shareout

Shareout

Privacy policy

What Shareout stores, who can see it, and how to delete it.

Effective October 2, 2026

Shareout is operated by Greg Eland. This policy covers shareout.io, pages hosted on shareout.page, and the Shareout CLI and MCP integrations. Questions or privacy requests: hello@gregeland.com.

What we collect

  • Account and connection information. Your email address, account status, connection names and permissions, credential hashes, sign-in records, and usage totals. We use these to authenticate you, operate your workspace, enforce limits, and protect the service.
  • The work you publish. HTML, bundled files, titles, descriptions, versions, sharing settings, invitations, and review comments. We store and serve this information so you can share, discuss, and revise your work.
  • Viewing activity. Document and version viewed, link used, time, approximate country/region/city, browser family, and referring website hostname when available. To estimate daily unique viewers, we derive a daily identifier from the visitor’s IP address and user-agent using a keyed hash. The view database does not store the raw IP address or full user-agent.
  • Support and safety records. Messages you send us, access requests, abuse reports, rate-limit identifiers, and audit records of account and document actions. Our infrastructure also processes IP addresses and request metadata to deliver traffic, prevent abuse, and diagnose failures.

Who can see your information

Public pages can be opened by anyone. Anyone with a complete private viewing link can use it until it expires or is revoked. Recipients can keep copies of content they have already received. Search indexing is a separate setting, and disabling indexing does not make a public page private.

Document owners and authorized collaborators can see information permitted by their role, including review comments and viewing statistics. Comments include an author label and may include selected text or a location within the document. Viewing statistics are estimates, not a verified list of readers.

Shareout’s operator may access stored information to provide support, investigate abuse, meet legal obligations, or maintain the service. Shareout is not end-to-end encrypted storage.

When you connect an agent, the connection receives the permissions you approve. Your agent provider processes the information returned to it under its own policies. Hosted uploads transfer files directly to Shareout; Shareout’s MCP tools do not accept document bytes in their arguments. The agent you use may already have access to the files you ask it to publish.

Service providers and external resources

Cloudflare provides hosting, storage, database, security, Turnstile verification, and transactional email infrastructure. Email also passes through the recipient’s email provider. Support email is forwarded to a Gmail inbox. These providers may process information in the United States and other countries where they operate. We do not promise storage in a particular country.

The shareout.io website also uses Cloudflare Web Analytics to measure page visits and loading performance, including page paths, referring sites, browser and device categories, and approximate country. This analytics service does not use cookies. See Cloudflare’s description of the data it collects. This is separate from the document view records described above.

Published pages may load scripts or fonts from permitted providers, including Cloudflare’s cdnjs, jsDelivr, Tailwind CSS, jQuery’s CDN, and Google Fonts. Those requests expose normal connection information, such as an IP address, to the provider. Authors can bundle assets instead. Links to other websites are governed by those websites’ policies.

See Cloudflare’s privacy policy and Google’s privacy policy. We do not sell personal information, use it for targeted advertising, or train AI models on your documents.

Cookies and browser storage

Recipient viewing does not require a Shareout cookie. Publisher and operator dashboards use secure, host-only session cookies on shareout.io. Sign-in uses a short-lived cookie to bind the email link to the browser that requested it. Cloudflare Turnstile processes browser signals for abuse prevention.

The website stores your Light, Dark, or System appearance preference in local browser storage. Clearing browser storage removes that preference. Published interactive pages may also keep their own local state in the document’s isolated origin.

Retention and deletion

  • Documents and versions remain until you delete them or their selected retention deadline is reached. New documents default to no scheduled deletion. Link expiry and revocation stop access through that link; they do not delete the document.
  • Deleted documents become unavailable immediately. An hourly cleanup process removes their stored files and associated document records in batches. Cleanup may take longer after a backlog or failure. Minimal deletion records and audit history remain.
  • Detailed view events are scheduled for deletion after 30 days. Daily unique-viewer identifiers are pruned on a roughly two-day schedule. Aggregate counts remain with the document.
  • Account deletion is available under Settings in the console. It disables the account, replaces its account email with a placeholder, revokes keys and sessions, and schedules owned documents for cleanup. Comments on other people’s documents and email addresses in invitation, access-request, support, or audit-related records may remain. Contact us to request review or removal of that information.
  • Other operational records, including audit history, reports, and support correspondence, do not currently have a uniform automatic deletion period. We retain them for service operations, security, dispute handling, and legal obligations. Infrastructure logs and backup copies follow the providers’ retention processes; deletion from active storage does not promise immediate removal from every backup.

Your choices and requests

You can change document visibility and retention, revoke links and agent connections, delete documents or your account, and edit or delete your own comments. To request access, correction, export, or deletion of personal information, email hello@gregeland.com. Depending on where you live, you may have additional privacy rights. We may need to verify your identity and authority over the affected information before acting.

For a document published by someone else, contact its publisher or send us the document address and a description of your request. Do not send API keys or private content that is not needed to explain the issue.

Age and changes

Shareout publishing accounts are intended for adults aged 18 or older. The service is not directed to children. If you believe a child has provided personal information, contact us.

We will update the date on this page when the policy changes. For material changes affecting existing accounts, we will provide notice through the service or by email as appropriate.