Our terms, in plain language.

01 You own your files.

We claim no ownership of your content and take no licence to use it beyond what is needed to store and deliver your transfer.

02 We keep your email address and short-lived security logs.

Your email address signs you in with a one-time code and delivers transfer notifications. Security logs are kept briefly to protect the service, then deleted.

03 We never sell data. Not even metadata.

We do not sell, rent or license files, metadata or anything else, and no file uploaded to YouSend is ever used to train an AI model.

04 Encrypted, then hard-deleted.

TLS protects every transfer on the way and AES-256 protects every file in storage. A transfer is permanently deleted after the last download, or at its expiry date if that comes first.

05 EU company, EU jurisdiction.

YouSend is operated by Apura Cloud B.V., a Dutch company. Your files are stored only on EU infrastructure.

06 Payments via Stripe — for now.

Card and billing details are processed by Stripe. We are moving to a Dutch payment provider as soon as possible.


The laws we comply with.

European and Dutch law, applied in full. Where a law does not strictly apply to a file-sharing service, we still meet it — and say exactly why.

GDPR — COMPLIANT

Regulation (EU) 2016/679

We keep only your email address and short-lived security logs, encrypt everything, store files only in the EU and hard-delete transfers after the last download or at expiry.

Dutch GDPR Implementation Act (UAVG) — COMPLIANT

Uitvoeringswet AVG

As a Dutch company, we apply the Dutch implementation of the GDPR in full.

ePrivacy Directive & Dutch Telecommunications Act — COMPLIANT

Directive 2002/58/EC · Telecommunicatiewet

We don't use cookies, don't track you and don't use your data for profiling or advertising.

NIS2 Directive & Dutch Cybersecurity Act — COMPLIANT

Directive (EU) 2022/2555 · Cyberbeveiligingswet

Encryption in transit and at rest, one-time-code sign-in and certified EU infrastructure support your supply-chain security obligations.

DORA — COMPLIANT

Regulation (EU) 2022/2554

EU-only, encrypted and independently certified infrastructure fits the ICT third-party requirements financial institutions must meet.

EU AI Act — COMPLIANT

Regulation (EU) 2024/1689

Because we don't use AI.

EU Data Act — COMPLIANT

Regulation (EU) 2023/2854

Your files remain yours, and transfers are deleted after the last download or at expiry, so there is no data to lock you in.

Data Governance Act — COMPLIANT

Regulation (EU) 2022/868

We don't share, reuse or broker data — with anyone.

Digital Services Act — COMPLIANT

Regulation (EU) 2022/2065

Clear terms, a single point of contact and a route to report illegal content.

Copyright in the Digital Single Market — COMPLIANT

Directive (EU) 2019/790 · Auteurswet

Your files are never subjected to text and data mining.

Cyber Resilience Act — COMPLIANT

Regulation (EU) 2024/2847

Security by design — encryption in transit and at rest and one-time-code sign-in by default.