cannot look up “your files” by name or email. Files are identified only by the public object URL and, for deletion, by a key that stays in the uploading browser.
Information we process
This instance processes the following categories of information.
Files you upload
When you upload a file, the file contents and the original filename you chose are sent from your browser directly to Vercel Blob. The application server does not proxy the file bytes. The stored object uses a sanitized filename, a content type derived from the extension, the size of the file, and a pathname that includes a hash of your delete key.
The current size limit is 50 MB. Accepted extensions are .avif, .csv, .doc, .docx, .gif, .jpeg, .jpg, .json, .m4a, .md, .mov, .mp3, .mp4, .ogg, .pdf, .png, .ppt, .pptx, .txt, .wav, .webm, .webp, .xls, .xlsx, .zip. Contents are not scanned for malware and are not reviewed by default.
Anyone with the public URL can retrieve the file. Treat an upload as a publication. Do not upload information that must remain private.
Delete keys and local history
Your browser generates a random 256-bit delete key, hashes it, and embeds only the hash in the object path. The raw key is stored in this browser’s local storage together with the public URL, filename, size, and provider for recent and unconfirmed uploads.
That information does not leave your device except when you ask L-Share to delete a file, in which case the key is sent to this origin so the server can verify it. Clearing site data, using a private window, or changing browsers deletes the local history. The operator cannot restore it.
Optional upload access key
The operator may require a shared access key before this instance issues upload authorization. If you enter that key, it is sent to this origin to check permission to start an upload. It is not an account identifier, it is not used to build a profile, and it does not make stored files private. This deployment does not currently require that key.
Technical logs collected by hosting
Vercel, as the host, records ordinary request metadata such as IP address, date and time, requested URL, referrer, user agent, and response status. Object storage providers record their own access logs when a file is uploaded, downloaded, or deleted. L-Share does not operate a separate analytics product and does not use advertising cookies or cross-site trackers.
The application itself does not set an account or session cookie. Your browser may still keep local storage records described above. Security headers on this instance include a restrictive Content Security Policy, frame denial, and related browser controls.
Why this information is processed
Information is processed only to:
- accept an allowed file and return a public link
- authorize deletion when the correct delete key is presented
- enforce the size, type, origin, and optional access-key rules
- host, secure, and debug the instance
- comply with law and respond to valid legal requests
Where a legal basis is required, the operator relies on performing the service you request and on the legitimate interest of operating a public file-sharing instance. Uploading a file is a request to store and publish that file at a public URL.
Processors and where data goes
This instance runs on Vercel. File objects are stored with Vercel Blob. Those providers may process data in the United States and in other countries where they operate. Their own terms and privacy notices apply to their processing.
- Vercel: Privacy Policy
- Vercel Blob is part of Vercel’s platform and is covered by Vercel’s notices
The operator does not sell your personal information and does not share it for cross-context advertising.
Retention
- Uploaded files remain in object storage until you delete them with the delete key, or the operator or storage provider removes them.
- Local history and delete keys remain in your browser until you clear site data or remove those records in the interface.
- Hosting and storage logs are kept for the period of the relevant provider.
After a file is deleted from the store, copies can still exist on recipient devices, in caches, CDNs, backups, or logs. L-Share cannot erase those copies.
Security
Uploads and page views use HTTPS. Long-lived storage credentials stay on the server. Upload authorization is short-lived and bound to an allowed path, type, and size. Deletion requires the high-entropy key created in your browser.
L-Share does not encrypt file contents for confidentiality. A public link is enough to read the file. On a shared or compromised device, another person may be able to read local history and delete those files. Do not use this service for secrets.
Your choices and rights
You can:
- choose not to upload a file
- avoid putting personal data in filenames or file contents
- delete a file from the interface if this browser still has the key
- clear this site’s data to remove local history from the device
Depending on where you live, you may have rights to access, correct, delete, or restrict personal data, to object to processing, to portability, and to complain to a supervisory authority. Because this service has no accounts, the operator usually cannot locate an upload without the file URL. If you want a file removed and no longer have the delete key, contact the operator with that URL.
Children
The service is not directed at children under 16, or under the digital-consent age in their country if that age is higher. Do not upload personal information about children. The operator will remove such material when it becomes aware of it.
Changes
The operator may update this policy by posting a new version at this URL. The “Effective” date at the top will change. If a change materially affects how already-uploaded files are handled, the operator will also note that on this page.
Contact
Privacy questions should be directed to the operator of the instance at share.leunos.com. The operator has not published a contact email for this deployment.