Official privacy notice: https://sharemydemo.com/en/privacy/
MyShare is provided by BUHUIPAO LTD. This notice covers the MyShare website, browser extensions and previews opened through the service.
Updated: 2026-09-14
Shared content and authentication
Your selected local addresses, files and visitor requests pass through MyShare’s Cloudflare gateway. Public connections use HTTPS/WSS; local services use the HTTP/HTTPS configuration you provide. The gateway processes requests and responses, so this is not end-to-end encryption that hides content from the service.
Local page and file bodies are used for relaying, not stored as long-term hosted copies. Requests may be temporarily buffered during transfer. Only files you select are read; copies held by the sharing page or extension remain in local memory.
Bearer, Basic and Cookie sign-in relay each visitor’s own credentials. The extension or project adapter isolates visitor cookies without reading or reusing the owner’s native sign-in. Application logs do not record request bodies, Cookie or Authorization values, passcodes or share-control credentials. Optional feedback records are described below.
Accounts, billing and domains
Registration processes your email and password; passwords are stored as hashes. We record your email verification status and use Resend to send 8-digit email verification and password reset codes. MyShare provides Resend with the recipient address, sender details and message content including the code to deliver these account emails. We do not send your password or shared content to Resend. MyShare stores a keyed hash of each code; codes expire after 10 minutes and become invalid after use. Account details, subscription state, Stripe customer/subscription identifiers and reserved domain records support sign-in, billing, entitlements and domain management.
Payment details are handled on Stripe’s checkout and billing pages. MyShare does not receive or store full payment-card numbers. Stripe, Cloudflare and Resend also process data required to operate their services under their own terms: Stripe privacy policy, Cloudflare privacy policy and Resend privacy policy.
If you choose an enabled Google, GitHub or Facebook sign-in option, we obtain your account identifier, available email and its verification status from that provider. We keep the provider and account identifier association to sign you in to MyShare. We do not request GitHub repository access, retain provider access tokens or merge accounts solely because their emails match. You can explicitly connect a provider from your signed-in account.
Essential cookies and local storage
The website uses cookies for anonymous share ownership and account sign-in, plus essential cookies lasting up to 10 minutes to bind provider sign-in checks. Previews use separate-origin cookies for access and feedback preferences. Your project sets its own sign-in cookies, which are mapped to the corresponding preview origin. Language preference is kept in local storage; share recovery state stays in the relevant tab or the extension’s private session storage.
These support authentication, limits, access control and recovery. Clearing browser data may sign you out, remove control of an existing share or require another unlock. Project cookies and storage at saved addresses may carry over to later shares, so use different names for different projects.
Visitor choices: analytics, comments and replay
Visitor features are off by default for the owner. When enabled, visitors choose whether to allow page paths, click counts, time spent and named custom events to be recorded. Studio replay needs a separate choice. Declining does not prevent browsing or commenting.
Replays record masked page structure and interactions, not screen video. Text and form inputs are masked by default; private areas, passwords and embedded pages are blocked. Network bodies, authentication credentials, console output and keystrokes are not recorded. URL query strings and fragments are removed, but paths and structure can still reveal project information. Share only content you are entitled to disclose.
Replay is limited to 5 minutes and 5 MiB per visitor. Withdrawing consent stops collection on the current page immediately. Once the server saves that choice, the visitor’s saved replays are deleted. Retry after an offline failure to complete server deletion; existing aggregate analytics may remain.
Visitors submit comments voluntarily. Comments are visible to the owner and other visitors. Do not include passwords or sensitive personal information. The owner can delete comments.
Retention
Share access expires when stopped or timed out. Content bodies are relayed; selected files are released with their local context.
Share details and feedback are cleaned up after the share ends: 30 days for Pro and 90 days for Studio. Free-share usage details are scheduled for cleanup 30 days after ending.
Creation records, usage and connection outcomes use a 90-day cleanup window. Active shares are retained while running; record and summary windows may start at different times.
Email codes expire after 10 minutes, with expired records scheduled for cleanup. Account sign-in sessions last 30 days. Account, billing and reserved-domain records have no single automatic expiry period.
Anti-abuse limits use irreversible HMAC identifiers derived from IP addresses. Share rate-limit counters last at most one hour; authentication limits use short-lived counters. Cloudflare Turnstile processes signals needed for security checks.
Contact and privacy requests
To ask about, access, correct or delete account-related data, contact chenhua22@outlook.com with your account email and request. Do not send passwords, email codes, full card numbers or share-control credentials. Data deletion and subscription cancellation are separate actions; use account billing management to stop future renewal charges.