Compliance built into the platform, not bolted onto the terms.

YouSend keeps your email address and nothing we could ever sell. Files are encrypted in transit and at rest, hard-deleted after the last download or at expiry, stored only on certified European infrastructure, and never used to train AI.

01 — Your Data

We keep your email address. We sell nothing.
Your account holds one thing: the email address you sign in with. Beyond short-lived security logs, we collect nothing. We will never sell data — not your files, not your metadata, not your contacts, not your transfer history. Nothing you send is ever used to train AI.

  • Account = email address
  • Never sold, not even metadata
  • Short-lived security logs
  • Never used to train AI

02 — Encryption & Deletion

Encrypted, then permanently deleted.
Every transfer travels over TLS and every stored file is encrypted with AES-256. Transfers are hard-deleted after the last download or at expiry, whichever comes first — removed from storage, not archived. Signing in always requires a one-time code.

  • TLS in transit
  • Hard delete: download or expiry
  • AES-256 at rest
  • OTP on every sign-in

03 — Certified Infrastructure

Hosted on certified European infrastructure.
Files are stored only with IONOS and Impossible Cloud — two German providers, both independently certified, both operating on EU data centres under EU jurisdiction.

  • ISO/IEC 27001
  • BSI C5:2020
  • ISAE 3000
  • SOC 2 data centres

The documents behind it.

Every commitment on this page is backed by our published terms.

  • Terms & Conditions — What you can expect from us, and what we expect from you.
  • Privacy Policy — Exactly what we hold, why, and for how long.
  • Laws & Regulations — The EU and Dutch laws we comply with, and why.

The certifications behind your files.

YouSend runs on two European infrastructure providers. The certifications below belong to them and cover the infrastructure your files are stored and processed on.

IONOS Cloud — Compute & Storage

IONOS SE · Montabaur, Germany · Gaia-X member

  • ISO/IEC 27001 (TÜV NORD) — Information security management system covering the entire IONOS Group — all products and processes.
  • ISO 27001 on BSI IT-Grundschutz (Valid to 09/2028) — Compute Engine, Cloud Object Storage and Managed Kubernetes in the Frankfurt and Berlin data centres.
  • BSI C5:2020 (Type 1) (PWC · 05/2026) — German federal cloud security attestation: 121 criteria across 17 areas, covering 33 IONOS Cloud services.
  • ISAE 3000 (Indep. Auditors) — Independent assurance report on security, availability, integrity and privacy controls.
  • ISO 50001 (TÜV NORD) — Energy management across all IONOS Cloud data centres.

Impossible Cloud — Object Storage

Impossible Cloud GmbH · Hamburg, Germany

  • ISO/IEC 27001 (Company ISMS) — Impossible Cloud is certified as a company, with an audited information security management system.
  • ISO 27001 · SOC 2 · PCI DSS (Data Centres) — Certifications held by the data centres that host Impossible Cloud storage.
  • EU-only storage (Residency) — Data is stored exclusively in European data centres (Germany and other EU regions), with country-level geofencing.