Privacy, in plain sight.
A clear view of the information behind a document view, and how we handle it.
Draft · September 9, 20261. Who we are
AnyShare is a document sharing service operated by Anysoft LLC. This draft describes the current preview and the intended configured service. The sharing organization decides which files to share, with whom, and which available viewer checks to require. Anysoft LLC operates the application and processes information needed to provide it.
2. Information the service handles
| INFORMATION | WHY IT IS USED |
|---|---|
| Account details | Authentication identifiers, email, and profile details supplied through Clerk are used to sign you in and associate you with your organizations. Membership records include your role, name, email, and join date. |
| Organization and invitation details | Organization names, membership roles, invited email addresses, invitation expiry dates, and trial start and end dates support team access and the 7-day trial. Invitation tokens are stored as hashes. This preview collects no payment information. |
| Documents and rooms | Uploaded files, converted previews, titles, versions, folders, share links, and access settings are used to store, organize, and deliver the content you choose to share. |
| Viewer details | Where required by a link, viewer email and its verification status are used to check access and identify visits. A captured email is not automatically a verified identity. |
| Viewing sessions | Session identifiers, visit times, document version, pages visited, completion, and active milliseconds displayed as seconds are used to provide document engagement analytics. |
| Technical information | Browser or device information and service request logs help operate the viewer and investigate technical problems. Infrastructure providers may process IP addresses and other connection information to deliver the service. |
| Product usage | When product analytics is enabled, selected organization, upload, sharing, and team actions help us understand adoption. Events use account and organization identifiers, file types, counts, and access-setting categories. Public document opens contribute an organization-level event without viewer identity. Document contents, names, email addresses, access tokens, and page-by-page viewing time are excluded from these events. |
3. What organization members can see
Members of the sharing organization can access its documents, rooms, links, and analytics, including visit counts, unique viewers, session details, pages visited, completion, and active time. When a viewer provides an email, members can see it and whether it was verified. Anonymous viewing, where permitted, is labeled as anonymous. Members can export available analytics as a CSV. Viewers should contact the person or organization that shared a document about that organization’s use of their information.
Organization members can see the team directory. Owners and admins can see pending invitations and manage access within their role. Accepting an invitation requires the matching verified account email. Removing a member ends their organization access but does not recall any files or analytics they previously downloaded.
Active time is recorded while a page is in the foreground, using periodic activity updates. Hidden tabs and idle viewers pause timing. This measures a limited engagement signal, not proof that you read, understood, or agreed to content. The application does not record your screen or use advertising trackers for these insights.
4. Cookies and access
The service uses essential authentication and viewer-session cookies to keep team members signed in, remember the selected organization, and remember completed viewer access checks. Organization membership is checked on the server; selecting an organization does not grant access. Viewer-session cookies are set with HttpOnly protection and expire. Disabling essential cookies may prevent sign-in or protected document viewing. This preview does not include an advertising cookie or cross-site advertising analytics system.
5. Service providers
The configured service uses providers to perform specific functions. Data handling also depends on the selected hosting regions and provider agreements; those choices and any required international transfer terms must be finalized before public launch.
- Clerk: account authentication and profile services.
- Supabase: application database and private document storage.
- Vercel: application hosting and request delivery when deployed.
- PostHog: selected server-side product usage events when enabled. This integration uses no browser tracking script, analytics cookie, or session recording. Customer-facing document engagement remains in our application database.
- The configured email delivery service sends viewer verification messages and team invitations. Its final production provider must be named before launch.
- A private document conversion worker prepares Office previews. Its final production hosting provider must be added to this notice before it receives production files.
6. Retention, deletion, and your choices
Content and related engagement records are retained to provide the organization and sharing features. Revoking a link stops future access through that link; it does not itself delete the underlying document, previous analytics, downloaded copies, or provider backups.
Before launch, Anysoft LLC must publish its retention periods or decision criteria, backup deletion timing, and a working process for account and viewer data requests. The applicable law may give you rights to access, correct, delete, restrict, or object to uses of your information. Requests about a sharing organization’s collection of viewer information should first be directed to that organization.
7. Security and permitted use
Documents are held in private storage and served after the applicable access checks. Organization members can choose available email verification, passwords, allowlists, expiry, downloads, and watermark controls. No displayed content can be guaranteed against screenshots or copying. Learn more on our security page.
8. Before public launch
This draft is not a completed production privacy notice. Anysoft LLC must add its address and privacy contact, confirm legal bases and regional rights where applicable, finalize retention and transfer arrangements, and describe any additional processors. This approach follows the transparency topics described in the ICO’s privacy information guidance; the reference does not claim certification or establish which laws apply to the service.