AlterSend is a peer-to-peer file transfer application operated by Devaprime LLC. This policy explains what information AlterSend processes, where it goes, and your choices.
AlterSend has no accounts and no cloud storage of its own. In most cases, files go directly between your devices and never pass through our infrastructure. A relay feature (on by default, and you can turn it off) can route encrypted data through a server we operate when a direct connection isn't possible — the data stays end-to-end encrypted the whole way, so we still can't see it. We collect almost nothing by default.
If you have not bought a subscription, the app never contacts our subscription service at all — not at launch, not in the background, never. You can check that yourself: the apps are open source, and you can watch your own device's network traffic.
Files are transferred between the two devices involved in a session, encrypted with the Noise protocol (Curve25519 key exchange + ChaCha20-Poly1305). We use no cloud storage — your files are never stored on our servers, whether a transfer completes directly or via the optional relay described below. We never see the contents of your transfers.
AlterSend uses Hyperswarm, a distributed hash table (DHT), to help two devices find each other. When you start a transfer session, your device's IP address is briefly visible to other nodes on the DHT network. This is an inherent property of any peer-to-peer system that uses a public DHT for discovery. The connection itself is encrypted; only the IP used to reach you is visible to DHT participants, not your file contents or the join code.
We do not operate the DHT ourselves. It is a decentralized network run by its participants.
AlterSend includes a relay feature (Settings → Relay) that is on by default; you can turn it off at any time. While it is on, and a direct connection between two devices isn't possible (for example, both devices are behind a VPN or a restrictive network), your transfer may route through a relay server that we operate, located in Frankfurt, Germany, or Singapore. The browser receiver at app.altersend.com always connects through one of these relays, since a browser can't make a direct peer-to-peer connection.
The relay is "blind": it forwards encrypted data between two devices without any ability to decrypt it — the same Noise-encrypted stream as a direct transfer. While a transfer is relayed, our relay server can see the temporary connection keys used for that session, the IP addresses of the two devices, and the volume and timing of data moved — but never file names, file contents, or any information about what was sent.
We do not keep per-transfer or per-user logs of relay activity. We retain only an aggregate monthly total of data relayed, used to manage server capacity and stay within our hosting budget.
The same applies to our subscription service: request logging is switched off there, so the IP addresses that reach it are not written down or retained by us. Cloudflare, which hosts it, keeps its own short-lived operational and anti-abuse records under its own policy, as any hosting provider does.
Mobile (iOS / Android): Crash reporting is disabled by default. You can enable it in Settings → Crash reports. When enabled, the app sends crash data to Sentry (a third-party service operated by Functional Software, Inc., based in the United States).
Desktop (macOS / Windows / Linux): Crash reporting is controlled by the toggle in the footer settings panel. When enabled, both the renderer and the main process send crash data to Sentry.
What Sentry receives when crash reporting is on:
Sentry's own privacy policy is at sentry.io/privacy. Event data is retained for 90 days.
The camera is used only to scan the QR code shown on the sender's screen. No images are captured or stored by AlterSend.
AlterSend requests access to your photo library only when you choose to send photos or videos, or when you accept received images and save them to your library. We do not scan, upload, or analyse your photos.
AlterSend stores the following on your device only:
All local data is removed when you uninstall the app.
AlterSend Pro is an optional paid subscription that raises the size limits on relayed transfers and gives your transfers priority when a relay is busy. Direct peer-to-peer transfers are unlimited for everyone, free or paid. Buying Pro still does not create an account.
When you subscribe you receive a 16-digit code. That code is your subscription — you enter it to activate Pro on your other devices. We store only a SHA-256 hash of it, alongside the plan tier and the date it is valid until. We do not store the code itself, which is why we cannot recover it for you if you lose it.
Payments are processed by Apple, Google, or Stripe, depending on where you buy. We never receive or store your card details. For purchases made by card, we store the Stripe customer identifier next to your code hash so that the "Manage subscription" button can open your billing portal — Stripe knows who you are, and that link is the only connection between your payment and your code. For purchases made in the iOS or Android app, Apple or Google knows who paid; we receive only the fact that a valid subscription exists.
We use RevenueCat to validate App Store and Google Play receipts. RevenueCat receives the SHA-256 hash of your code as an identifier, the purchase itself, and the store and country it came from. The app contacts RevenueCat only when you open the upgrade screen or act on a subscription — if you never open it, it is never contacted.
While a subscription is active, the app periodically checks that it is still valid: at launch, when you return to the app, and roughly every twelve hours. Those requests carry your code and, like any HTTPS request, the IP address you connect from. We do not retain request logs. If you have never purchased Pro, the app makes none of these requests at all.
| Service | Purpose | Policy |
|---|---|---|
| Sentry | Crash reporting (opt-in) | sentry.io/privacy |
| Hyperswarm DHT | Peer discovery | Decentralized; no central operator |
| Stripe | Card payments for Pro | stripe.com/privacy |
| RevenueCat | App Store and Google Play receipt validation | revenuecat.com/privacy |
| Cloudflare | Hosting for the subscription service | cloudflare.com/privacypolicy |
| Supabase | Database holding subscription code hashes and expiry dates | supabase.com/privacy |
We do not use advertising SDKs, analytics platforms, or tracking pixels.
AlterSend is not directed at children under 13 years of age. We do not knowingly collect information from children. If you believe a child has provided information through the app, please contact us and we will delete it promptly.
Because AlterSend has no accounts and no cloud storage, there is almost nothing to delete from our systems. All data stored by the app lives on your device and is removed when you uninstall it.
If you have an AlterSend Pro subscription, we hold one record: the hash of your code, the plan tier, and the date it runs until. It contains no name, email, or device identifier. Cancel the subscription and the record simply expires; to have it removed sooner, email us from anywhere with your code and we will delete it. Stripe, Apple, and Google keep their own payment records under their own policies and tax obligations, which we cannot delete on your behalf.
The optional relay feature does not retain any data tied to your device: relayed bytes are discarded immediately once your transfer completes, and we keep only an aggregate monthly total, not per-user records.
If you enabled crash reporting and want Sentry to delete your crash events, you can contact Sentry directly at sentry.io/privacy referencing AlterSend as the application.
If we make material changes we will update the "Last updated" date at the top of this page and, where appropriate, notify users via the app or release notes.
AlterSend is a product of Devaprime LLC. Questions or concerns about this policy: hello@altersend.com
To report abusive content received through the app: abuse@altersend.com