AnonShot

Privacy and data

What AnonShot processes during a share, what recipients can see, and how technical data protects the service.

No account does not mean no technical processing

A one-off link requires no name or email address. AnonShot still uses a session identifier in a cookie so you can find and delete shares from the same browser.

If you create an optional account, the email address and a secure password hash are stored. The password itself is never retained in plain text.

Pictures and metadata

The shared copy is converted to WebP and stripped of EXIF metadata. The original, extracted metadata, and cleaned copy are held in private storage for moderation, security, and abuse management; only the cleaned file is served through the public link.

An individual link stops working after its 30-day expiry, owner deletion, or burn-after-read. Disabling public access does not necessarily mean immediate erasure of technical records and private material needed for moderation.

Connection data

During an upload or photo opening, the service may record the IP address, browser, approximate infrastructure-provided location, and an irreversible IP + browser fingerprint used to count unique views.

This data supports operation, rate limits, abuse detection, moderation, and aggregate statistics. Private photo and album pages do not load Vercel Analytics or Cloudflare Web Analytics scripts.

Visibility and control

The /p/ and /a/ links are unlisted, excluded from the sitemap, and marked noindex. Anyone who knows an address can still forward it or save what they see.

Owners can disable a share from their session or account. A password and burn-after-read reduce exposure but cannot prevent a recipient from making a copy.

Last updated: August 2, 2026.