privacyhow-to

The Hidden Privacy Cost of Sending Files With WeTransfer

WeTransfer stores your files longer than you'd expect, grants itself broad license rights, and shares data with advertisers. Here's what to know.

You need to send a large file to someone. A video, a PDF, a set of photos. It’s too big for email, so you drag it into WeTransfer, paste the recipient’s address, and hit send. Seven days later the link expires and the file disappears. Simple. Private. Done.

Except it isn’t quite that simple.

Temporary file sharing services — WeTransfer, Send Anywhere, file.io, Smash, Filemail, and a dozen others — have quietly become a common channel for moving sensitive documents. Contract drafts. Medical scan results. Tax returns. Immigration paperwork. Client deliverables. And the privacy terms governing what happens to those files during the upload window are almost never read.

What “Temporary” Actually Means

The defining feature of services like WeTransfer is that files expire. On the free tier, WeTransfer deletes files after seven days. Paid subscribers can extend this to a year. After expiry, the file is removed from their servers.

The obvious assumption: the file lives for seven days, then it’s gone.

The reality is a little more complicated. Deletion timelines cover the hosted file itself — the bytes you can download. They don’t necessarily cover:

  • Metadata: Information about the transfer, including sender email, recipient email, IP addresses, file names, file sizes, and timestamps
  • Server logs: Infrastructure logs that capture access patterns and can persist beyond the content deletion window
  • Backup copies: Content delivery and redundancy systems may hold temporary copies in additional locations
  • Analytics data: Aggregated data about file types, transfer volumes, and usage patterns derived from your transfer

WeTransfer’s privacy policy acknowledges retaining “usage data” for analysis and service improvement purposes even after file deletion. The exact retention period for this metadata is not specified in their public terms.

The License Rights Nobody Reads

When you upload a file to WeTransfer, you agree to terms of service. Those terms contain a content license.

WeTransfer’s terms grant the company a non-exclusive, worldwide, royalty-free license to store, display, adapt, reproduce, and sublicense your content for the purposes of operating the service. The “adapt” and “sublicense” language is broader than most people expect from what they perceive as a simple file courier.

To be clear: WeTransfer’s stated policy is that they don’t commercially exploit your file content or use it to train AI models. But a terms-of-service license is a legal instrument that exists independently of stated policy. If WeTransfer’s policy changes, if they’re acquired by another company, or if they’re served with a lawful request, those license rights follow the content.

Competitors have similar structures. Send Anywhere, Smash, and file.io all grant platform-level licenses over uploaded content as a condition of using the service.

Encryption Isn’t the Same as Privacy

Most reputable temporary file sharing services encrypt files in transit (TLS) and at rest (typically AES-256). This is meaningful protection against interception during transfer.

Encryption at rest, however, means the files are encrypted on the server — with the service holding the decryption keys. A WeTransfer employee, a court order, a data breach, or a change in company ownership can all create scenarios where encrypted files become accessible to parties beyond you and your intended recipient.

Zero-knowledge encryption — where keys are derived from a password you control and never leave your device — is not a feature of most mainstream temporary file sharing services. Internxt, for example, offers this for permanent storage; it’s rare for ephemeral transfer tools.

What you’re getting with standard encryption on these services is confidentiality from passive eavesdroppers on the network. You’re not getting confidentiality from the service itself.

The Advertising Layer

Free tiers of temporary file sharing services are supported by advertising, and that creates a data collection dynamic that goes beyond the files themselves.

WeTransfer uses cookies, pixel trackers, and advertising SDKs. Their privacy policy explicitly states they collect personal data, device identifiers, location data, and behavioral signals, and share this information with advertising partners and service providers.

Your upload — even if the file content is never examined — generates signals: the fact that you’re using the service, when you use it, what size files you send, how often, and from what type of device. These signals have commercial value independent of what the file contains.

If you’re on the free tier, you are, in the traditional sense, also the product.

What Categories of Files Are Most at Risk?

Not every file warrants heightened scrutiny. Sending a public press release or a generic template carries very different risk than other document types. Files that deserve particular caution include:

Legal documents — Contracts, NDAs, settlement agreements, litigation materials, and powers of attorney often contain explicit confidentiality obligations. Many legal agreements between clients and their legal counsel explicitly prohibit sharing document content with third-party platforms without explicit authorization.

Medical records and imaging — Health records, lab results, insurance documents, and medical imaging files contain protected health information. Passing these through a consumer file sharing service typically does not satisfy HIPAA or equivalent obligations, because these platforms don’t offer Business Associate Agreements.

Financial documents — Tax returns, bank statements, loan applications, and investment records contain account numbers, Social Security numbers, and financial data with a long shelf life of usefulness to identity thieves.

Identity documents — Passport scans, driver’s license images, and national ID copies should never pass through an ephemeral service unless you have explicit knowledge of the security model.

Client work — If you’re sending files on behalf of a business client, your contractual obligations to that client may extend to how you transmit their data.

Better Alternatives for Sensitive Files

The goal isn’t to abandon file sharing — it’s to match the tool to the sensitivity of the content.

For genuinely confidential files, use a service where you control the encryption keys, or send via a channel with built-in confidentiality guarantees. Signal’s “Note to Self” feature, ProtonMail with encrypted attachments, or a shared SFTP/SSH endpoint are all more defensible choices.

For files you want to host yourself, services like Nextcloud allow you to run your own file sharing server with your own data retention policies.

For personal memories and important documents, a privacy-focused storage service lets you organize and share files without the advertising-supported data collection model.

If you must use a temporary sharing service, prefer paid tiers over free tiers (fewer advertising data flows), use strong download passwords when offered, and avoid it for anything covered by a confidentiality agreement or regulatory obligation.

What Happens When These Services Get Acquired or Shut Down?

Temporary file sharing is a competitive, low-margin market. Services in this space frequently get acquired, pivot, or shut down.

WeTransfer has changed hands and pivoted strategy multiple times. When a file sharing service is acquired, the acquiring company inherits its terms of service — and its rights under those terms.

This matters for a reason beyond active data misuse. User data is often listed as an asset in M&A transactions. The privacy policy you agreed to when you first used a service may have been amended multiple times since. Notifications of policy changes are typically buried in account emails that most users don’t read.

A file you sent two years ago through a service that has since been acquired may now be covered by a different company’s terms.

Practical Audit: What’s Still Out There?

Most people have used temporary file sharing services dozens of times without thinking about what persists after the link expires.

A useful practice: search your email for “WeTransfer” or “file.io” or similar service names. Look at what you’ve sent. Consider whether any of those transfers involved files you’d be concerned about if they were associated with your email address in a data breach.

Then ask yourself: would you have made those transfers differently if you’d read the terms first?

The Metadata Is the Exposure

The file itself may genuinely expire and be deleted. The record of the transfer — who sent what, to whom, from which device, when — is a different matter.

Metadata of this type is often more durable than content, and it can be more revealing than any single file. A pattern of transfers — your email address sending files to a lawyer’s address around a particular time period, or to a recruiter’s address while you were ostensibly happy in your current job — tells a story even without the file contents.

Privacy on temporary file sharing services requires thinking about metadata as carefully as content.

The Minimal Footprint Principle

For sensitive file transfers, the cleanest approach is one that leaves the smallest possible record on third-party infrastructure. That means:

  • Using services that don’t require account creation when possible
  • Preferring services that don’t run advertising (meaning they have fewer incentives to collect data)
  • Choosing services that offer password protection and automatic deletion
  • Never uploading files covered by a professional confidentiality obligation to a general-purpose consumer platform
  • Storing originals in a location you control, not in the ephemeral service itself

The convenience of services like WeTransfer is real. So is the privacy cost. For casual non-sensitive file transfers, the tradeoff is probably acceptable. For anything that matters, it deserves a closer look.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts