Likz Drop is a peer-to-peer file-sharing app for Android, iPhone, Mac and Windows. It is built to move your files with as little data collection as possible. This policy explains what we do — and don’t — collect.
The short version
- Live transfers are not kept as cloud files. Contents move device-to-device (or through an encrypted relay that only forwards sealed bytes). Optional Keep 24h for group drops is a separate feature that stores a temporary encrypted copy when you choose it. Hosted Likz Cloud photo backup is discontinued and no longer accepts new uploads.
- We do not sell your data, show ads, or track you across other apps or websites. There are no advertising or analytics SDKs in the app.
- You can use the app as a Guest — no account required to start. An account is optional for linked devices, nickname identity, groups, and Pro.
What the app collects
1. Files you send or receive (live transfer)
File contents are encrypted on your device and sent to the receiving device over your local network or a direct path when possible. When devices are on different networks, the transfer may be relayed as opaque encrypted bytes — the relay cannot read your files and does not keep them as a stored download after the stream ends; it forwards the encrypted stream while the transfer is in progress.
1b. Optional Keep 24h (group drops only)
If you use Keep 24h on a group drop, Likz stores a temporary encrypted copy so members can download it after the sender goes offline. Keep is opt-in for that feature path, subject to Free/Pro storage quotas (see Pricing), and copies are removed when retention expires or you remove the drop. Live one-to-one transfers do not use Keep unless you use that group feature.
1c. Likz Cloud Photo Backup (discontinued)
Likz Cloud Photo Backup no longer accepts new uploads. Previously stored hosted photo objects have been deleted. Keep 24h group copies are a different product and are unchanged. Pro’s 200 GB allowance is for Keep 24h only.
2. Account information (only if you sign in)
By default you can use Guest mode (an anonymous session with an auto-generated nickname) and provide nothing. If you choose to sign in, we may store identifiers needed for your account depending on the method you use:
- Email + one-time code — your email address for sign-in and recovery.
- Sign in with Google / Apple — the identity token and profile fields those providers return (typically a stable provider id and email or private relay email), so we can create or link your account.
We do not receive your full payment card details when you buy Pro through the App Store or other platform stores; those platforms process payment and we receive subscription or entitlement status needed to unlock Pro.
3. Nickname
A short public handle (e.g. @bluefox42) so others can send to you. Guests get a random one; signed-in users may choose their own. Nicknames are filtered against a blocklist of offensive or reserved names.
4. Device presence (for your own devices)
To let you send between your signed-in devices and find devices nearby, we store, per device: a device id and name, local network address, online status, last-seen time, and a push-notification token. This is visible only to your own account.
5. Transfer signaling (transient)
When you send by nickname we create a short-lived “offer” record containing the sender/recipient, nickname, a local address, a one-time transfer token, and file metadata only (names and sizes — never contents). These records expire automatically.
6. Share links & groups
Share-by-link and group features may store link or room tokens, membership, and related metadata so downloads and group drops work. Abuse and rate-limit logs may retain IP and request metadata for security for a limited period.
7. Notifications
On mobile we use a push token (APNs / FCM) to notify you of incoming files. Desktop uses local operating-system notifications (no remote token required for local alerts).
We do not collect your contacts, location, advertising identifiers, or usage analytics. We access your photo library only when you pick media to send, save received media, or explicitly start the opt-in foreground Photo Backup described below. Photo Backup now copies to a same-account PC or a user-owned remote. Optional Keep 24h stores encrypted group blobs. Legacy Likz Cloud photo objects, if any, remain downloadable from the app until we announce deletion.
Website analytics
Our public website uses a self-hosted, cookieless OpenPanel deployment to understand aggregate page usage and improve navigation. Website analytics is on by default unless you opt out or your browser sends Global Privacy Control or Do Not Track. OpenPanel does not store raw IP addresses or use analytics cookies; its anonymous visitor identifier rotates daily. We do not send file contents, file names, query parameters, share-link fragments, advertising identifiers, or cross-site profiles.
You can change this at any time through Analytics settings in the website footer. Choosing “Turn off analytics” prevents future analytics events on that browser.
Service providers (data processors)
We use a small number of trusted providers solely to operate the app; they process data on our behalf under their own terms and security commitments:
- Authentication & database (Supabase) — account sign-in, nicknames, device presence, transfer signaling, groups/share metadata.
- Push notifications (Firebase / APNs / FCM) — delivering incoming-file alerts on mobile (device token).
- Transfer relay — forwarding encrypted file bytes between devices on different networks. It does not decrypt live file contents and does not keep live streams as permanent storage.
- Object storage for Keep 24h — temporary encrypted blobs for optional group Keep copies, deleted after retention or when you remove the drop.
- Object storage for leftover Likz Cloud photos — client-encrypted Photo Backup batches uploaded before hosted photo backup was discontinued; no new objects are accepted. Existing objects stay until a published deletion notice.
- Website analytics (self-hosted OpenPanel) — cookieless aggregate website usage statistics; no raw IP storage, advertising profiles, file data, query parameters, or share-link fragments.
- App stores / billing platforms — process Pro purchases; we store entitlement or transaction identifiers needed to unlock Pro, not full card numbers.
Device permissions
The app may request: Local Network (to discover nearby devices), Bluetooth (to find nearby devices for offline transfers, where supported), Notifications, Photos / Media (to pick media to send, save received media, or—only after you opt in—run foreground Photo Backup), and limited storage access (to save received files and pick files to send). Each permission is used only for these purposes. Limited Photos access restricts backup to media the operating system makes accessible.
Photo Backup asks for broader Photos/Media access only after a signed-in user explicitly starts a foreground backup to a selected same-account PC or user-owned remote (NAS / WebDAV / S3). It inventories and copies the full library the operating system makes accessible; limited Photos access restricts that to the media the operating system exposes. iCloud originals may download while it runs. Data normally transfers directly to the selected local For PC targets, data uses the direct path when possible and the existing encrypted fallback relay across networks. User-owned remote targets receive HTTPS uploads directly from the phone. Hosted Likz Cloud no longer receives new batches. Checkpoint metadata stays on the device; Likz never deletes source media, and starting over clears only checkpoint metadata (manual destination deletion does not invalidate it).
How long we keep data
- Live transfer bytes: not retained as cloud files after the stream ends.
- Keep 24h objects: temporary; deleted when retention expires (about 24 hours) or when you remove the drop, subject to normal job scheduling.
- Likz Cloud Photo Backup objects: hosted photo copies have been deleted. New uploads are rejected.
- Transfer-signaling records: short-lived; expire automatically.
- Device presence: refreshed while you use the app; goes offline by timeout.
- Account (email / provider id, nickname): kept until you delete your account.
- Billing entitlements: kept while a subscription is active and as needed for accounting or fraud prevention after cancellation.
Your choices and rights
- Use without an account (Guest mode) — provide no personal data to start sending.
- In-app privacy controls — block specific contacts, or set “only receive from contacts” to auto-decline strangers.
- Delete your account — use in-app account deletion where available, or follow Delete your Likz Drop account. You can also email privacy@likz.me. We will action deletion of account profile, device, and signaling data within a reasonable period; some security or billing records may be retained where required by law.
Children
Likz Drop is a general-audience utility and is not directed to children under 13 (or the minimum age in your country). We do not knowingly collect personal data from children.
Security
For a plain-language data-flow diagram of paths (LAN, relay, offline, share link, Keep 24h), see Security & data flow.
Live transfers are end-to-end encrypted with a unique key per transfer, and the connection between your two devices is verified when the product supports that path. Connections to our service providers use TLS. No method is 100% secure, but we design the product to minimize the data that exists in the first place.
Changes to this policy
We may update this policy from time to time. We will revise the “Last updated” date above and, for material changes, note them in the app or on our website.
Contact
Questions or data requests: privacy@likz.me.