Media2URL
Privacy

Privacy Policy

How Media2URL handles account data, uploaded files, public links, security signals, abuse reports, and legal requests.

Last updated: September 13, 2026

How Media2URL handles account data, uploaded files, public links, security signals, abuse reports, and legal requests.

This Privacy Policy explains what Media2URL processes when you visit the service, create an account, upload or share a file, use an integration, contact support, or submit an abuse or copyright report. It is written to describe the real operating purposes of the platform; it is not a promise that every security or privacy risk can be eliminated.

The policy applies to visitors, account holders, workspace members, recipients of shared links, API and integration users, reporters, and people who contact us about safety or legal matters. Rights available under the law that applies to you are not limited by this policy.

1. Information We Process

Account and workspace data: We process the email address and authentication information needed to sign in, workspace membership and roles, plan and entitlement information, integration identifiers, and account-support communications. Payment providers process full payment credentials; Media2URL receives the billing status and transaction details needed to operate subscriptions.

Files and asset metadata: We process the file supplied to the service and the records needed to store, validate, transform, deliver, organize, replace, and remove it. This can include the original filename, file type, size, checksum or signature results, storage object key, dimensions or duration, folder and workspace relationship, link slug, privacy setting, expiry, download or view settings, and password hash where password protection is used.

Security and abuse signals: Requests may produce IP address or IP-derived rate-limit values, user agent, request time, route, status, bandwidth and quota events, authentication events, upload validation results, abuse reports, moderation actions, and integration or API activity. We use the minimum information reasonably needed for security, fraud prevention, troubleshooting, and enforcement. We do not need to retain a readable copy of a password to verify password-protected links.

2. Why We Use This Information

Service delivery: We use account, asset, link, workspace, and usage data to upload, store, process, organize, replace, share, and delete files; enforce plan entitlements and quotas; provide direct URLs and share pages; and respond to support requests.

Security and abuse prevention: We use validation results, rate limits, account and workspace signals, delivery events, reports, and other security data to detect spam, automated abuse, malware or phishing indicators, privacy violations, copyright complaints, evasion, and attacks against the platform. This may involve automated checks followed by human review.

Legal and operational purposes: We process information to comply with lawful requests, protect users and the service, investigate incidents, maintain records, resolve disputes, prevent fraud, improve reliability, and enforce the Terms of Service and Acceptable Use Policy. We do not sell uploaded files or use the contents of uploaded files for behavioral advertising.

3. Public Links Are Not Confidential Storage

A public or unlisted link can be opened by anyone who obtains the URL. A direct media URL, embedded image, custom delivery-domain URL, share page, QR code, or downloaded copy can be forwarded or copied by a recipient. Unlisted means less discoverable, not private or confidential.

Private and password-protected links use additional access checks, but they cannot prevent a recipient from copying a URL, sharing a password, taking a screenshot, or redistributing a file after access. Do not upload passwords, recovery codes, private keys, regulated records, or other material that requires a dedicated confidential-storage system.

Media2URL may use no-index controls on appropriate user-generated pages, but search-engine controls cannot guarantee that a URL will never be discovered or that a third party will not publish a copy elsewhere.

4. Abuse Reports, Review, and Strict Response

A report may include the exact hosted URL, category, explanation, reporter contact details, safe evidence, and technical information required to prevent repeated submissions. Do not download, attach, or email suspected illegal material or live malware merely to make a report.

Reports are triaged by urgency. Credible child-safety concerns, active malware or phishing, non-consensual intimate content, serious threats, and similar immediate risks may cause access to be restricted before the investigation is complete. Repeated independent reports may also trigger a temporary delivery block while an operator reviews the asset; a report count is a triage signal, not by itself a final finding.

When enforcement is required, Media2URL may disable the file and its links across direct delivery, share pages, variants, transformations, downloads, and verified custom delivery domains; quarantine or remove versions and generated outputs; restrict uploads; suspend or terminate an account or workspace; revoke integration credentials; preserve limited evidence; and report conduct to authorities or rights holders when required or appropriate.

5. Service Providers and International Processing

Media2URL uses service providers for application hosting, authentication and database services, object storage and CDN delivery, email, payments, monitoring, and related operations. Providers receive only the information needed for their assigned function and may process it in the countries where they operate.

Examples of current infrastructure providers include Supabase, Cloudflare R2/CDN, application hosting providers, payment processors, and transactional email providers. The provider list and processing arrangements may change as the service grows; material changes will be reflected in this policy where required.

Where applicable law requires safeguards for international transfers, Media2URL will use a lawful transfer mechanism and appropriate contractual or organizational protections. Nothing in this paragraph promises a particular legal mechanism in every country.

6. Retention, Deletion, and Legal Holds

Files and asset metadata are retained while needed to provide the service, honor link settings, maintain versions, enforce quotas, investigate abuse, resolve disputes, or comply with law. Expired, deleted, or disabled content may become inaccessible immediately while technical deletion completes asynchronously.

A file restricted after an abuse report is not automatically deleted merely because it was reported. It may remain in a restricted state for operator review. After a confirmed violation, Media2URL may permanently remove the asset, versions, variants, and storage objects, while retaining limited report, audit, or legal records when reasonably necessary.

Deletion may be delayed or limited by legal holds, fraud prevention, security investigations, billing records, dispute handling, backup cycles, or another legal obligation. Backups are for service recovery and are not a customer archive or a promise of selective restoration.

7. Privacy Rights and Requests

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of certain personal information. Send requests to support@media2url.com from the account email when possible. We may verify identity, request clarification, and apply lawful exceptions before completing a request.

A request to delete information does not require Media2URL to restore content, remove records that must be preserved, or erase information that has already been copied by another person. We may retain a limited record of the request and its outcome for accountability and legal compliance.

8. Security Boundaries and Incident Response

Media2URL uses access controls, restricted storage credentials, HTTPS, validation, rate limits, controlled object keys, and delivery-state checks to reduce unauthorized access and abuse. No online service, CDN, browser, or storage system can guarantee perfect security.

If we confirm a security incident, we will investigate, contain affected access, revoke or rotate credentials where appropriate, preserve relevant evidence, and provide notices required by applicable law. Report suspected account compromise, exposed credentials, harmful files, or platform vulnerabilities promptly.

9. Policy Changes and Contact

We may update this policy when the service, providers, legal requirements, or abuse-response practices change. The effective date shown on this page identifies the current version. If a change materially affects how we use personal information, we will provide notice where required.

For privacy, security, abuse, copyright, or account questions, contact support@media2url.com or use the Contact page. Do not send passwords, secret keys, live malware, or unnecessary sensitive files in a support message.

Contact Media2URL about this page

If you have questions about this policy, your account, billing, uploads, abuse reports, DMCA notices, privacy requests, refunds, or legal/safety concerns, visit the Contact page or email us directly. For account specific requests, email from the account address when possible.