Privacy policy
Effective 10 October 2026 · Updated 11 October 2026 · Beta
fwd: sends links, text and files between your own devices. Everything you send is end-to-end encrypted on your device before it leaves, and only your own devices hold the keys to read it. We run the service that stores and relays the encrypted data, and we can't read it.
What we can't see
The content of your pushes: links, page titles, text, files, file names, file types, thumbnails, and the names of your devices. These are encrypted with keys that never leave your devices. Your recovery key is never sent to us.
What we can see
- Your email address, used to sign you in, send sign-in codes and security notices.
- How many devices you have, each device's platform (Android or browser), its public keys and its push token.
- Which device sent each push to which device or devices, when, and how large it is. Sizes aren't padded, so they roughly reveal how long a text or link is and how big a file is. We can also tell whether a push carries a file.
- When devices are added, removed or recovered, and when your recovery key is replaced.
- IP addresses of requests, used only for abuse protection and rate limiting, and not kept in our logs.
Delivery and service measurement
When a push arrives, the receiving device tells our service whether it opened successfully or failed, with no content. We use this to show "received" to the sender and to measure delivery speed and failures. Individual records are kept for 7 days; after that we keep only aggregate counts. There is no analytics or advertising SDK in our apps.
Service providers
- Cloudflare hosts our service, database and encrypted file storage, and sends our emails. It also protects our website against bots and may set security cookies to distinguish legitimate visitors from automated traffic. These are separate from our cookieless analytics.
- Google Firebase Cloud Messaging wakes the Android app, and your browser's push service (for Chrome, also Google) wakes the extension. These messages contain no content or identifiers beyond "something new".
- Your own email provider receives the emails we send you.
- Umami and Cloudflare Web Analytics count visits to the usefwd.io home page and blog: the page, referrer, browser, device type and country, without cookies. The apps, and the account deletion, privacy and terms pages, have no analytics.
- getwaitlist.com holds the waitlist. If you join it on usefwd.io, our service passes your email address, browser language and time zone to them without storing it, and we use it only to send you an invite and occasional updates about fwd:. Ask hello@usefwd.io to be removed.
We don't sell or share your data with anyone else, and we don't use it for advertising.
How long we keep data
Your encrypted history and files are kept for as long as your account exists, until you delete them. Deleting a push removes it from every device as each one reconnects; a small record that the push existed and was deleted is kept so deleted items can't reappear. Files and text you saved or copied outside fwd: stay on your devices.
Deleting your account
You can delete your account in the Android app, in the browser extension, or at usefwd.io/delete. Deletion from an app starts immediately. A deletion requested on the website, which is confirmed by email alone, is held for 72 hours so you can cancel it from any of your devices if someone else got into your email; your account is disabled during the hold. After that, we erase your account, devices, encrypted history and files within 24 hours. Our database provider's point-in-time recovery may retain encrypted data for up to 30 days before it ages out.
Security
Encryption uses P-256, HKDF-SHA256 and AES-256-GCM, with HPKE (RFC 9180) for sharing keys between your devices. Removing a device rotates the keys for future pushes. If you lose every device and your recovery key, your history can't be recovered by anyone, including us.
Children
fwd: isn't directed at children under 13, and we don't knowingly collect their data.
Changes and contact
We'll post changes here and, if they're significant, tell you by email. Questions or requests: hello@usefwd.io.