We never store your files. Peeza is a conduit: file bytes stream between two devices that are online at the same time, end-to-end encrypted with a key our servers never receive. There is no cloud copy of your files — nothing to store, subpoena, or leak.
To route transfers and run accounts, our relay stores a small amount of metadata — never file contents or encryption keys:
| Data | Why | Kept for |
|---|---|---|
| Account (email, sign-in provider, display name, plan) | your account | while your account exists |
| Session token | keep you signed in | until you sign out |
| Share link (token, room, timestamps) | deliver a one-time link | 48 hours, then deleted |
| Your devices (name, OS, version, public key) | "send to my devices" | until you remove the device |
| Directed-send envelope (sealed key, opaque to us) | hold a transfer for an offline device | 7 days, then deleted |
| Connectivity metrics (direct-vs-relay, timings) | improve reliability | anonymous — no account, room, or IP |
Our own software uses your IP address only in memory, only for rate limiting (to keep the free relay fair). The relay application never writes it to disk and never includes it in application logs; it is discarded when the relay restarts.
The infrastructure that carries the traffic is a separate matter, and we won't pretend otherwise: our relay runs on Fly.io and this website is served through Cloudflare. Like virtually all hosting providers, they process and may temporarily log connection IPs to deliver traffic, prevent abuse, and keep their networks running, under their own privacy policies (Fly.io, Cloudflare). We do not receive or use those logs.
Paid plans are processed by our merchant of record, who acts as the seller of record and handles billing and applicable taxes. We receive confirmation of your plan, not your full payment details.
Product analytics are off by default and opt-in; if enabled, they contain no identifiers and no file names — only aggregate, day-bucketed counts. Crash reports are never sent automatically; you are shown the report and choose whether to send it, and home-directory paths and file names are scrubbed first. The share site (get.peeza.app) carries no analytics of any kind.
This marketing website (peeza.app) uses privacy-friendly, anonymous traffic statistics; a cookie banner lets you decline non-essential cookies.
You can access, correct, export, or delete your data — for most users that's an email address and a usage counter. To make a request, email [email protected]; we respond within 30 days. EU users have a right to a representative and to lodge a complaint with a supervisory authority; where we have no EU establishment we appoint an Article 27 representative (details to be listed here on publication).
Peeza is operated from Montréal, Québec. As required by Québec's Loi sur la protection des renseignements personnels dans le secteur privé (as amended by Loi 25), the person responsible for the protection of personal information is the operator of peeza (title: Responsable de la protection des renseignements personnels). Reach them at [email protected] for any question, request, or complaint about how personal information is handled. Complaints are answered within 30 days.
The relay runs on Fly.io; this website is served through Cloudflare. We aim to keep EU users' signaling and relay traffic in EU regions. Because files are end-to-end encrypted and never stored, no readable file data crosses any border through us. Some of this processing happens on servers outside Québec and Canada; we have assessed these transfers and limit what leaves your device to the encrypted and minimal metadata described above.
We cannot see file contents. Report abuse — including child-safety concerns — to [email protected]; our only remedy is invalidating a share link, and we preserve and report as required by law. See also Security.
Privacy questions or requests: [email protected].