throw.dog

Privacy Policy

The short version

throw.dog is built to know as little about you as possible: no accounts, no tracking cookies, no profiling analytics, no ads.

Your text and your files

The text you throw lives only in the server's memory, for about 10 minutes at most, and is erased the moment it is handed out.

A file is too big for that, so a file is written to disk โ€” and this is the one place where saying "nothing is written to disk" would be a lie, so we do not say it. A thrown file lives on our disk for at most 10 minutes, counted from the moment it finishes arriving, and is deleted as soon as it has been fetched or that time runs out, whichever comes first. There are no backups; a restart of the service erases every file on it. In the closed mode what is on that disk is ciphertext we cannot read, and the file's own name is inside it, so we do not know that either. In the open mode we can read the file, which is why open files are capped far lower.

The content of a throw is never logged. Neither is a file's name, nor its exact size โ€” the log records that a throw of some size class was created or read, and nothing that could identify it.

In the closed mode what reaches us is ciphertext your browser produced (AES-256-GCM), and the key never reaches us at all: it travels in the fragment of the link โ€” the part after the # โ€” which browsers do not send with any request. We could not read a closed throw if we wanted to, and we cannot recover one for you. In the open mode the text passes through our memory as you wrote it, and we are technically able to read it. The mode is your choice and it is shown on screen when you make it.

What the closed mode does not protect you from

It protects you from us as a place your text is stored. It does not protect you from us as the source of the page doing the encrypting: we serve that page, so anyone who can change what we serve could change it. No in-browser encryption anywhere can escape that, and we would rather name it than let the word "encrypted" imply otherwise. What we do about it is narrow and real: on the two pages where a key is created or used — the closed compose page, and any page that opens a link — every line of code that runs arrived inside that one document. No analytics, no fonts, no third-party code of any kind is loaded there. Those pages do make one request of their own, for the throw itself, and it never carries the key. Everything else is in the source you received, which is all there is to audit.

Logs

We keep minimal operational logs (for example, that a throw was created or read) to run the service and stop abuse. Throw codes are pseudonymized in logs with a keyed hash, so a log on its own cannot be turned back into a working code, and neither the text, nor a file's name, nor its content is ever included.

Cookies & tracking

No cookies, no profiling, no third-party trackers, no ads. The homepage and the legal pages load one script of our own โ€” a cookieless visit counter self-hosted on our analytics subdomain, which records no identifiers and builds no profile. It is named here rather than tucked away because "no third-party scripts" and "no scripts at all" are different claims, and only the first is true of the homepage. The pages where a key exists — the closed sender and every page that opens a throw — load no script at all, by design. Nothing on any page is fetched from a CDN, a font host, or anyone else.

Contact

Questions or abuse reports: abuse@throw.dog.