Legal
BimdUP Privacy Policy
How BimdUP handles information while connecting your Android device and computer.
Overview
BimdUP is a privacy-focused file-transfer utility operated by ThoferLabs LLC. It uses a temporary BimdUP application service to pair devices, exchange connection information, provide relay credentials when needed, and record restricted operational diagnostics. BimdUP does not require an account and its application server is not permanent file storage.
Information used to provide pairing
The service creates a public session identifier and temporary credentials for the computer and Android device. It stores hashed forms of the six-digit pairing code and peer credentials, the pairing state, creation and activity times, expiry, and claim time where applicable. The credentials authorize only the associated temporary session.
Trusted Devices
If you explicitly trust a paired device, BimdUP stores an opaque relationship identifier, hashed credentials for each peer, platform type, pseudonymous TURN subject where available, relationship state, and creation, update, and last-used times. The server does not store the local device nickname. Each reconnect creates new temporary session credentials. You may forget a trusted device to revoke the relationship; expired reconnect requests and old incomplete or revoked relationships are removed by scheduled cleanup.
Android encrypts trusted relationship credentials with an Android Keystore key. Browsers store trusted relationship credentials in origin-scoped IndexedDB. Clearing browser site data, clearing Android app data, or uninstalling the app removes that device's local credential.
Signaling information
To establish WebRTC, the peers temporarily send the BimdUP service an offer, answer, ICE information, and end-of-candidates messages. These records are associated with the pairing session and are used to establish and maintain the connection.
File transfers
File contents are not uploaded to BimdUP for permanent storage. Transfers use encrypted WebRTC connections. When a direct connection is unavailable, encrypted traffic may be relayed through the configured TURN provider. BimdUP currently uses Cloudflare Realtime TURN for this fallback, so encrypted relay traffic and the network metadata needed to route it may pass through Cloudflare infrastructure.
Operational diagnostics
BimdUP records a restricted set of operational events for reliability, troubleshooting, connectivity analysis, and transfer-failure diagnosis. Depending on the event, these can include a transfer identifier; event, stage, and reason; app and protocol versions; transfer direction; file index; filename length (not the filename); declared or actual byte totals; whether a MIME type is present; connection and DataChannel state; TURN provider; candidate type; whether a relay was used; and transport protocol.
The diagnostics interface rejects fields outside its allowlist and is intentionally designed not to contain file contents, filenames, paths, pairing codes, credentials, raw SDP, or complete ICE candidate strings.
Network information
Like other internet services, BimdUP infrastructure receives source network addresses as part of ordinary HTTPS connections. Diagnostic records do not store the raw remote address; they store a one-way HMAC-derived identifier so events from the same network source can be investigated without writing that raw address to the diagnostic record. WebRTC peers and any STUN or TURN provider also process network information needed to establish or relay a connection.
Rate limiting and abuse prevention
BimdUP derives one-way SHA-256 identifiers from source network addresses for pairing creation and claim limits, and from the pairing-session identifier together with the source network address for diagnostic limits. The raw source address is not used as the rate-limit filename. Each record contains only counter and timing state used for security, abuse prevention, and service protection—not file-transfer content. Scheduled cleanup removes these records when their modification time is older than the configured retention period, which is 24 hours by default and is never configured shorter than the longest applicable rate-limit window.
Optional feedback
If you voluntarily open and submit the feedback form, BimdUP receives the name, email address, and feedback or message contents you enter. We use that information for support, bug reports, suggestions, product feedback, and replying to you. Feedback is optional and is not automatically attached to transferred files, contacts, device contents, pairing credentials, or file contents.
Feedback may remain in our support and email systems only as long as reasonably needed to respond and maintain support history. The feedback page uses Google reCAPTCHA to prevent spam and abuse; Google may process the network and browser information required to provide that service.
Information stored on Android
The app stores app-private state needed for continuity: the active reusable pairing session identifier and credential, its expiry, encrypted trusted-device relationship credentials, a saved Android Storage Access Framework destination reference and display label, and the appearance/theme preference. The saved destination can be changed in Settings. Android cloud backup and device-to-device migration are disabled for this app-private state.
Retention and deletion
Pairing sessions remain eligible for cleanup after they expire; the cleanup job deletes sessions whose expiry is more than one day in the past, and associated signaling records are then deleted by the database relationship. Diagnostic log files are removed when their file modification time is more than 10 days old. Rate-limit records are removed when older than the configured bounded period described above. Expired TURN credential cache files are removed by the cleanup job. These are scheduled cleanup rules, not a promise of deletion at the exact instant a threshold is reached.
Disconnecting or session expiry removes pairing authority according to the app's session behavior. Temporary server data ages out under the rules above. Android app data can be removed through the system's clear-storage control or by uninstalling BimdUP.
Third-party infrastructure
Cloudflare Realtime TURN may process temporary credentials, network routing information, and encrypted WebRTC traffic when relay fallback is necessary. BimdUP may also rely on ordinary hosting and network providers to deliver its website and application service. This policy does not claim Cloudflare is the only infrastructure provider.
Advertising and analytics
BimdUP does not include advertising SDKs or general-purpose analytics SDKs. It does collect the restricted operational diagnostics described above; those diagnostics are not advertising or behavioral analytics.
Accounts and user controls
BimdUP does not currently create user accounts, so there is no account record or account-deletion flow. You control which files you select, may cancel a transfer or disconnect, may change the saved receive destination in Settings, may forget a trusted device to revoke it, and may clear local state using Android's app-data controls or uninstall the app.
Security
BimdUP uses HTTPS for API and signaling traffic, stores hashed pairing codes and peer credentials on its application server, uses encrypted WebRTC transport for file traffic, restricts accepted diagnostic fields, and disables Android backup of app-private state. No system can be guaranteed completely secure, and these measures do not eliminate every risk.
Changes to this policy
We may update this policy when BimdUP's practices or legal obligations change. The effective date above will be updated when a revised policy is published.
Contact
For privacy or support questions, contact ThoferLabs LLC at info@thoferlabs.com.
Relay usage protection
The Android app creates a random app-installation identifier for TURN relay security, usage accounting, and abuse prevention. It is stored privately, excluded from backup and device migration, persists across ordinary restarts, and rotates when app data is cleared or the app is reinstalled. It is not derived from an advertising, account, telephone, or hardware identifier.
BimdUP immediately converts that value to a pseudonymous HMAC-derived value and does not retain the raw identifier. When encrypted traffic uses Cloudflare TURN, the derived value may be sent to Cloudflare as a usage dimension. Short-lived aggregate relay byte counts may be cached outside the public site for abuse and cost protection; account-wide relay controls also apply. Analytics can be delayed or sampled, so quotas are not byte-perfect.
Direct peer-to-peer file contents are not stored by BimdUP. When direct connectivity is unavailable, Cloudflare TURN may transit encrypted WebRTC file traffic but BimdUP's PHP/MySQL service remains signaling and control only.