The short version
- Your notes and files are encrypted on your device before they’re uploaded. We only ever store that encrypted data.
- No accounts, no cookies, no ads, no analytics and no tracking. We don’t sell or share your data.
- Every drop deletes itself after 10 minutes, an hour or a day, or right after it’s opened if you choose burn after reading.
Who runs 4dots
4dots (“we”) runs the service at 4dots.app. You can reach us at support@4dots.app. 4dots is open source, so you can check everything on this page in the code on GitHub.
What we can’t see
Your browser encrypts your note, your files and their names with AES-256-GCM before anything leaves your device, and the recipient’s browser decrypts them. Our storage provider never receives readable content or your code. Our server sees which code is being opened, but only ever handles encrypted data.
The key comes from your four-digit code plus a per-code secret held by our server. Because a code has only 10,000 possibilities, whoever runs the server could in principle work out keys. We never try to, and it’s why 4dots is meant for things that matter for minutes, not secrets that must stay secret for years.
What we handle, and why
- Encrypted drops, so the recipient can download them.
- Drop details: each drop’s size, when it was created and expires, whether it burns after reading, and a fingerprint of the token that lets the sender delete it early. We need these to deliver and delete drops.
- IP addresses, counted briefly to limit how many drops one address can create and how many wrong codes it can try. This is what stops codes from being guessed.
- Technical logs: our hosting provider keeps short-lived records of requests and errors, which can include IP addresses and browser details, so we can run and fix the service.
- Emails you send us: your address and message, used only to reply.
Under the EU’s GDPR, we rely on our legitimate interest in running a working, secure service (Art. 6(1)(f)) and on providing the service you ask for (Art. 6(1)(b)).
How long we keep it
- Drops: until they expire, are opened with burn after reading, or are deleted by the sender. The stored data is deleted straight after. There are no backups.
- Unfinished uploads: deleted 15 minutes after the last activity.
- Rate-limit counters: they reset after 10 minutes and are deleted within an hour.
- Technical logs: a few days.
- Emails: as long as it takes to deal with your message.
Who processes data for us
- Cloudflare hosts the site and the server, protects them from attacks, and forwards emails sent to 4dots.app addresses. See Cloudflare’s privacy policy.
- nimbo.fun stores encrypted drops until they’re deleted. It receives only encrypted data under random names.
Their servers may be outside your country, including outside the EU.
On your device
4dots sets no cookies and loads nothing from other websites. It may save one setting in your browser: whether to use lighter animations on a slow device. When you share files to the installed app, they stay on your device only until 4dots opens them.
Your rights
Depending on where you live, for example under the GDPR, you can ask to access, correct or delete personal data we hold about you, object to how we use it, and complain to your data protection authority. With no accounts and almost nothing kept, there’s usually little or nothing we can link to you, but write to support@4dots.app and we’ll help.
Children
4dots isn’t meant for children under 13, or under the age of digital consent in your country if that’s higher (16 in many EU countries).
Changes
If this policy changes, we’ll update this page and the date below.
Last updated 2 October 2026