P PassToView
Create publicationMy publications
No registration or trackersRU

Draft · version 4 September 2026

Privacy Policy

PassToView shares text, photos, and audio through a password-protected link without registration. This page describes the service's actual data processing.

What is stored

Content and comments are encrypted at rest on the server. Each publication has a separate data key wrapped by a server-side encryption key. This is encryption at rest, not end-to-end encryption: the server can technically decrypt data when the key is available. Passwords are stored as Argon2id hashes; only SHA-256 digests of session tokens are stored.

Data minimisation

The service requires no name or account, sets no advertising or analytics cookies, uses no external analytics, and does not estimate unique visitors. Daily metrics contain aggregate page and action counters only—no IP, User-Agent, public_id, email, referrer, or per-user history.

To limit credential guessing, keyed HMAC digests derived from the request source are retained temporarily instead of raw IP addresses. Expired security buckets are removed by maintenance.

Email

Email for sending an Owner Link is optional, used for that delivery only, not stored in the Owner/Publication database, and not used for account recovery. Configured SMTP infrastructure may process it temporarily. An email voluntarily supplied with an abuse report is stored with that report for follow-up.

Retention and deletion

Link unavailability, logical deletion, and physical purge are separate stages. After expiry, recipient access ends; after the retention period, a publication is marked deleted. Physical purge runs separately under the current service setting and may not be immediate. Backups have a separate lifecycle.

Contact

The privacy@passtoview.ru mailbox is planned but has not yet been verified by the owner. Until it is verified, use the available service forms.

PassToView · password-protected link sharing
PrivacyTermsAcceptable useCopyrightReport abuseSecurity