Last updated August 2026

Privacy Policy.

AlterSend is a peer-to-peer file transfer application operated by Devaprime LLC. This policy explains what information AlterSend processes, where it goes, and your choices.

The short version

AlterSend has no accounts and no cloud storage of its own. In most cases, files go directly between your devices and never pass through our infrastructure. A relay feature (on by default, and you can turn it off) can route encrypted data through a server we operate when a direct connection isn't possible — the data stays end-to-end encrypted the whole way, so we still can't see it. We collect almost nothing by default.

If you have not bought a subscription, the app never contacts our subscription service at all — not at launch, not in the background, never. You can check that yourself: the apps are open source, and you can watch your own device's network traffic.

What we collect

1. Files you transfer

Files are transferred between the two devices involved in a session, encrypted with the Noise protocol (Curve25519 key exchange + ChaCha20-Poly1305). We use no cloud storage — your files are never stored on our servers, whether a transfer completes directly or via the optional relay described below. We never see the contents of your transfers.

2. IP addresses and peer discovery

AlterSend uses Hyperswarm, a distributed hash table (DHT), to help two devices find each other. When you start a transfer session, your device's IP address is briefly visible to other nodes on the DHT network. This is an inherent property of any peer-to-peer system that uses a public DHT for discovery. The connection itself is encrypted; only the IP used to reach you is visible to DHT participants, not your file contents or the join code.

We do not operate the DHT ourselves. It is a decentralized network run by its participants.

3. The optional relay feature

AlterSend includes a relay feature (Settings → Relay) that is on by default; you can turn it off at any time. While it is on, and a direct connection between two devices isn't possible (for example, both devices are behind a VPN or a restrictive network), your transfer may route through a relay server that we operate, located in Frankfurt, Germany, or Singapore. The browser receiver at app.altersend.com always connects through one of these relays, since a browser can't make a direct peer-to-peer connection.

The relay is "blind": it forwards encrypted data between two devices without any ability to decrypt it — the same Noise-encrypted stream as a direct transfer. While a transfer is relayed, our relay server can see the temporary connection keys used for that session, the IP addresses of the two devices, and the volume and timing of data moved — but never file names, file contents, or any information about what was sent.

We do not keep per-transfer or per-user logs of relay activity. We retain only an aggregate monthly total of data relayed, used to manage server capacity and stay within our hosting budget.

The same applies to our subscription service: request logging is switched off there, so the IP addresses that reach it are not written down or retained by us. Cloudflare, which hosts it, keeps its own short-lived operational and anti-abuse records under its own policy, as any hosting provider does.

4. Crash reports (optional, opt-in)

Mobile (iOS / Android): Crash reporting is disabled by default. You can enable it in Settings → Crash reports. When enabled, the app sends crash data to Sentry (a third-party service operated by Functional Software, Inc., based in the United States).

Desktop (macOS / Windows / Linux): Crash reporting is controlled by the toggle in the footer settings panel. When enabled, both the renderer and the main process send crash data to Sentry.

What Sentry receives when crash reporting is on:

  • Crash stack traces and unhandled error messages
  • Device model, operating system version, and app version
  • Recent in-app events leading up to the crash (e.g. which screen was active)
  • A randomly-generated installation identifier, not linked to your identity
  • No file names, file contents, peer keys, or personal information is intentionally included

Sentry's own privacy policy is at sentry.io/privacy. Event data is retained for 90 days.

5. Camera access (iOS / Android)

The camera is used only to scan the QR code shown on the sender's screen. No images are captured or stored by AlterSend.

6. Photo and media library access (iOS / Android)

AlterSend requests access to your photo library only when you choose to send photos or videos, or when you accept received images and save them to your library. We do not scan, upload, or analyse your photos.

7. Local storage

AlterSend stores the following on your device only:

  • A per-session Noise key pair used to authenticate your device to a peer during a transfer. This key is ephemeral and is not synced or uploaded anywhere.
  • Your crash-reporting preference (on/off).
  • Your relay feature preference (on/off).
  • Your AlterSend Pro code, if you have one, held in the system keychain on mobile and in the operating system's encrypted store on desktop.
  • Pending transfer state while a transfer is in progress.

All local data is removed when you uninstall the app.

8. AlterSend Pro subscriptions (optional)

AlterSend Pro is an optional paid subscription that raises the size limits on relayed transfers and gives your transfers priority when a relay is busy. Direct peer-to-peer transfers are unlimited for everyone, free or paid. Buying Pro still does not create an account.

When you subscribe you receive a 16-digit code. That code is your subscription — you enter it to activate Pro on your other devices. We store only a SHA-256 hash of it, alongside the plan tier and the date it is valid until. We do not store the code itself, which is why we cannot recover it for you if you lose it.

Payments are processed by Apple, Google, or Stripe, depending on where you buy. We never receive or store your card details. For purchases made by card, we store the Stripe customer identifier next to your code hash so that the "Manage subscription" button can open your billing portal — Stripe knows who you are, and that link is the only connection between your payment and your code. For purchases made in the iOS or Android app, Apple or Google knows who paid; we receive only the fact that a valid subscription exists.

We use RevenueCat to validate App Store and Google Play receipts. RevenueCat receives the SHA-256 hash of your code as an identifier, the purchase itself, and the store and country it came from. The app contacts RevenueCat only when you open the upgrade screen or act on a subscription — if you never open it, it is never contacted.

While a subscription is active, the app periodically checks that it is still valid: at launch, when you return to the app, and roughly every twelve hours. Those requests carry your code and, like any HTTPS request, the IP address you connect from. We do not retain request logs. If you have never purchased Pro, the app makes none of these requests at all.

What we do not collect

  • Your name, email address, phone number, or any account credentials — AlterSend has no accounts.
  • Your location.
  • Any identifiers from advertising networks or analytics SDKs.
  • Your payment card details. Card payments are handled entirely by Stripe, and in-app purchases entirely by Apple or Google.
  • The content of your transfers — file names, file contents, or previews — under any circumstance, whether a transfer is direct or relayed.

Third-party services

ServicePurposePolicy
SentryCrash reporting (opt-in)sentry.io/privacy
Hyperswarm DHTPeer discoveryDecentralized; no central operator
StripeCard payments for Prostripe.com/privacy
RevenueCatApp Store and Google Play receipt validationrevenuecat.com/privacy
CloudflareHosting for the subscription servicecloudflare.com/privacypolicy
SupabaseDatabase holding subscription code hashes and expiry datessupabase.com/privacy

We do not use advertising SDKs, analytics platforms, or tracking pixels.

Children's privacy

AlterSend is not directed at children under 13 years of age. We do not knowingly collect information from children. If you believe a child has provided information through the app, please contact us and we will delete it promptly.

Data deletion

Because AlterSend has no accounts and no cloud storage, there is almost nothing to delete from our systems. All data stored by the app lives on your device and is removed when you uninstall it.

If you have an AlterSend Pro subscription, we hold one record: the hash of your code, the plan tier, and the date it runs until. It contains no name, email, or device identifier. Cancel the subscription and the record simply expires; to have it removed sooner, email us from anywhere with your code and we will delete it. Stripe, Apple, and Google keep their own payment records under their own policies and tax obligations, which we cannot delete on your behalf.

The optional relay feature does not retain any data tied to your device: relayed bytes are discarded immediately once your transfer completes, and we keep only an aggregate monthly total, not per-user records.

If you enabled crash reporting and want Sentry to delete your crash events, you can contact Sentry directly at sentry.io/privacy referencing AlterSend as the application.

Changes to this policy

If we make material changes we will update the "Last updated" date at the top of this page and, where appropriate, notify users via the app or release notes.

Contact

AlterSend is a product of Devaprime LLC. Questions or concerns about this policy: hello@altersend.com

To report abusive content received through the app: abuse@altersend.com