Privacy
Last updated 26 August 2026
The short version. We store the files you upload so we can serve them at your link. Automated previewers read only the bounded structure needed to render them; no person or AI model reads them, and we do not scan them for malware or train anything on them. Nothing you share is listed publicly or indexed by search engines. Anyone holding your link can open it, so put a password on anything sensitive.
#What you upload
Your files are stored in Cloudflare R2 and served from there when somebody opens your link. We keep them until you delete them, until the expiry you set, or — for links made without an account — for 7 days.
An expiry is a real deletion, not a hidden link. A job runs every night and removes the stored bytes of anything whose date has passed, whether or not the link was ever opened again.
Alongside the bytes we record what the file is called, how large it is, what kind of thing our detection decided it was, and a fingerprint: a SHA-256 digest of the first four megabytes together with the exact byte length. The fingerprint exists for one purpose — when a file is reported and removed, that fingerprint is blocked so the same file cannot be uploaded again under a different name. It is not used for anything else and it cannot be turned back into your file.
Detection reads the first few kilobytes to decide which viewer to draw. When somebody opens the link, that viewer may read a bounded prefix or the structured parts required for the preview — for example slide XML in a PowerPoint file or rows in a spreadsheet. This happens automatically inside our Cloudflare Worker; no person or AI model reads the file, no macros or programs are executed, and the preview is never sent to a third-party document service.
#Who can open your link
A link is the key. There is no list of who is allowed to open one, so anybody holding it can — including anybody they forward it to.
A random code is unguessable. A name you choose is not. Links normally get 5 random characters, which nobody finds by trying. On Scale you can name a link instead, and 2l.nz/spring-menu is a name somebody could think of. That is the point of the feature, and it is a real trade: name the things you would not mind a stranger finding, and let everything else keep its random code.
Three things narrow it further, and they work on any plan that has them:
- A password. Checked on the server. The bytes are not sent until it matches, so the file is not merely hidden behind a form.
- An expiry. The link stops working and the bytes are deleted that night.
- Delete after the first read. The record is removed before the page is drawn, so two people opening it at the same moment cannot both see it.
Links made on Scale carry no 2L footer. The report link stays on every page whatever the plan — it is how anything harmful gets taken down, and it is not something a plan can switch off.
#When somebody opens a link
Each visit records a timestamp, the country Cloudflare reports, whether the request came from a phone, a tablet or a desktop, which browser family it was, and the domain of the referring page. It does not record IP addresses, and there is no cookie, no fingerprinting script and no third-party analytics on any page of this site.
Only the owner of a link sees those numbers, and how much of them they see depends on their plan. We keep the last 100 visits per link and a running total.
#Your account
An account holds a username, an email address, a password hash, and — if you turn it on — a TOTP secret and a set of one-time backup codes. Passwords are stored as PBKDF2-SHA256 with a per-account salt and 300,000 iterations of work; they are never stored in a form that can be turned back into your password.
Your email address is stored in the clear so we can send you security notices, and indexed as a SHA-256 hash — meaning the database column used for lookups is not a mailing list. Backup codes and one-time codes are stored only as hashes.
An API key acts as your whole account. It is stored as a hash and shown to you exactly once, when it is made. Anybody holding it can do anything you can do through the API, so make a separate key for each place you use one and revoke rather than delete when a key leaks.
#Links made without an account
There is no account to attach an anonymous upload to, so we store a salted hash of the uploading IP address instead. It answers exactly two questions — “was this the same uploader as that one” and “block this uploader” — and it cannot be turned back into an address. It is deleted with the link.
#How long things are kept
| What | How long |
|---|---|
| A link made without an account | 7 days, then deleted |
| A link made with an account | Until you delete it, or until the expiry you set |
| Visit records | The last 100 per link, deleted with the link |
| The fingerprint of a removed file | Kept, so the same file cannot be re-uploaded |
| Your account | Until you delete it; dormant after twelve months without a sign-in |
Deleting a link removes the record, its analytics and the stored bytes together. It is immediate and we keep no copy, which also means we cannot restore it for you afterwards.
#Who else is involved
| Who | What for |
|---|---|
| Cloudflare | Serving the site, storing files (R2), the database (D1), and the bot check on anonymous uploads (Turnstile). |
| Resend | Sending account email — verification codes, password resets, security notices. |
| Dodo Payments | Taking payment for paid plans, through Vapih Pay. We never see or store your card details. |
That is the complete list. There is no advertising network, no analytics vendor and no data broker. Notably, the QR code for a link is drawn on our own servers rather than fetched from a QR service, because a QR service would otherwise be told about every link anybody generates a code for.
#Search engines
Every page that shows uploaded content carries X-Robots-Tag: noindex, nofollow, noarchive, and the paths files are served from are disallowed in robots.txt. Only the marketing pages of this site are meant to be found in a search.
That is a strong measure and not an absolute one. If somebody you sent a link to publishes it on a public page, a crawler can reach it from there.
#Your rights, and changes to this
You can delete any link at any time from your dashboard, and you can delete your whole account, which removes everything above. If you want a copy of what we hold about you, or you have any other question about this, write to support@2l.nz.
If we ever change any of this in a way that matters, the date at the top changes and anybody with an account gets an email about it.