← share.nebulos.net

Privacy Policy

Last updated: 4 May 2026

This policy explains what personal data share.nebulos.net collects, why, how it is processed, and what rights you have over it. It is written to comply with the General Data Protection Regulation (GDPR, EU 2016/679) and the Estonian Personal Data Protection Act.

Contents
  1. Data controller
  2. What data is collected
  3. Purposes and legal basis
  4. Third-party processors
  5. International transfers
  6. Retention periods
  7. Your rights
  8. Cookies
  9. Security
  10. Children
  11. Changes to this policy
  12. Complaints
  13. Contact

1. Data controller

The data controller for share.nebulos.net is:

Operatornebulos.net
Country of residenceEstonia
Contact[email protected]

The service is operated by a private individual on a non-commercial basis. Postal address is available on request via the contact email.

2. What data is collected

2.1 Account data (when you sign in)

Authentication is performed via Discord OAuth. When you sign in, share.nebulos.net receives the following from Discord:

2.2 Uploaded content

Files you upload to create a share are stored on infrastructure described in section 4. Each share has an expiry of at most 30 days; on expiry, the files are deleted and are not recoverable. Files are not scanned for content beyond malware checks (anti-virus engine ClamAV) and are not used to train any model.

2.3 Recipient interactions

When a recipient downloads a share, we record the timestamp, the share identifier, and the source IP address. We do not record recipient identity beyond the IP address.

2.4 Technical logs

Our reverse proxy (Caddy) and our application record:

2.5 Session cookies

One HTTP-only, secure session cookie is set on sign-in. It contains a JWT used to authenticate subsequent requests. No analytics, advertising, or cross-site tracking cookies are set.

3. Purposes and legal basis

PurposeLegal basis (GDPR Art. 6)
Provide the file-sharing service you signed up forPerformance of a contract — Art. 6(1)(b)
Authenticate you via Discord and verify server membershipPerformance of a contract — Art. 6(1)(b)
Operate the service securely (rate-limiting, abuse prevention, malware scanning)Legitimate interests — Art. 6(1)(f)
Comply with binding legal requests (DSA, court orders)Legal obligation — Art. 6(1)(c)
Send you transactional emails (share-ready notifications, password resets)Performance of a contract — Art. 6(1)(b)

4. Third-party processors

The service relies on the following processors. Each handles only the data necessary for its function and operates under its own privacy commitments.

ProcessorFunctionLocation
Cloudflare, Inc.CDN, DDoS protection, TLS termination at edgeUnited States (with EU presence)
Discord, Inc.OAuth authentication providerUnited States
Resend, Inc.Outbound transactional emailEuropean Union (via AWS Dublin)
OVH SASUnderlying infrastructure hostEuropean Union (France)

The application database, file storage, and logs are hosted on infrastructure controlled by the operator and are not shared with any other third party.

5. International transfers

Where data is transferred outside the European Economic Area (notably to Cloudflare and Discord in the United States), the transfer is covered by Standard Contractual Clauses (SCCs) under Article 46 GDPR, in conjunction with the EU–US Data Privacy Framework where applicable.

6. Retention periods

DataRetained for
Uploaded files (share content)Until the share expires (maximum 30 days), then deleted within 24 hours
Account record (your Discord-linked profile)Until you delete your account or the service is shut down
Application logs (signin, share creation, downloads)Up to 30 days
Reverse-proxy access logsUp to 7 days
Configuration backups (do not contain uploaded files)Up to 7 daily snapshots

7. Your rights

Under the GDPR you have the following rights with respect to your personal data:

To exercise any of these rights, email [email protected]. We respond within one month as required by Art. 12(3) GDPR.

8. Cookies

We set one strictly-necessary cookie: a session token used to keep you signed in. It is HTTP-only, Secure, and SameSite=Lax. It expires according to the configured session duration (currently 1 year, refreshed on activity). No analytics, advertising, or third-party tracking cookies are set.

9. Security

The service is protected by, at minimum:

No system is perfectly secure; if you discover a vulnerability, please report it to [email protected].

10. Children

This service is not directed at persons under 16 years of age. We do not knowingly collect personal data from children. If you believe a minor has provided personal data, please contact us and it will be deleted.

11. Changes to this policy

We may update this policy. The "last updated" date at the top of this page reflects the current version. Material changes affecting how your data is processed will be communicated by email to active account holders before they take effect.

12. Complaints

If you believe your personal data is being processed in violation of the GDPR, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon):

13. Contact

For all privacy-related questions or to exercise your rights, please email [email protected].