Effective date: September 27, 2026 (updated for v1.11.0)
ZeroDrop ("the app") lets you send photos, videos, files and links directly between phones that are physically next to each other. This policy explains what the app does with your data. The short version: ZeroDrop has no servers, no accounts, no ad networks and no analytics. Your files go directly from one phone to the other and are never uploaded to us or anyone else.
We (the developer) do not collect, store, sell or receive any personal data. The app contains no advertising SDKs, no analytics SDKs and no crash-reporting SDKs, and it does not create user accounts.
ZeroDrop shows a small, clearly labelled link to Klevo (klevo.live), another product made by the
same developer. The link only opens in your web browser when you tap it; ZeroDrop does not send Klevo any
information about you, your device or your transfers. The link includes a campaign tag (for example
utm_source=zerodrop) that only tells Klevo which ZeroDrop screen the visit came from. Klevo has its
own privacy policy, which applies once you visit it. You can hide the suggestion on the home screen at any time.
ZeroDrop does not share data with third parties, including Klevo. Files are only sent to the device you physically tap or that scans the code shown on your screen. Android‑to‑Android connections may use Google Play services' Nearby Connections API, which runs on your device to establish the local link; it does not receive the content of your files, which are encrypted by ZeroDrop before they are sent.
We hold no data about you, so there is nothing for us to delete. Files you receive are stored on your phone like any other photo or download; you can delete them at any time from your gallery or file manager. Encryption keys exist only in memory for the duration of a transfer. ZeroDrop also keeps one device identity key inside your phone's secure hardware (Android Keystore), used only to prove to the other phone that it is talking to genuine ZeroDrop; it never leaves the secure hardware and is removed when you uninstall the app.
Copied text. ZeroDrop reads your clipboard only when you tap Send what I copied, and only its text, which is then shared like any other link or text you choose to send.
ZeroDrop Web Direct (browser to browser). In the ZeroDrop web app, devices on the same network can share directly with each other (for example iPhone to Windows). To find each other, they briefly connect to ZeroDrop's introduction service, which sees your network's public IP address (only to group devices on the same network, hashed and never stored) and the random device name shown in the app. Files never pass through it: they go directly between the two devices, encrypted, and nothing connects until the receiver accepts and the access code is typed. Connections may use Google's public STUN service to find a direct path between the devices; it doesn't receive your files.
The app in Web Direct. While a ZeroDrop screen is open, the app also takes part in Web Direct, so browsers on the same network (for example an iPhone or a computer with the ZeroDrop web app) can see this phone by its device name and ask to send to it; you can also send to them from the app. It works the same way as between browsers: nothing arrives unless you tap Accept and the access code is typed, and everything received is checked by ZeroDrop Shield on your phone. It isn't used when "Receive only from trusted phones" is on.
Security checks between phones. When two phones connect, each one's secure hardware also reports whether its system protection is on (bootloader locked, system verified). ZeroDrop uses this only to warn you, or, in Strict mode, to refuse the connection; it isn't stored or sent anywhere. Files you send are checked by ZeroDrop Shield on your phone before they leave it. Phones you block are remembered by name on your phone only.
Trusted phones. If you choose Always accept for one of your phones, ZeroDrop stores that phone's name and a fingerprint of its secure-hardware identity key on your phone only, so it can send to you without the Accept tap. The fingerprint identifies the phone's ZeroDrop key, not you; it never leaves your phone, and you can remove it any time in This phone › Trusted phones.
Computers, Macs and tablets. They use the same temporary local web page as phones without ZeroDrop. Tablets and iPads can scan the QR code. Computers pair with the phone over Bluetooth using the ZeroDrop web app (below); there is no address to type. Each share only works on the device that opened it first and the devices you allow.
ZeroDrop web app. The optional ZeroDrop web app for computers, Macs and tablets is a static page that runs in your browser; it collects nothing, uses no cookies or analytics, and files never pass through it. Its Find my phone button uses your browser's Bluetooth, only while Connect a computer is open on your phone (2 minutes). The browser and the phone create a shared encryption key; the phone shows an access code that you type on the computer, which proves it's your phone and that nobody is in between. Only then does the phone send its share link, encrypted for that computer. During those 2 minutes, nearby Bluetooth devices can see your phone's Bluetooth name. Scanning with the camera happens entirely on your device; no image is sent anywhere.
Received links. A link or text shared from another ZeroDrop phone is kept only in the app's memory and is never saved or uploaded. If "Open received items automatically" is on, links of well‑known apps (for example Spotify, YouTube or Google Maps) and received photos or videos open in their app after a short animation you can cancel. Other links open only when you tap them, and documents or apps never open by themselves.
Transfers between Android phones are end‑to‑end encrypted. Transfers to an iPhone use a one‑time link that works only on your local network; on public (password‑less) Wi‑Fi, ZeroDrop automatically switches to its own password‑protected hotspot. Before any file moves, the two phones check with their secure hardware (Android key attestation) that both run the genuine ZeroDrop app, so look‑alike apps can't send to or receive from you. To do this, ZeroDrop downloads Google's public list of revoked attestation keys about once a day; this request contains no information about you. No method of transmission is 100% secure, but ZeroDrop is designed so that your data never leaves the two devices involved.
ZeroDrop is not directed at children under 13 and does not knowingly collect any data from anyone.
If this policy changes, the updated version will be posted on this page with a new effective date.
Questions about privacy: [YOUR SUPPORT EMAIL]