Privacy
threewordshare is built so we see as little of your data as possible. Here is what that means in practice.
Your files are encrypted before they leave your device
When you send a file, it is encrypted in your browser. The key is derived from your three words, so anyone you give the words to can open the file, and we only ever store the scrambled version plus a hashed form of the words.
So we do not keep your files or filenames in readable form. Being honest about the limits: the encryption is only as strong as the words. Because we store a hash of them, someone with access to our database could in theory work back to the words and open the file. The optional fourth secret word (on Pro and Max) closes that gap. It is generated on your device and never reaches us, so we hold nothing that can open a file locked with one.
What we actually store
- The encrypted file, in Cloudflare R2, until it expires.
- A hashed version of your three words that points to the file, plus a small encrypted blob of metadata, in Redis. We store a hash, not the words themselves, so the words cannot be read back out of our database.
- The expiry the sender picked for each transfer. When it is up, the file and its words are deleted and the words go back into circulation. On Max a sender can choose no expiry, and then the file stays until they delete it or their plan ends. When a plan ends, its files are deleted 48 hours later.
- For each account, the size and expiry of its live transfers, so we can enforce the storage limit, and a count of today’s burn-after-download transfers, which clears after two days.
Accounts are three words too
Accounts do not use an email or a password. Your account is three words, and we store only a hash of them. That means we genuinely cannot recover them for you, so write them down. We keep your plan, your subscription status and a few device session tokens, nothing else about you.
Payments
Billing runs through Dodo Payments, which acts as the seller and handles the payment. Your card details go to them, not to us. We keep only the subscription id, which plan it is, how many months you have paid and whether it is active, so we know what to unlock and what to charge next.
Analytics
We count visits with Samehost, an analytics tool we built and operate ourselves on the same server as this site, so we can see which pages people land on and where they came from. Once you have agreed to analytics, each page you view sends it the address of the page, the site that sent you here, your browser and its language setting, and your IP address. Samehost stores your IP address, with the record of the visit, and it is not passed to anyone else. It does not record anything about your files, your words or what you send.
Samehost sets one cookie, sh_vid, holding a random id for a year so a second visit is not counted as a new person. Scripts on the page cannot read it. Choosing "No thanks", including later from the Cookies link at the bottom of every page, deletes it and stops Samehost for you.
What we do not do
We do not run ads. We do not sell or share your data with data brokers, and nothing we load follows you across other sites. We do not ask for your email. Beyond the analytics cookie above, we set one more cookie, and it exists only to keep you signed in to your account.
Abuse prevention
We keep short-lived counters tied to IP addresses in Redis to rate-limit requests and stop spam. They expire within minutes and are not used to profile you.
Deleting your data
Every file deletes itself when it expires. Turn on burn-after-download and it is gone the moment it is fetched. Respin your account words or cancel your plan and the old record stops working.
Contact
Questions about any of this: hecodesforme.com.