Our terms, in plain language.
01 You own your files.
We claim no ownership of your content and take no licence to use it beyond what is needed to store and deliver your transfer.
02 We keep your email address and short-lived security logs.
Your email address signs you in with a one-time code and delivers transfer notifications. Security logs are kept briefly to protect the service, then deleted.
03 We never sell data. Not even metadata.
We do not sell, rent or license files, metadata or anything else, and no file uploaded to YouSend is ever used to train an AI model.
04 Encrypted, then hard-deleted.
TLS protects every transfer on the way and AES-256 protects every file in storage. A transfer is permanently deleted after the last download, or at its expiry date if that comes first.
05 EU company, EU jurisdiction.
YouSend is operated by Apura Cloud B.V., a Dutch company. Your files are stored only on EU infrastructure.
06 Payments via Stripe — for now.
Card and billing details are processed by Stripe. We are moving to a Dutch payment provider as soon as possible.
The laws we comply with.
European and Dutch law, applied in full. Where a law does not strictly apply to a file-sharing service, we still meet it — and say exactly why.
GDPR — COMPLIANT
Regulation (EU) 2016/679
We keep only your email address and short-lived security logs, encrypt everything, store files only in the EU and hard-delete transfers after the last download or at expiry.
Dutch GDPR Implementation Act (UAVG) — COMPLIANT
Uitvoeringswet AVG
As a Dutch company, we apply the Dutch implementation of the GDPR in full.
ePrivacy Directive & Dutch Telecommunications Act — COMPLIANT
Directive 2002/58/EC · Telecommunicatiewet
We don't use cookies, don't track you and don't use your data for profiling or advertising.
NIS2 Directive & Dutch Cybersecurity Act — COMPLIANT
Directive (EU) 2022/2555 · Cyberbeveiligingswet
Encryption in transit and at rest, one-time-code sign-in and certified EU infrastructure support your supply-chain security obligations.
DORA — COMPLIANT
Regulation (EU) 2022/2554
EU-only, encrypted and independently certified infrastructure fits the ICT third-party requirements financial institutions must meet.
EU AI Act — COMPLIANT
Regulation (EU) 2024/1689
Because we don't use AI.
EU Data Act — COMPLIANT
Regulation (EU) 2023/2854
Your files remain yours, and transfers are deleted after the last download or at expiry, so there is no data to lock you in.
Data Governance Act — COMPLIANT
Regulation (EU) 2022/868
We don't share, reuse or broker data — with anyone.
Digital Services Act — COMPLIANT
Regulation (EU) 2022/2065
Clear terms, a single point of contact and a route to report illegal content.
Copyright in the Digital Single Market — COMPLIANT
Directive (EU) 2019/790 · Auteurswet
Your files are never subjected to text and data mining.
Cyber Resilience Act — COMPLIANT
Regulation (EU) 2024/2847
Security by design — encryption in transit and at rest and one-time-code sign-in by default.