Privacy policy

Last updated: 18 September 2026

Downaro is a public-link helper. We try to collect as little as a working tool allows.

What we process

  • URLs you submit to the resolver so we can check the host and look for public media. They are used to fulfill the request. They are not used to build a public browse history.
  • Technical logs that a host may keep (IP address, user agent, time) for security and rate limiting.
  • Contact messages you send, including the email you type.
  • Theme preference stored in your browser via localStorage if you toggle light or dark mode.

What we do not want

  • Platform passwords, session cookies, or two-factor codes.
  • Payment card data (there is no checkout at launch).
  • Files uploaded from your device. You paste a URL; you do not attach media.

Analytics

No analytics product is hardcoded into Downaro. If the operator later enables privacy-conscious analytics or GA4, this policy will be updated on the same day and the measurement IDs will live in environment variables — not in public git.

When analytics is on, useful events may include tool submit, success, error, download click, and platform selected. They should not include the full pasted URL.

Cookies

A session cookie is used for CSRF protection on the contact form. It is HTTP-only and uses SameSite=Lax.

Third parties

When you ask Downaro to resolve a link, our server may request a public page or public JSON from that platform. Those companies then see a request from our servers, not a login as you.

Hosting is provided by the operator’s host (initially Hostinger). Email, if configured, uses the host mail transport.

Retention

Rate-limit files are short-lived. Contact messages stay in the inbox until they are handled. We do not operate a user account database at launch.

Contact

Privacy questions: hello@downaro.com or the contact form.