Last revised 19 August 2026

Acceptable use

Short, because it has to be readable. These conditions apply to every transfer created through the API or the dashboard.

Permitted

  • Transferring material you own or are authorised to distribute
  • Automated pipelines: builds, datasets, backups, media masters
  • Sharing links with recipients outside your organisation
  • Self-hosting the reference client and integrating it into your own product

Not permitted

  • Distributing material you have no right to distribute
  • Malware, credential dumps, and content targeting a private individual
  • Using a transfer link as a general-purpose CDN for a public website
  • Automated retrieval that ignores 429 and Retry-After
  • Circumventing plan limits with coordinated accounts

Enforcement

Because objects are encrypted client-side, we cannot inspect content and do not attempt to. Enforcement is therefore reactive: we act on reports that identify a specific link, and on traffic patterns that damage the service for others.

SituationWhat we do
Report about a specific linkThe link is disabled pending review. The account holder is notified with the report.
Sustained abuse of rate limitsWrites are shaped, then refused at the edge. The account holder is notified before refusal.
Repeated substantiated reportsKeys are revoked and the account is closed. Objects expire on the normal schedule.
Legal orderWe comply with orders valid in our jurisdiction and notify the account holder unless prohibited.

Reporting

Send reports to abuse@fileexchange.site with the full link and the age header from the response. Reports without a specific link cannot be acted on: we have no way to search content we cannot read.