Privacy Policy
Last updated: October 4, 2026. How we handle shares and sender accounts.
1. Sharing and Optional Accounts
Basic sharing and receiving do not require an email address or traditional account. Woff creates an anonymous session identifier to enforce room membership and ownership. If you choose a sender account, we use your email address for sign-in and account support. Files, notes, and any personal details you choose to put in them are stored to provide the sharing service.
2. Data Storage and Retention
We hold your files, notes, and text to make sharing possible. Woff is for instant sharing, not permanent cloud storage or backups. Keep your own copy of anything you need.
- Temporary Spaces: Non-Pro spaces expire after 48 hours without new or edited content. Opening a room or downloading files does not reset the timer. Adding content or editing a note starts a new 48-hour window. Expired spaces become unavailable to open and their content is scheduled for permanent deletion.
- Extension Uploads: Chrome extension uploads expire 48 hours after upload, even if the room stays active or is Pro.
- Pro Spaces: Pro handoff rooms have a fixed 7- or 30-day expiry. Activity does not extend that deadline. Download everything you need before expiry; Woff is not permanent storage or a backup.
- Manual Deletion: A sender can delete their own messages; the room owner can delete the complete room. Content is scheduled for storage cleanup. Deleted content is not recoverable through an ownership key.
3. Cookies and Browser Data
Functional browser data supports sign-in, ownership, preferences, and draft recovery. Public-page measurement, if enabled, is described separately below.
- Session cookies: Supabase Authentication provides anonymous or signed-in sessions used to authorize access. Optional email sign-in links are separate from room invitation and recovery secrets.
- Local storage: Used for interface preferences, unsaved note recovery drafts, the last used room, and locally saved room recovery keys. Clearing browser data can remove these local copies.
4. Analytics Services
Third-party analytics scripts are disabled. Private first-party daily counters measure room and note creation, file publication, authorized share or download initiation, and upload failure. These counters contain no note contents, filenames, titles, invitation links, room codes, recovery keys or user identifiers. Service operations can retain session identifiers, timestamps, usage records and security or error records needed for access control, quotas, billing and support. A download initiation counter does not prove that a download completed.
5. Service and Checkout Providers
Woff uses hosting, authentication, database, and file-storage providers to operate the service. Shared content is processed by these systems so recipients can view it; Woff does not provide end-to-end encryption. A private note restricts access to its creator, while shared room content is available to authorized participants.
If checkout is available, the provider identified at checkout handles payment details and may collect billing and tax information. Woff keeps purchase or subscription references and status to manage your plan. Full card numbers are handled by the checkout provider, not stored by Woff.
6. Access, Deletion, and Questions
Use room controls to remove owned content. For account-data or deletion requests, contact us from the account email so ownership can be verified. Deleting a room does not withdraw copies recipients already downloaded. Billing records needed to handle transactions, disputes, or required record keeping may remain after content is removed.
Contact us about your data