Privacy
hopli ยท last updated 31 August 2026
We collect nothing.
No account, no sign-up, no analytics, no cookies, no tracking, no logs of what you send. There is no server that receives your files, so there is nothing for us to keep, sell, lose, or hand over.
Where your files go
Directly from one of your devices to the other, across your own Wi-Fi, over an encrypted connection. They do not pass through this website or any server we run. When the transfer ends, nothing remains except the file where you chose to save it.
You can prove this yourself: disconnect your internet and keep transferring. It still works, because nothing was ever going anywhere else.
What this page does see
Being straight about the one exception. To open Hopli, your browser downloads this page from a static host (Cloudflare Pages). Like any website, that request involves your IP address and reaches their servers. We do not add analytics on top of it, and we do not receive or store anything from it.
The pairing details โ your desktop's address, its
certificate fingerprint, the session token โ travel in the part of the URL
after the #, which browsers never send to a server. The host
therefore cannot learn who paired with whom, even in principle.
What stays on your devices
Your phone keeps a random device id in browser storage, so a desktop you have already approved does not ask again every time. Your desktop keeps a short-lived key and a list of devices you approved. Both are local. Clearing your browser data removes the first; deleting Hopli's configuration folder removes the second.
Children and everyone else
Hopli has no accounts and collects no personal data from anyone, of any age.
Questions
The code is the real answer to most privacy questions, and it is readable. If something here does not match what the code does, that is a bug worth reporting.