Last updated July 27, 2026
Privacy
Share by iill stores the HTML or Markdown you publish so it can provide the temporary link you requested. Do not publish secrets, credentials, sensitive personal data, or anything you do not have permission to share.
What we process
We process published content, link settings, coarse service logs, hashed rate-limit identifiers, and—if you sign in—your account identifier and OAuth profile. Passwords for protected shares and private management tokens are not stored in plaintext.
Product measurement and viewer sessions
The publisher keeps a random product-measurement session in your browser’s local storage for up to seven days. The isolated viewer uses a strictly necessary, HttpOnly session cookie for up to seven days so repeated opens can be counted consistently and abuse can be limited. A password-protected preview also uses a strictly necessary, HttpOnly unlock cookie for up to 30 minutes.
Measurement records may include the action name and time, pseudonymous HMAC-derived session and share identifiers, locale, landing or input type, selected expiry, whether a password was enabled, a coarse content-size range, referral channel, and a bounded result code. These product records do not contain published content, raw share URLs, passwords, management tokens, email addresses, or full IP addresses.
Why and for how long
Data is used to create, protect, operate, and prevent abuse of temporary links. Anonymous content expires according to the duration you select and is removed by automated cleanup. Product-measurement events are deleted after 90 days. Browser sessions expire after seven days, while rate-limit identifiers rotate or expire with their bounded quota windows. Limited security, billing, and operational records may remain longer where needed to prevent abuse, resolve transactions, or satisfy legal obligations.
Service providers
Cloudflare provides the application runtime, database, DNS, and delivery network. OAuth and payment providers process information under their own policies when those optional features are enabled.
Your choices
Use the private management link to update or delete a share. You can clear local storage and iill cookies in your browser at any time; doing so starts a new pseudonymous session and may require you to unlock protected previews again. Signed-in users can manage linked accounts and request account deletion from the account page. For an account access or privacy request, email contact@iill.dev.