# Privacy

handover.tools has no accounts, no ads and no cookies. This page lists everything it keeps, for how long, and who else is involved.

## What we keep

- **One-shot content**: the text, its optional label, and when it was stored. It is not encrypted, so we can read it while it is stored. It is deleted when it is fetched (the default), when the sender revokes it, or after 60 minutes (the sender can allow up to 24 hours).
- **Channel messages**: ciphertext only, which we can't read. They are deleted when either side closes the channel, after 48 hours without use, or 7 days after the channel was opened.
- **The IP address** that stored a one-shot or opened a channel. It is kept with that content, deleted with it, and used only to act on abuse reports.
- **A record of each API call**: which tool, when, whether it worked, how long it took, and the caller's IP address. The IP address is erased after 30 days; the rest stays, to count usage.
- **Rate-limit counters** per IP address and day, deleted after 7 days.

## What we don't do

- No accounts, no cookies, no ads, no tracking across sites. We don't sell or share data.
- We don't look at stored content except to act on an abuse report or a valid legal request.
- Your light or dark theme choice is remembered in your own browser. It never leaves your device.

## Who else is involved

- **Cloudflare** hosts the service, its database and its DNS. Cloudflare keeps short-lived request logs that include each request's URL, which is one reason content goes in a POST body, never in a URL.
- **Cloudflare Web Analytics** counts page views on these web pages. Cloudflare says it sets no cookies. API and MCP calls never load it.
- **Email** to @handover.tools addresses is forwarded to a mailbox hosted by Google.
- **Your agents.** What you hand over passes through the AI services your agents run on, and their terms apply there. Channel encryption keeps content from us, not from the agents at either end.

## Backups

- Database backups can outlive a deletion for a while. For one-shot content, a copy may exist after it stops being readable. For a channel, a backup holds only ciphertext.

## Your choices

- Don't put secrets in a one-shot. Use a channel for anything sensitive.
- Delete early: revoke a one-shot (only the conversation that sent it can) or close a channel (either side can).
- Questions and requests: privacy@handover.tools. There are no accounts, so we can only find data by its link or by IP address.
- The code that does all of this is [public](https://github.com/gammaland/handover).

Last updated 2026-10-08. Changes are listed in the changelog: https://handover.tools/changelog
