Privacy and browser storage
Last updated: 17 September 2026
Insurgent Studios Limited operates this service. For privacy requests or concerns, email info@insurgentstudios.com.
Sharing and receiving files
Files and notes are encrypted in the sender's browser before upload. The sharing link contains the information needed for the recipient to decrypt them. Treat the complete link as confidential: anyone who receives it may be able to access the content. Encryption does not remove the need to have permission to share personal information.
The server stores encrypted content and the metadata needed to deliver it, such as upload identifiers, size, creation and expiry times and download or view counts. We use connection information, including IP addresses, for service security and rate limits. SkySend uses rotating IP-derived identifiers for upload quotas. Our hosting provider also processes operational and security information.
The service runs on AWS Lightsail in London, UK. Files and notes become unavailable at their chosen expiry or applicable access limit. The maximum selectable expiry is seven days. Background cleanup removes expired content from the active service; temporary outages may delay physical cleanup. Separate backup copies, if made, follow the applicable backup lifecycle. The recipient's downloaded copies are outside this service's control.
Uploader accounts
Uploads and note creation require an account approved by us and two-factor authentication through our Authelia sign-in service. Recipients do not need an account to use a valid sharing link. We process uploader usernames, names, email addresses, group membership and authentication records to manage access and protect the service. Passwords are stored as hashes; two-factor registration data is protected in Authelia's encrypted database.
Our lawful basis for account, security and service administration is our legitimate interest in providing a secure sharing service. Account data is kept while access is needed and removed when the account is retired, except records needed to investigate a specific incident or meet legal obligations. People sharing documents remain responsible for their purpose and lawful basis for that sharing.
Browser storage
- skysend-auth: an essential, secure, HttpOnly sign-in cookie, valid for up to one hour.
- skysend-pkce: an essential, secure, HttpOnly cookie protecting the login exchange, valid for up to five minutes.
- insurgent_auth_session: an essential authentication cookie scoped to auth.insurgentstudios.uk. The sign-in session expires after one hour or 15 minutes of inactivity; extended “remember me” is disabled. SkySend has its own one-hour session.
- skysend-theme: local storage used to remember the display theme, including the system-theme default. It has no automatic expiry and remains until this site's browser data is cleared.
- skysend-lang: a language preference cookie set when you select a language, with a maximum lifetime of one year.
- Downloads may use temporary browser file storage and a service worker to handle large files. Cleanup is attempted after the transfer. An interrupted transfer may leave temporary data until a later cleanup or until you clear this site's data in your browser. Ordinary HTTP caching and files you choose to download may also remain.
We do not add advertising or visitor analytics. Login and transfer storage is used to provide the functions you request. Display storage remembers appearance and language preferences; it is not used for advertising. You can change those choices in SkySend and remove stored values by clearing this site’s browser data. Blocking essential storage may prevent signing in or downloading.
Providers and your rights
AWS provides hosting. Mythic Beasts delivers authentication notification emails. Privacy enquiries reach our Google Workspace mailbox; enquiries that do not become client work follow our 12-month retention policy after the last substantive contact. Some provider processing may occur outside the UK under their applicable data-processing and transfer safeguards. Contact us for information about the relevant safeguards.
Depending on the circumstances, you can request access, correction, erasure or restriction of your personal data, and portability where it applies. You can object to processing based on legitimate interests. Email us to exercise your rights. We do not make solely automated decisions with legal or similarly significant effects. You may complain to the Information Commissioner's Office (0303 123 1113).