This policy explains what personal data share.nebulos.net collects, why, how it is processed, and what rights you have over it. It is written to comply with the General Data Protection Regulation (GDPR, EU 2016/679) and the Estonian Personal Data Protection Act.
The data controller for share.nebulos.net is:
| Operator | nebulos.net |
|---|---|
| Country of residence | Estonia |
| Contact | [email protected] |
The service is operated by a private individual on a non-commercial basis. Postal address is available on request via the contact email.
Authentication is performed via Discord OAuth. When you sign in, share.nebulos.net receives the following from Discord:
Files you upload to create a share are stored on infrastructure described in section 4. Each share has an expiry of at most 30 days; on expiry, the files are deleted and are not recoverable. Files are not scanned for content beyond malware checks (anti-virus engine ClamAV) and are not used to train any model.
When a recipient downloads a share, we record the timestamp, the share identifier, and the source IP address. We do not record recipient identity beyond the IP address.
Our reverse proxy (Caddy) and our application record:
One HTTP-only, secure session cookie is set on sign-in. It contains a JWT used to authenticate subsequent requests. No analytics, advertising, or cross-site tracking cookies are set.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide the file-sharing service you signed up for | Performance of a contract — Art. 6(1)(b) |
| Authenticate you via Discord and verify server membership | Performance of a contract — Art. 6(1)(b) |
| Operate the service securely (rate-limiting, abuse prevention, malware scanning) | Legitimate interests — Art. 6(1)(f) |
| Comply with binding legal requests (DSA, court orders) | Legal obligation — Art. 6(1)(c) |
| Send you transactional emails (share-ready notifications, password resets) | Performance of a contract — Art. 6(1)(b) |
The service relies on the following processors. Each handles only the data necessary for its function and operates under its own privacy commitments.
| Processor | Function | Location |
|---|---|---|
| Cloudflare, Inc. | CDN, DDoS protection, TLS termination at edge | United States (with EU presence) |
| Discord, Inc. | OAuth authentication provider | United States |
| Resend, Inc. | Outbound transactional email | European Union (via AWS Dublin) |
| OVH SAS | Underlying infrastructure host | European Union (France) |
The application database, file storage, and logs are hosted on infrastructure controlled by the operator and are not shared with any other third party.
Where data is transferred outside the European Economic Area (notably to Cloudflare and Discord in the United States), the transfer is covered by Standard Contractual Clauses (SCCs) under Article 46 GDPR, in conjunction with the EU–US Data Privacy Framework where applicable.
| Data | Retained for |
|---|---|
| Uploaded files (share content) | Until the share expires (maximum 30 days), then deleted within 24 hours |
| Account record (your Discord-linked profile) | Until you delete your account or the service is shut down |
| Application logs (signin, share creation, downloads) | Up to 30 days |
| Reverse-proxy access logs | Up to 7 days |
| Configuration backups (do not contain uploaded files) | Up to 7 daily snapshots |
Under the GDPR you have the following rights with respect to your personal data:
To exercise any of these rights, email [email protected]. We respond within one month as required by Art. 12(3) GDPR.
We set one strictly-necessary cookie: a session token used to keep you signed in. It is HTTP-only, Secure, and SameSite=Lax. It expires according to the configured session duration (currently 1 year, refreshed on activity). No analytics, advertising, or third-party tracking cookies are set.
The service is protected by, at minimum:
No system is perfectly secure; if you discover a vulnerability, please report it to [email protected].
This service is not directed at persons under 16 years of age. We do not knowingly collect personal data from children. If you believe a minor has provided personal data, please contact us and it will be deleted.
We may update this policy. The "last updated" date at the top of this page reflects the current version. Material changes affecting how your data is processed will be communicated by email to active account holders before they take effect.
If you believe your personal data is being processed in violation of the GDPR, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon):
For all privacy-related questions or to exercise your rights, please email [email protected].