Privacy Policy
Last updated July 2026
This policy explains what happens to your files and your data when you use Drefly. It is written in plain language on purpose, so you know exactly what we do and do not keep.
Temporary file storage only
Most tools on Drefly process your file on our servers only for the time it takes to complete the task, such as converting, compressing, merging, or downloading. Crop Video, Clip Video, Reel Maker, and Record do their editing (cropping, trimming, recording, arranging clips) entirely in your browser, and that part never reaches our servers. If you then export to a different format than the one you started with, that final file is sent to our servers to be converted, the same as our dedicated Convert Video and Convert Image tools.
- We do not impose an artificial file size limit. You can process large files, and they are handled the same way as small ones, with no signup and no extra step.
- For server-processed tools, files are stored only for as long as your task takes to run.
- Once a task finishes and the result is delivered directly to you in the same browser session, the temporary file is automatically deleted from our servers.
- If a file is large enough that we email you a download link instead, the converted file is kept only long enough for you to retrieve it: it is automatically deleted 24 hours after conversion, and the download page also lets you delete it yourself at any time before that.
- We do not keep a permanent copy of any file you upload, convert, or download through Drefly.
- We do not review, scan, or use the content of your files for any purpose other than completing your request.
- If you provide an email address so we can send you a download link for a large file, that email is used only for that delivery (and, if needed, to tell you a conversion failed) and is not added to any marketing list.
The Drefly widget on other websites
Some websites and apps embed the Drefly widget so their own visitors can record a screen capture and send it straight to that site's team, usually to report a bug or show a support issue. If you see a recording control on a site that is not drefly.pro, it is the Drefly widget, running on behalf of that site's owner.
- A recording only starts after you click the record control and approve your browser's own screen sharing prompt. Nothing is captured before that click, and your browser's built in indicator shows whenever screen or microphone access is active.
- The widget asks your browser to favor sharing only the current browser tab rather than your whole screen or another window, and it never has access to any other tab, application, or window you have open.
- While a recording is running, the widget automatically blurs password fields and other clearly sensitive fields, such as card numbers, card security codes, and fields the site owner has explicitly marked as sensitive, so those values are not visible in the recorded video.
- A finished recording is uploaded directly to storage that belongs to the site you were using, not to Drefly. Drefly operates the widget code and the upload pathway, but the site owner controls where recordings are stored and who can view them.
- Each widget only accepts recordings from the specific domain or domains its owner registered it to, including wildcard subdomains such as *.example.com, so a widget key cannot be reused on a site it was not configured for.
- You can decline the browser's screen sharing prompt at any time to cancel a recording before it starts, and you can stop a recording in progress from the widget itself.
- Because each site sets its own widget up independently, questions about how a specific recording is used, stored, or deleted should go to that site, not to Drefly.
Recording and your own cloud storage
The Record tool lets you record your screen, camera, or both directly in your browser. What happens to a recording depends entirely on how you choose to save it.
- If you simply save a recording to your device, it is captured and processed entirely in your browser, and the recording itself never reaches our servers.
- Connecting a cloud drive is required only if you choose to save a recording with a shareable drefly.pro link. Google Drive, Dropbox, and OneDrive are all supported. No other tool on Drefly requires you to connect a drive or sign in to anything.
- When you choose "Save to your Drive," the recording is uploaded directly to a folder in your own connected drive, and the shareable link points to that file in your drive, not to a copy on our servers.
- For Google Drive and OneDrive, the recording is sent from your browser straight to your drive; it never passes through Drefly's servers. For Dropbox, Drefly's server acts as a relay to complete the upload, since Dropbox does not support the same direct browser upload method. Your recording bytes pass through that relay in transit only, are never written to disk or stored on Drefly's servers, and the relay handle used for this is encrypted and expires automatically.
- We do not store your recordings, or copies of them, on Drefly's servers. We keep only the small amount of reference information needed to show the recording on your Recordings page and let you manage or revoke a share, such as the drive file ID and the share link itself.
- Drefly's access to your drive is limited to creating, reading, and managing the recordings it saves there on your behalf. We do not browse, read, or use any other files already in your drive.
- You can disconnect a connected drive at any time from the Drives panel on the Recordings page. Disconnecting removes the access token Drefly stored for that drive; recordings already saved remain in your drive, but Drefly can no longer manage them until you reconnect.
Your own API keys (BYOK)
Certain AI tools allow you to use your own API key from a provider such as Anthropic, OpenAI, or Google Gemini. We take a strict approach to these keys.
- We do not store your API key on our servers at any point, permanently or otherwise.
- Your key is kept in your browser, either in local browser storage on your own device or in temporary memory only while a single request is being served.
- Your key is sent directly to the AI provider you selected to complete your request, and is never logged or saved on our end.
Your local file history
Drefly keeps a history of the files you download or share from any tool, so you can find and re-download them later. This history is stored only inside your own browser, using a browser feature called IndexedDB - it is never uploaded to, copied to, or stored on Drefly's servers.
- Each result is saved automatically to this browser right after you download it or share it, with no extra step required from you.
- You can view your history for a single tool from the History button on that tool's page, or across every tool at once on the History page.
- Each saved file also gets its own local link (for example,
/tools/merge-pdf?historyId=...), similar to how some other web apps give each saved document its own URL. This link only works in the same browser on the same device, because the file itself never leaves your browser - it cannot be opened by anyone else, on another device, or by Drefly. - History is kept until you delete an individual entry, use "Clear this tool's history" or "Clear all history," or clear your browser's site data. Drefly does not set any automatic expiry on it.
- Because this history lives in browser storage, it does not sync between browsers or devices, and it can be removed at any time by clearing your browser's storage for drefly.pro (for example, through your browser's site settings or by using a private/incognito window, which never saves it in the first place).
- We cannot see, read, or access this history - it is not sent to us at any point.
Information we collect
We keep the data we collect to a minimum.
- Basic technical information such as browser type and general usage patterns, used only to keep the service running and to fix problems.
- Aggregated usage analytics collected through Google Analytics, described in the "Cookies and analytics" section below.
- Information you choose to submit through the Feedback form, such as your name, email, and message, which is used only to respond to you.
- We do not sell your data, and we do not build advertising profiles from your activity.
No accounts, no payments
Drefly does not require you to sign up, log in, or create an account for any tool. We also do not ask for payment, a card, or a subscription. Every tool is free to use as a guest.
Cookies and analytics
Drefly uses a small amount of cookies and browser storage needed for the site to function correctly, such as remembering a BYOK key you entered. We also use Google Analytics, on an opt-in basis, to understand overall traffic and usage patterns, such as which pages and tools are visited and roughly how often.
- On your first visit, a cookie banner asks whether you'd like to allow analytics cookies. Analytics stays off by default until you choose "Accept all," and no analytics cookies are set if you choose "Reject non-essential." We use Google's Consent Mode to enforce this choice technically, not just visually.
- You can change your choice at any time by clearing your browser's cookies or site data for drefly.pro, which will show the banner again on your next visit.
- If you accept, Google Analytics sets cookies and collects information such as your approximate location (derived from IP address), device and browser type, and the pages you visit on Drefly.
- This data is processed by Google under its own privacy policy, and is used by us only in aggregate to improve the site - we do not use it to identify you individually.
- We do not run advertising trackers or third party ad networks, we do not use this data to build advertising profiles, and we do not sell it.
- Even after accepting, you can also opt out of Google Analytics tracking using the Google Analytics Opt-out Browser Add-on, or by using your browser's tracking-protection or "Do Not Track" settings.
Third party services
Drefly runs on third party infrastructure for hosting, and uses Google Analytics for site analytics as described above. When you use a downloader tool, we retrieve content from the source platform you link to. When you use your own API key, your request is sent to the AI provider tied to that key. Each of these providers has its own privacy practices, and we encourage you to review them if you have questions beyond what is covered here.
Data retention
Because we do not keep permanent copies of user files, there is nothing to retain beyond the short processing window described above. Feedback messages are kept only as long as needed to review and respond to them.
Children's privacy
Drefly is not directed at children under 13, and we do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time as Drefly changes. Any changes will be posted on this page, and the date at the top will be updated.
Contact us
If you have any questions about this policy or how your data is handled, email support@drefly.pro.