xocat.host
Private R2 file hosting
legal
Terms of Use
Last updated August 11, 2026.
1. What this is
Xocat.host is a private file hosting service backed by Cloudflare R2 storage. It is operated as a personal project, not a commercial company, and is provided as-is with no guaranteed uptime, support, or service level.
Accounts are created by signing in with Discord. By creating an account or uploading a file, you agree to these terms.
2. Accounts and Discord
- Accounts are created by signing in with a Discord account that is not already linked to an account here. There is no other way to register.
- You are responsible for keeping your account credentials and profile picture link private if you don't want them shared.
- One account per person unless explicitly permitted by the operator.
- Signing in with Discord links one Discord account to one xocat.host account. A Discord account already linked to an account here cannot be used to open a second one. The sign-in requests only the identify and email scopes, so it reads your Discord id, username, avatar, and verified email and nothing else, and it never posts or acts as you. Section 5 of the Privacy Policy sets this out in full.
- Every account needs a linked Discord account to be usable. An account created before this rule keeps its password and can still sign in with it, but is limited to its account page until it links one.
- A password is a backup way to sign in, for when Discord is unavailable. You are responsible for choosing a strong one and keeping it private.
3. Storage and uploads
- Regular accounts have a fixed storage quota of 500 MB shown on the dashboard. Premium accounts have a 2 GB quota, and purchased extra storage adds $1 per extra GB. Uploads that exceed the account quota will be rejected.
- Regular individual file uploads are limited to 10 MB. Premium individual file uploads are limited to 100 MB. Files larger than your tier limit will be rejected.
- Supported upload types include images, gifs, webp, avif, videos, and regular files.
- Files are stored exactly as uploaded and are kept until you delete them. Embedded metadata, including EXIF data such as GPS coordinates, is not removed, so review a file yourself before uploading it if that matters to you.
- An upload link has no password, expiry, or view limit. Anyone who has the link can open the file as often as they like, so treat every upload link as public.
4. Prohibited content and conduct
You may not upload, host, link to, or distribute through xocat.host:
- Child sexual abuse material (CSAM) or any content sexualizing minors, in any form. This is covered separately in section 5.
- Content that is illegal under the laws applicable to you or to the operator
- Malware, exploits, phishing pages, or anything designed to compromise another person's device or accounts
- Content that infringes copyright or other intellectual property rights you do not own or have rights to distribute
- Material intended to harass, threaten, dox, or non-consensually expose another person, including non-consensual intimate imagery
- Content promoting terrorism, extremist violence, or that otherwise facilitates serious harm to others
- Violation of this section results in content removal or quarantine and account termination, and may be reported to relevant authorities or Cloudflare where required by law or acceptable use policy.
5. Child sexual abuse material
There is zero tolerance for child sexual abuse material on xocat.host. There is no warning, no strike system, and no appeal.
Where the operator becomes aware of such material, all of the following happen:
- It is reported to the National Center for Missing & Exploited Children (NCMEC), as required by 18 U.S.C. 2258A.
- The account is terminated immediately.
- The content and the records associated with it are preserved and disclosed to NCMEC and to law enforcement. Those records include the IP address the file was uploaded from, the user agent, the upload timestamp, the account email and handle, and the account's other upload history.
- The material is preserved even though it stops being publicly accessible. Preservation is a legal obligation, so this content and its records cannot be deleted at your request, and deleting your account does not remove them.
6. Moderation, suspension, and termination
The operator may remove or quarantine content, and may suspend or ban an account, for violation of these terms or for operational reasons (such as shutting down the service entirely). This can happen with or without notice.
Quarantined content stops being publicly accessible: its links stop serving the file, and it also disappears from the uploader's own dashboard. Copies already cached by the CDN or by someone's browser can survive briefly after that, so removal is not instantaneous everywhere. The underlying file is not necessarily destroyed. Where the law requires the material to be preserved, or where it is evidence in an investigation, it is retained rather than deleted. Removing public access and destroying evidence are deliberately separate steps.
- A banned account loses access to the dashboard and to its files.
- Evading a ban is itself a violation of these terms. Registering again after a ban, signing in with a different Discord account to come back, or creating an additional account to get around a suspension will result in the new account being removed as well.
- The operator may refuse registration from an email address, an email domain, or an IP address associated with a previous violation.
- You may delete your own files from the dashboard at any time, except while a file is quarantined. You may request deletion of your account and data at any time by contacting the operator, subject to the preservation obligations described in section 5.
7. Custom domains and CDN
Subdomains configured under domain settings (such as a custom CDN subdomain) route uploads through DNS records controlled by the operator. Removing a domain from your settings does not retroactively delete files already served through it, but new uploads will stop routing through a removed domain.
8. Removal and takedowns
The operator may remove any file or account at their discretion, particularly in response to a valid copyright complaint, legal request, or violation of section 4 or 5. If you believe content hosted on xocat.host infringes your rights, contact the address in section 10 with enough detail to identify the file (URL, upload date, and a description of the issue).
9. No warranty
Xocat.host is provided as-is and as-available. The operator does not guarantee that the service will be uninterrupted, secure, or error-free, and is not liable for data loss, including files lost through account termination, moderation action, or service discontinuation. Keep independent backups of anything you cannot afford to lose.
10. Changes and contact
These terms may be updated at any time. Continued use of xocat.host after changes are posted constitutes acceptance of the updated terms. For questions, takedown requests, or account issues, contact support@xocat.online.