fwd:

Privacy policy

Effective 10 October 2026 · Updated 11 October 2026 · Beta

fwd: sends links, text and files between your own devices. Everything you send is end-to-end encrypted on your device before it leaves, and only your own devices hold the keys to read it. We run the service that stores and relays the encrypted data, and we can't read it.

What we can't see

The content of your pushes: links, page titles, text, files, file names, file types, thumbnails, and the names of your devices. These are encrypted with keys that never leave your devices. Your recovery key is never sent to us.

What we can see

Delivery and service measurement

When a push arrives, the receiving device tells our service whether it opened successfully or failed, with no content. We use this to show "received" to the sender and to measure delivery speed and failures. Individual records are kept for 7 days; after that we keep only aggregate counts. There is no analytics or advertising SDK in our apps.

Service providers

We don't sell or share your data with anyone else, and we don't use it for advertising.

How long we keep data

Your encrypted history and files are kept for as long as your account exists, until you delete them. Deleting a push removes it from every device as each one reconnects; a small record that the push existed and was deleted is kept so deleted items can't reappear. Files and text you saved or copied outside fwd: stay on your devices.

Deleting your account

You can delete your account in the Android app, in the browser extension, or at usefwd.io/delete. Deletion from an app starts immediately. A deletion requested on the website, which is confirmed by email alone, is held for 72 hours so you can cancel it from any of your devices if someone else got into your email; your account is disabled during the hold. After that, we erase your account, devices, encrypted history and files within 24 hours. Our database provider's point-in-time recovery may retain encrypted data for up to 30 days before it ages out.

Security

Encryption uses P-256, HKDF-SHA256 and AES-256-GCM, with HPKE (RFC 9180) for sharing keys between your devices. Removing a device rotates the keys for future pushes. If you lose every device and your recovery key, your history can't be recovered by anyone, including us.

Children

fwd: isn't directed at children under 13, and we don't knowingly collect their data.

Changes and contact

We'll post changes here and, if they're significant, tell you by email. Questions or requests: hello@usefwd.io.