Privacy policy
Last updated: 18 September 2026
Downaro is a public-link helper. We try to collect as little as a working tool allows.
What we process
- URLs you submit to the resolver so we can check the host and look for public media. They are used to fulfill the request. They are not used to build a public browse history.
- Technical logs that a host may keep (IP address, user agent, time) for security and rate limiting.
- Contact messages you send, including the email you type.
- Theme preference stored in your browser via
localStorageif you toggle light or dark mode.
What we do not want
- Platform passwords, session cookies, or two-factor codes.
- Payment card data (there is no checkout at launch).
- Files uploaded from your device. You paste a URL; you do not attach media.
Analytics
No analytics product is hardcoded into Downaro. If the operator later enables privacy-conscious analytics or GA4, this policy will be updated on the same day and the measurement IDs will live in environment variables — not in public git.
When analytics is on, useful events may include tool submit, success, error, download click, and platform selected. They should not include the full pasted URL.
Cookies
A session cookie is used for CSRF protection on the contact form. It is HTTP-only and uses SameSite=Lax.
Third parties
When you ask Downaro to resolve a link, our server may request a public page or public JSON from that platform. Those companies then see a request from our servers, not a login as you.
Hosting is provided by the operator’s host (initially Hostinger). Email, if configured, uses the host mail transport.
Retention
Rate-limit files are short-lived. Contact messages stay in the inbox until they are handled. We do not operate a user account database at launch.
Contact
Privacy questions: hello@downaro.com or the contact form.