Privacy

hopli ยท last updated 31 August 2026

We collect nothing.

No account, no sign-up, no analytics, no cookies, no tracking, no logs of what you send. There is no server that receives your files, so there is nothing for us to keep, sell, lose, or hand over.

Where your files go

Directly from one of your devices to the other, across your own Wi-Fi, over an encrypted connection. They do not pass through this website or any server we run. When the transfer ends, nothing remains except the file where you chose to save it.

You can prove this yourself: disconnect your internet and keep transferring. It still works, because nothing was ever going anywhere else.

What this page does see

Being straight about the one exception. To open Hopli, your browser downloads this page from a static host (Cloudflare Pages). Like any website, that request involves your IP address and reaches their servers. We do not add analytics on top of it, and we do not receive or store anything from it.

The pairing details โ€” your desktop's address, its certificate fingerprint, the session token โ€” travel in the part of the URL after the #, which browsers never send to a server. The host therefore cannot learn who paired with whom, even in principle.

What stays on your devices

Your phone keeps a random device id in browser storage, so a desktop you have already approved does not ask again every time. Your desktop keeps a short-lived key and a list of devices you approved. Both are local. Clearing your browser data removes the first; deleting Hopli's configuration folder removes the second.

Children and everyone else

Hopli has no accounts and collects no personal data from anyone, of any age.

Questions

The code is the real answer to most privacy questions, and it is readable. If something here does not match what the code does, that is a bug worth reporting.