Last updated: October 8, 2026

This page describes, without marketing gloss, the measures that protect files shared through ShareIt.onl and the exact lifecycle of every share. For what data we collect about you, see the privacy policy.

Security measures

  • TLS everywhere. Uploads, share pages, and downloads all travel over HTTPS; files are stored with an established cloud object-storage provider in the United States, behind our own branded delivery domain.
  • Unlisted random links. Every share lives at a randomly generated address that is never listed, published, or submitted for search indexing.
  • Optional password protection. A password-protected share cannot be opened without the password, even with the link.
  • One-time links. "Delete after first download" destroys the files the moment the first download completes.
  • Automatic link expiry. Every link has a built-in lifetime. Expiry permanently disables that public address; it does not delete files held in an account.
  • Automated malware screening. We may screen uploads with automated malware-reputation checks and remove flagged files. This is not a real-time antivirus scan of every file, so treat downloads from people you don't know with normal caution.
  • Human abuse review. Abuse reports and DMCA notices are reviewed by a person; offending shares are removed and repeat abusers are blocked. See the Acceptable Use Policy.
  • Delivery logs. Uploads, downloads, and share-page views are logged (details below), which lets us investigate abuse after the fact.
  • Optional end-to-end encrypted chat. Creators can choose browser-side AES-256-GCM for messages, reactions, filenames, and chat attachment copies. Recovery vaults are passphrase-encrypted, channel keys are wrapped separately for each registered device, and a permanent removal rotates the channel key. Standard channels are clearly labelled and store readable messages.

To be equally clear about the boundary: in an encrypted channel, attaching a file creates a separate encrypted copy that our server cannot preview, malware-scan, or bundle into a ZIP. A standard channel sends the ordinary ShareIt link instead. Our team can access ordinary uploads and standard messages when reviewing a report, but not an encrypted chat copy or message unless a member deliberately discloses readable evidence.

What expiry does, and does not, destroy

Two different things have lifetimes here, and keeping them apart is the whole model: the link and the files.

  • The link always expires on the schedule the uploader picked. When it does, the share page stops working for everyone holding that address, immediately and permanently. Re-sharing later issues a new address; an expired link never comes back to life.
  • The files belong to the account that uploaded them and are kept until that account deletes them. They are not archived copies: they are the files themselves, listed in the uploader's file manager, and they keep counting against that account's 20 GB of storage until they are deleted.

An upload with no account behind it at all - the fallback when a browser refuses cookies - is the exception: it still self-destructs on the schedule in the table below, because there is no file manager it could live in.

So the honest summary is: expiry protects the link, and deletion is what destroys the files. If you need a file gone from our storage, delete it from your file manager; waiting for the link to expire will not do it.

Lifecycle at a glance

EventPublic linkStored files
Chosen expiry arrivesDisabled permanentlyKept in the browser or Google-connected account
Owner re-shares an expired itemA new address is createdThe same stored files are used
One-time download completesDisabled immediatelyDestroyed immediately
Owner deletes filesDisabled immediatelyMoved through the rubbish-bin lifecycle, then destroyed
No browser account could be createdDisabled at expiryDestroyed by the next cleanup sweep
Valid abuse or DMCA removalDisabledDestroyed

The keep-alive rule: each download extends a live link by 24 hours from that download, so a share that is actively being used stays up; once downloads stop, the link expires on the schedule above.

Deletion, whoever asks: a file deleted from a file manager is removed from storage immediately, as is one removed after a valid takedown notice or an acceptable use report. Deleted files cannot be recovered by you or by us. Where several accounts happen to hold an identical file, the stored copy goes when the last account holding it deletes it.

What we log, and why

  • Upload records (share token, file names and sizes, upload time, uploader IP, user agent) - Kept after the files are deleted, so abuse can be investigated and legal obligations met.
  • Download logs (time, file, downloader IP, country, user agent) - Abuse prevention and, in aggregate, the stats members see in their dashboard.
  • Share-page views (time, IP, country) - Abuse prevention and aggregate stats.

Retention and your deletion rights for these logs are covered in the privacy policy.

What we cannot do

Link expiry cannot erase copies that recipients already downloaded. One-time files, files permanently removed from the rubbish bin, and files destroyed after a valid abuse or copyright removal cannot be recovered by you or by us. Keep your own backup of anything important.

Found a security problem or an abusive share? Report it via the report abuse form or email [email protected]. See also the terms of service and acceptable use policy.