هذه الصفحة باللغة الإنجليزية. النسخة الإنجليزية هي المعتمدة.
ملخص
نجمع فقط ما نحتاجه لتشغيل الخدمة: بريدك الإلكتروني وتجزئة كلمة المرور إن أنشأت حسابًا، والملفات التي ترفعها، وبيانات الشبكة (مثل عناوين IP) لأغراض الأمان ومنع الإساءة. نفحص الملفات نحن ومزودون موثوقون. لا نبيع البيانات الشخصية. راسل privacy@putit.online للوصول إلى بياناتك أو تصحيحها أو حذفها.
Privacy policy
Last updated 11 October 2026
Put It Online (putit.online) is operated from Singapore. This policy explains what personal data we collect, why, who processes it for us and how long we keep it, in line with Singapore's Personal Data Protection Act 2012 (PDPA). Questions, access or correction requests, and requests to delete your data go to our data protection contact: privacy@putit.online.
What we collect and why
- Files you upload, their names and sizes, to store and serve them to people with the link, and to scan them for abuse (below).
- Account details: your email address and a salted hash of your password (we never store the password itself), your plan, and your links.
- IP address: every upload, sign-up, log-in, report and checkout is checked against public lists of VPN, proxy, Tor, iCloud Private Relay and hosting networks (on our own servers, no lookup service is sent your IP), and counted for rate limits (per IP address; IPv6 per /64 network). The uploader's IP is stored with each link so we can enforce our rules.
- Cookies (all first-party, all needed for the service, no advertising or tracking cookies):
pi_sessionkeeps you logged in (30 days);pi_anonlets you manage links you uploaded without an account (1 year);pi_csrfprotects forms (until you close the browser);pd1bmakes the next pages show what you just changed (60 seconds, after you change something); a per-link unlock cookie remembers that you entered a link's password (7 days). Your browser also keeps a list of your recent uploads in local storage, which never leaves your device. - Usage: daily view counts and referring sites per link (shown to the link's owner), and aggregate page statistics from Cloudflare Web Analytics, which uses no cookies and doesn't identify you.
- Checkout and contact forms: name, email, country, IP and browser type when you subscribe; name, email, company and message when you contact sales. Reports: the reason, details, and your email if you give it.
- Emails we send: password resets, and notices about your account and subscription.
AI assistants, the MCP server and the API
You can use Put It Online from AI assistants such as Claude, ChatGPT, Cursor or VS Code through our MCP server, or from your own code through the API.
- What we receive: only what the assistant sends us when it calls one of our tools: the files or page content to publish, file names, and the link settings it asks for. We don't receive your conversation with the assistant. The assistant provider handles your chat under its own privacy policy.
- Connecting your account (OAuth): we store which app you connected (its name, client ID and redirect address, plus the IP address it registered from, for apps that register themselves), the permissions you approved, and when it was last used. Access tokens are stored only as hashes, last 1 hour, and can be refreshed for up to 30 days. Disconnect any assistant on the Connect to AI page and its access stops immediately. Self-registered apps that are never used are deleted after 30 days.
- API keys: stored only as hashes, with the name you gave them and when they were last used. Revoke them on the Connect to AI page.
- Without an account: we see the IP address the request comes from (for hosted assistants, the provider's server, not you), the name the app gives itself, and an identifier for the conversation: an MCP session ID we issue, or the anonymised user ID ChatGPT sends (
openai/subject). We keep these only as one-way hashes, use them for rate limits and to enforce our rules, and store them with the links created (kept like the uploader IP below). - An app connected to your account may tell us your own IP address (
X-End-User-IP); if it does, we record that IP as the uploader instead of the app's.
Safety scanning
Every upload is checked automatically: quick checks before it goes live, and the full scan within seconds after (before, for large files and while we see a spike in abuse); anything that fails is taken down. Most checks run on our own servers (file type, malware patterns, known-bad file hashes, phishing signs). Some checks use these services:
- OpenAI moderation (OpenAI, USA): images, a few frames sampled from videos (by your browser during upload, deleted after the check), and the text of text and HTML files are sent to OpenAI's moderation API to detect sexual, violent or otherwise harmful content. No account details are sent.
- CIRCL hashlookup (Luxembourg): for risky file types, only the file's SHA-256 fingerprint is looked up, never the file.
Confirmed violations are recorded with the uploader's account, browser token and IP address (or network) so the suspension can be enforced, and fingerprints of removed files are kept so they can't be uploaded again. Child sexual abuse material is preserved and reported to the authorities as the law requires.
Who processes data for us
- Cloudflare hosts the whole service: the website and API, the database (Asia-Pacific region), file storage, email delivery and the analytics above. Requests pass through Cloudflare's global network.
- OpenAI and CIRCL for the scanning described above.
These providers process data on our behalf, outside Singapore in some cases. We only use providers bound to protect it to a standard comparable to the PDPA. We don't sell personal data or share it for advertising.
How long we keep it
| Data | Kept |
|---|---|
| Files | While the link is online (free links: 7 days). Deleted up to 30 days after a link expires, and right away when you delete the link. Files removed for breaking our rules: 30 days, longer only when the law requires us to preserve them. |
| Uploader IP stored with a link | Until 90 days after the link's files are deleted. |
| Rate-limit counters (per IP / account) | 2 days. |
| Connected assistants and API keys | Until you disconnect or revoke them (tokens expire on their own: 1 hour, refreshable for 30 days). Unused self-registered apps: 30 days. |
| Account (email, password hash, links) | Until you ask us to delete your account. Log-in sessions end after 30 days; password-reset links expire after 30 minutes. |
| Checkout records | 2 years. |
| Contact-form messages | 2 years. |
| Abuse reports | 1 year after they're closed (reports of child abuse material: as the law requires). |
| Daily view counts and referrers | About 13 months. |
| Records of violations and suspensions | As long as the suspension applies. |
| Log of emails we sent | 6 months. |
Your rights
Under the PDPA you can ask what personal data we hold about you and how we've used it in the past year, ask us to correct it, and withdraw consent (for example by deleting your links or asking us to close your account). Email privacy@putit.online from the address on your account; we reply within 30 days. If you're not satisfied, you can contact Singapore's Personal Data Protection Commission (pdpc.gov.sg).
Put It Online isn't meant for children under 13. If we learn that a data breach is likely to harm you, we'll notify you and the PDPC as the PDPA requires.
Changes
We'll update this page when our practices change; the date at the top shows the latest version.