Privacy Policy

Last updated: 7 October 2026

SMBDrop moves photos, videos and files between your iPhone and SMB network shares that you own or control. It is designed so that your data stays yours.

This policy has two parts: the SMBDrop app, which sends nothing to anyone except a feedback message you choose to submit, and this website, which may use Google Analytics to count visits.

The app: data we collect

SMBDrop has no accounts, no analytics, no advertising and no tracking. Apart from the optional feedback form described below, the app does not collect, store or transmit any personal data to the developer or to any third party.

Optional feedback form

Settings › Request a Feature lets you send a message to the developer. Nothing is sent unless you type a message and tap Send. When you do, the app sends:

It is sent over HTTPS to a small relay run by the developer on Cloudflare Workers, which passes it to the email service Resend for delivery to the developer's inbox. It is used only to read and reply to your feedback. No files, photos, server details, passwords or device identifiers are included. If the relay can't be reached, the app offers to open your own Mail app instead, where you can see and edit everything before sending.

Where your files go

Files you send or import travel directly between your device and the SMB server you configure, over your own network. No third-party server is involved at any point, and the developer never sees your files or your server details.

Server credentials

The username and password for each SMB share are stored only in your device's iOS Keychain. They are used solely to connect to the server you configured and are never written to preferences, logs or any external service. Deleting a saved share removes its stored password.

Photos access

SMBDrop asks for photo-library access only so you can pick photos and videos to send, and for add-only access when you choose to save an imported image or video to your library. The app reads only what you select and never uploads anything you did not explicitly choose to send to your own server.

Local network access

SMBDrop asks for local-network permission because connecting to an SMB server on your network requires it. It is used only for the connections you initiate.

This website (smbdrop.com)

The website (not the app) may use Google Analytics 4 to count page views and see which pages and guides are useful. When it does, it is configured as follows, to collect as little as possible:

If analytics is on, what Google receives is the page address, the referring page, and general browser, device and approximate location information (country or city level). Google processes this data as described in Google's Privacy Policy. You can block it with any content blocker, or with Google's opt-out browser add-on, and the site works exactly the same.

The site also loads its fonts from Google Fonts, which means your browser requests them from Google's servers. The site is hosted on Cloudflare, which processes standard request logs to deliver it. Nothing you do on this website is connected to the app, and the app never contacts this website.

Changes

If this policy ever changes, the updated version will be published at this address with a new date.

Contact

Questions about privacy or the app? Open an issue on the SMBDrop issue tracker.