xocat.host

Private R2 file hosting

legal

Privacy Policy

Last updated July 2, 2026.

1. Overview

This policy explains what data xocat.host collects, why it's collected, and how it's stored. Xocat.host is a small, invite-only service, this data is not sold, and is not shared with advertisers.

2. Data we collect

DataWhy it's collected
Email addressAccount login, notices about your account or service changes
Display name and profile pictureShown inside the dashboard and account page
Uploaded files and filenamesCore function of the service
Password (hashed)Account authentication. Passwords are hashed before storage and are never stored or logged in plain text
IP address and request logsRate limiting, abuse prevention, and security (retained through Cloudflare's edge logging)
Invite code usageTracking which codes have been used, to prevent reuse

3. File metadata

When the clear location data setting is enabled (on by default), embedded metadata such as GPS EXIF data is stripped from uploaded images before storage. If you disable this setting, metadata embedded in your files by your device or software is stored as part of the file and may be visible to anyone with the file's link.

4. Where data is stored

Files and account data are stored using Cloudflare R2 and associated Cloudflare infrastructure, including DNS routing for any custom subdomains configured in domain settings. Cloudflare acts as the infrastructure provider and processes data on behalf of xocat.host under its own data processing terms.

5. Retention and deletion

  • Files are retained until you delete them, unless the autowipe setting is enabled, in which case files are automatically deleted after the configured period.
  • Files uploaded with the exploding files setting are permanently deleted after being opened once.
  • You may delete individual files or your entire account at any time. Account deletion removes your profile data and revokes access, associated files are deleted from storage as part of that process.
  • Deleted files and deleted accounts are not recoverable once removed.

6. Security

Passwords are stored using salted hashing rather than plain text. The service applies rate limiting on authentication and upload endpoints, and has undergone review for common web vulnerabilities including cross-site scripting (XSS). No system is perfectly secure, if you believe you've found a vulnerability, report it to the contact below rather than exploiting it.

7. Who can see your data

Uploaded files are accessible to anyone who has the generated link, unless you use the exploding files setting or otherwise restrict access. Account details (email, display name) are visible only to you and the operator, they are not shown publicly.

8. Children's privacy

Xocat.host is invite-only and is not directed at children. Accounts are not knowingly created for or by anyone under the age of 13, and any account discovered to belong to a child under that age will be removed.

9. Changes and contact

This policy may be updated as the service changes. For questions about your data, or to request account or file deletion, contact support@xocat.online.