This Privacy Policy explains how personal data is processed when you use Transferly, including the Android app, Windows app, Transferly website, browser-based Web Transfer and the temporary Internet Relay service.
Last updated: 23 August 2026
Controller
The controller responsible for the processing described in this Privacy Policy is:
Andreas Martin SchreinerSole proprietor, operating under the business designation Realm of Salt
Langobardenstraße 191/9
1220 Vienna
Austria
Email: info@saltyy.at
Phone: +43 680 4003436
Scope
This Privacy Policy applies to the Transferly product and its related services operated by the controller, including:
- Transferly for Android
- Transferly for Windows
- transferly.saltyy.at
- transfer.saltyy.at Web Transfer
- the Transferly Relay/API at
api.saltyy.at/transferly
Third-party platforms such as Google Play or GitLab apply their own privacy policies when you actively open or use those services.
Direct Nearby and local transfers
When Transferly can send a file directly between native devices on the same local network, the file payload is transferred directly between those devices. The file does not pass through the Transferly Internet Relay.
The apps may exchange technical information required to discover and authenticate nearby devices, such as a device name or alias, platform information, connection addresses, short-lived discovery identifiers and cryptographic identity information.
The legal basis is Article 6(1)(b) GDPR where this processing is necessary to provide the transfer requested by the user and Article 6(1)(f) GDPR for secure and reliable device discovery, authentication and abuse prevention.
Temporary Internet Relay sessions
If you choose an Internet transfer, selected files are temporarily uploaded to the Transferly Relay so another authorized device or browser can retrieve them.
A Relay session may process or temporarily store:
- a random session identifier and authentication token
- a short Transfer ID and a cryptographic hash of the access code
- session creation and expiry timestamps
- file names, MIME types, file sizes and upload timestamps
- a SHA-256 hash used for file-integrity verification
- a technical origin label indicating the sending client
- temporary abuse-prevention identifiers derived from the source IP address
The normal session lifetime is 45 minutes. Relay files and session metadata are deleted when the session expires or when the sender ends the session. Expired sessions are also removed by automatic cleanup jobs.
Transferly does not use the Relay as a permanent cloud drive and does not send file payloads to third-party cloud-storage providers.
The legal basis is Article 6(1)(b) GDPR for providing the transfer requested by the user and Article 6(1)(f) GDPR for security, rate limiting, integrity checks and abuse prevention.
IP addresses, security and rate limiting
Like most Internet services, the Transferly website, Web Transfer and Relay necessarily receive the source IP address while handling a request. Hosting infrastructure may also create ordinary server access or security logs.
The Relay itself uses derived or hashed IP-based identifiers for rate limiting and abuse prevention instead of storing the source IP address as a plain value in normal Relay session metadata. Rate-limit state is short-lived and is automatically cleaned up.
This processing is based on Article 6(1)(f) GDPR. The legitimate interests are secure operation, protection against abuse, troubleshooting and maintaining service availability.
Bluetooth-assisted Nearby rendezvous
For supported cross-platform discovery flows, Transferly may use short-lived Relay records to help nearby Android and Windows devices find and authenticate each other when a direct local route is not immediately available.
These short-lived records may contain a rotating discovery token, a truncated identity prefix, device alias, platform, app version, transfer size/count information and cryptographic identity proof used to authorize the intended receiver. The Bluetooth advertisement itself does not contain file payloads, Relay session credentials or file names.
Presence records normally expire after roughly 90 seconds; targeted rendezvous offers normally expire after roughly 75 seconds and are cleaned up shortly after expiry or a response.
Data stored locally on your device
Depending on the platform and features you use, Transferly may store information locally on your Android or Windows device, including:
- your Transferly device name
- trusted-device information and device fingerprints
- transfer history and local file references
- theme, language and feature settings
- update-check state and cached release information
This local information is not a Transferly account and is not used to create a permanent server-side profile. You can remove local app data through the relevant app controls or the operating system.
Android permissions and background receiving
The Android app may request permissions required for enabled features, including Nearby devices, Bluetooth, notifications and foreground/background receiving.
On older Android versions, Android may require a location permission for Bluetooth or Nearby discovery compatibility. Transferly does not use that compatibility permission to track your physical location.
When background receiving is enabled, Android may show an ongoing foreground-service notification so Transferly can remain available for incoming transfers as expected by the user.
Update checks
The Android and Windows apps can check the Realm of Salt release service at release.saltyy.at for current Transferly version information. The request may result in ordinary technical server-log data such as IP address, request time and user-agent information being processed by the hosting infrastructure.
Update checks do not require a Transferly account and are not used to create a personal advertising profile.
Support and diagnostics
If you contact Transferly support, the information you choose to send is processed to answer your request. This may include your email address, message content, attachments and technical diagnostics.
Diagnostics generated by the app may include information such as app version, operating-system version, device model, permission states and relevant feature states. Transferly does not automatically attach the contents of transferred files to a support request.
Article 6(1)(b) GDPR applies where support is required for a contractual relationship or pre-contractual steps. In other cases, processing is based on the legitimate interest in responding to enquiries under Article 6(1)(f) GDPR.
Cookies, analytics and browser storage
At the time of this update, the public Transferly website and Web Transfer do not use analytics tracking, personalized advertising or tracking cookies. They do not require a user account.
Because Transferly does not currently use optional tracking cookies or comparable tracking technologies, the site does not currently display a cookie-consent banner. If optional analytics, advertising, cookies or similar technologies are introduced later, this Privacy Policy and any required consent mechanism will be updated before those technologies are used.
External links and platforms
Transferly may provide normal links to services such as Google Play, GitLab or other Realm of Salt pages. Merely displaying a normal link does not establish a connection to the destination provider. When you actively open an external service, that provider may process personal data under its own terms and privacy policy.
Recipients and international transfers
Personal data is disclosed only where necessary for hosting, infrastructure, communication, service delivery, legal compliance or protection of legal rights. Recipients may include hosting and technical service providers, email or telecommunications providers, professional advisers, public authorities or courts where legally required.
If a service provider processes data outside the European Economic Area, an appropriate legal transfer mechanism is used where required by data protection law.
Retention
Transferly keeps personal data only for as long as necessary for the relevant purpose:
- Relay files and ordinary Relay session metadata: until the session ends or expires, normally within 45 minutes
- Bluetooth presence and rendezvous data: seconds or a few minutes, depending on the flow
- rate-limit and abuse-prevention state: short-lived and automatically cleaned up
- local app data: until you remove it or uninstall/reset the app
- support communications and server logs: only as long as required for the request, security, troubleshooting, statutory duties or legal claims
Data security
Appropriate technical and organisational measures are used to protect data against unauthorized access, alteration, loss or destruction. Internet Relay traffic is transported over HTTPS. Transferly also uses random session secrets, access-code verification, rate limiting and SHA-256 integrity checks where applicable.
No Internet-based transmission or storage system can be guaranteed to be completely secure.
Your rights
Subject to the legal requirements, you may have the right to:
- request access to your personal data
- request correction of inaccurate or incomplete data
- request deletion of data
- request restriction of processing
- object to processing based on legitimate interests
- receive data in a portable format where applicable
- withdraw consent at any time where processing is based on consent
To exercise these rights, contact info@saltyy.at. Identity verification may be requested where necessary to protect your data.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority in Austria is:
Austrian Data Protection AuthorityBarichgasse 40-42
1030 Vienna
Austria
Email: dsb@dsb.gv.at
Website: www.dsb.gv.at
Changes to this Privacy Policy
This Privacy Policy may be updated when Transferly, its transfer architecture, hosting setup or legal requirements change. The current version is published on this page together with its update date.