Small window. Smaller target.
Security
Last updated: [Date]
A zap carries a file, not a lifetime of data. Security starts with encrypted movement and limited access. The biggest control is the fuse: the file does not stay.
The fuse is a control
Every zap has a deadline. When it expires, the file is deleted automatically. That limits how long a forgotten link or stored object can remain exposed. Temporary storage is part of the security model, not decoration.
Across the wire
Uploads, status checks, zap links, and downloads use HTTPS/TLS through Cloudflare’s network. File data is not sent in clear text.
While the file waits
Live zaps are stored in Cloudflare R2. Service components receive only the access needed for their role, following least-privilege principles.
A zap link is a key
Transfer IDs are long, random, and non-sequential. They are designed to resist guessing, but possession still matters: anyone with a live zap link can download the file. Share it directly and avoid public channels. zappp Plus may add password protection where available.
When the timer ends
At expiration, the file is removed from active storage. Residual information in caches, backups, or logs is cleared on a limited rolling schedule. Faded zaps cannot be recovered.
How we run the service
We minimize long-lived data, limit privileges, log security-relevant events, monitor for abuse, update infrastructure, and use automated safeguards to detect malicious activity.
No magic shield
No online service is perfectly secure. We will not pretend otherwise. zappp reduces exposure with encrypted transport, limited access, a small data footprint, and short retention.
Your side
Send zap links through trusted channels, keep your original until delivery is confirmed, and do not open a file you were not expecting. A zappp link is not proof that its contents are safe.
Found a vulnerability?
Email [Support Email] with enough detail to reproduce the issue. Give us a reasonable window to investigate before public disclosure, and do not access or alter data that is not yours. Good-faith security research is welcome.