Privacy Policy
Effective Date: August 2026 • Zero Tracking Manifesto
Teleporter is built on the philosophy of zero tracking. We do not require accounts, we do not sell or monetize personal data, we do not set third-party tracking cookies, and we do not profile your document reading habits.
1. Information We Do NOT Collect
We do not collect names, email addresses, phone numbers, payment details, hardware serials, or social login credentials. There is no user registration, sign-in, or centralized identity profiling on Teleporter.
2. Anonymous Device Node IDs & Karma Sync
To maintain Karma rank tiers, bandwidth quotas, and dispatch logs without requiring logins or email accounts, Teleporter assigns a randomized, anonymous Device Node ID (e.g. DEV-8B3F1A20) stored in your local browser's localStorage.
This node identifier contains zero hardware fingerprints, IMEI numbers, or personal identifying attributes. You may unlink, reset, or transfer this identifier at any time through the Station Telemetry controls.
3. Storage Security Methods & Cryptographic Architecture
We implement enterprise-grade defense-in-depth security measures to protect every document transmitted through the relay:
- AES-256 Server-Side Encryption at Rest: All file payloads stored in Cloudflare R2 are automatically encrypted with industry-standard 256-bit Advanced Encryption Standard (AES-256).
- TLS 1.3 End-to-End Encryption in Transit: All upload streams, document views, and claim token lookups enforce strict HTTPS with TLS 1.3 and Perfect Forward Secrecy (PFS).
- Cryptographic Path Obfuscation: Files are stored under high-entropy, randomized 10-character folder prefixes generated with cryptographic randomness (
nanoid), preventing directory enumeration or automated scraping. - Time-Limited SigV4 Presigned URLs: Uploads and downloads utilize temporary presigned URLs signed with AWS Signature Version 4 credentials that expire in 15 minutes, blocking unauthorized URL reuse or hotlinking.
- Zero Public Bucket Perimeter: Cloudflare R2 storage buckets have public listing and direct read/write disabled; all data access is gated through verified claim tokens.
4. Direct-to-Storage Streaming & Zero AI Training
File transfers stream directly between your web browser and Cloudflare R2 object storage via ephemeral presigned URLs. Teleporter's application compute layer never buffers, inspects, or reads your file payloads.
We strictly NEVER inspect, monetize, index, or feed your uploaded documents, manuscripts, research, source code, or images into AI or machine learning models.
5. Abuse Defense & One-Way SHA-256 IP Hashing
To defend against volumetric DDoS attacks, flooding scripts, and storage pool saturation, client IP addresses are processed through a one-way SHA-256 cryptographic hash function. Raw, unhashed IP addresses are never permanently logged, readable, or retained in database tables.
6. Irreversible Ephemeral File Deletion
Uploaded documents are subject to strict cryptographic erasure upon ticket expiration (1 to 30 days), on-demand author purge, or proactive capacity self-healing (>85% high-watermark). Once deleted, files and metadata are physically and permanently destroyed with zero recovery backups.
7. Third-Party Infrastructure Providers
Teleporter operates on Cloudflare R2 (for zero-egress encrypted object storage) and Neon (for serverless PostgreSQL metadata). Neither provider is granted authorization to access, inspect, or commercialize your files.
