PRIVACY
Only what the transfer needs.
Astral stores your account identifier—or a temporary anonymous guest identifier—plus file metadata and file content in Firebase until the selected expiry or an earlier manual deletion.
Share links are unguessable and are not listed publicly. Anyone who has a valid link can download its file before expiry.
When you paste an image link into a third-party service, that service may fetch and cache the social preview independently. Astral cannot remove copies held in another provider’s cache.
Firebase and Vercel process the technical data required to authenticate users, store transfers, and serve the application.
Astral separates necessary browser storage from optional analytics and advertising. Optional providers are initialized only after the matching consent, and the versioned first-party choice uses a Secure, SameSite=Lax cookie plus a localStorage mirror. Global Privacy Control and Do Not Track keep non-essential categories off while those signals are active. You can review categories and reopen the controls in the Cookie notice.
When you use a paid plan, Stripe processes your billing contact details, payment method, tax information, invoices, subscription status, and refunds. Astral stores Stripe customer, subscription, invoice, and refund identifiers plus the plan status needed to grant account limits; Astral does not store full card details.
Selected public content pages may show advertising supplied by Google AdSense. A guest upload may also offer an explicitly accepted Google Ad Manager rewarded ad as a shortcut to the visible-tab wait. Google and its advertising partners may use cookies, local storage, device information, and interaction data to deliver, secure, and measure ads. Astral keeps Google advertising disabled in production unless a Google-certified consent platform is configured; where required in the EEA, the United Kingdom, or Switzerland, that platform must collect the applicable advertising choices before ads are requested.
Paid Aether accounts do not receive advertising. Astral does not place ads in the private dashboard, status page, direct share or download pages, or upload-request flows. Declining or blocking a rewarded guest-upload ad leaves the non-ad wait available.
Outage reports are stored privately for up to 30 days. Public status totals expose only counts by area; the optional text and a one-way network rate-limit key are never shown publicly.
For account security, Astral records active browser and Chrome-extension sessions with creation, expiry, and last-use times plus a derived browser/operating-system label and the rough city/country headers supplied by Vercel. Raw IP addresses and full user-agent strings are not retained in these session records. You can revoke one session or all sessions from the Account page.
The Chrome extension keeps its revocable session, preferences, recent upload jobs, synchronized request summaries, notification deduplication markers, and—if you connect it—the selected extension-folder handle in Chrome's local extension storage or IndexedDB. When connected, it performs a bounded account sync every 15 minutes while Chrome is running. System notifications are disabled by default, require an optional Chrome permission, and can be configured separately for newly received and soon-expiring files. Direct off-store updates are also opt-in: the extension checks a pinned Astral release, verifies its size, SHA-256, per-file ZIP checksums, safe paths, version, and manifest identity, and writes only after Chrome grants access to the chosen unpacked folder.
Signed-in users can download a machine-readable copy of the account data Astral can attribute to them from the Account page. Passwords, password hashes, access tokens, webhook secrets, and PIN digests are never included.
Permanent account deletion cancels any Stripe subscription, deletes the Stripe customer and stored payment methods, revokes account and extension access, and removes attributable Astral data. In-flight upload reservations remain quarantined for their anti-race grace period before automated cleanup. Shared deduplicated bytes needed by another user may remain, but the deleted account identifier is replaced. Stripe may retain transaction records where accounting or law requires it, and a one-way deletion marker is retained for up to 30 days to prevent delayed billing webhooks from recreating the account.