PlainTray

The Simple Data Tray

Terms of Service & Privacy Policy

Effective: February 15, 2026

Terms of Service

Acceptance of Terms

By using PlainTray, you agree to these Terms of Service and our Privacy Policy. If you do not agree, please do not use the service. You must be at least 16 years old to use PlainTray in Switzerland and the European Union, or at least 13 years old in the United States. By using PlainTray, you represent and warrant that you meet the applicable age requirement. If you are a parent or guardian and believe your child has provided personal data, contact us at legal@plaintray.com to request deletion.

What PlainTray Is

PlainTray is a free, zero-knowledge encrypted platform for sharing text and files. No account is required. You get a short code that serves as both your access key and the source of your encryption key. The server never sees your plaintext content.

Using PlainTray

You may use PlainTray for any lawful purpose. You are solely responsible for all content you upload and for ensuring your use complies with applicable laws.

Prohibited Uses

You must not use PlainTray to: store or share content that infringes intellectual property rights (copyrights, trademarks, patents); distribute malware, viruses, or harmful code; share content that depicts, promotes, or facilitates child sexual abuse material (CSAM) or any exploitation of minors; store or distribute content promoting terrorism or violent extremism; share personal data of others without consent (doxxing); facilitate harassment, stalking, or threats of violence; send unsolicited bulk messages or spam; conduct phishing or fraud; violate export control or sanctions laws; or engage in any other illegal activity. PlainTray uses zero-knowledge encryption and cannot inspect your content — you remain legally responsible for what you store and share. We act on credible abuse reports and legal notices reactively, not through proactive content scanning. We may delete trays without notice if we receive a valid abuse report or legal request.

Your Content

You own everything you put into PlainTray. We do not claim any rights over your content. Because of our zero-knowledge architecture, we cannot access, review, or moderate your content — it is encrypted end-to-end and only readable with your tray code.

Zero-Knowledge Architecture

Your tray code is hashed client-side to derive both a tray ID (for database lookup) and an AES-GCM encryption key. The encryption key never leaves your browser. We cannot recover your data if you lose your code, and we cannot read your content under any circumstances.

Storage & Retention

Each tray can store up to 5 GB of data. Trays expire 7 days after creation and are then permanently deleted — including all associated files. There is no way to recover a deleted tray.

Service Availability

PlainTray is provided "as is" without any guarantees of uptime or availability. We may modify, suspend, or discontinue the service at any time without prior notice.

Abuse & Takedown

We reserve the right to delete any tray at any time if we receive a valid abuse report or a legal request, even though we cannot view its contents. Upon receiving a valid notice, we will act within 24 to 48 hours. For content falling under the EU Terrorism Content Online Regulation (TCO), we will comply with removal orders within 1 hour as required by law. To report abuse, visit our report page.

Third-Party Complaints

If we receive a complaint from a third party regarding content you uploaded, we will forward the complaint to you via any contact information associated with your tray (if available). We may provide the complainant with metadata necessary to pursue legal remedies. We reserve the right to recover reasonable costs incurred in responding to complaints caused by your violation of these Terms.

Copyright Infringement (DMCA)

If you believe content on PlainTray infringes your copyright, please send a notice to dmca@plaintray.com containing: (1) your contact information; (2) identification of the copyrighted work; (3) the tray URL containing the allegedly infringing content; (4) a statement that you have a good faith belief the use is not authorized; (5) a statement under penalty of perjury that your notice is accurate and you are the copyright owner or authorized to act on their behalf; and (6) your physical or electronic signature. Upon receiving a valid DMCA notice, we will remove or disable access to the allegedly infringing content. Repeat infringers will have their access to the service terminated.

Liability

PlainTray is provided without warranties of any kind, whether express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, or non-infringement. To the fullest extent permitted by law, our total liability for any claims arising from your use of the service is limited to CHF 100. This limitation does not apply to liability for fraud, gross negligence, willful misconduct, personal injury, or violations of applicable data protection laws, which cannot be limited under Swiss law (OR Art. 100).

Indemnification

You agree to indemnify, defend, and hold harmless PlainTray, its operator, and affiliates from any claims, damages, losses, or expenses (including reasonable legal fees) arising from: (a) your use of the service; (b) content you upload or share; (c) your violation of these Terms; or (d) your violation of any third-party rights, including intellectual property rights.

Changes to These Terms

We may update these terms from time to time. For material changes affecting your rights or how we process your data, we will provide at least 30 days' notice by posting the updated terms with a new effective date. The effective date at the top of this page will reflect the latest revision. Continued use of PlainTray after changes take effect constitutes acceptance of the revised terms.

Severability

If any provision of these Terms is found to be unenforceable or invalid, that provision will be limited or eliminated to the minimum extent necessary, and the remaining provisions will remain in full force and effect.

Force Majeure

We are not liable for any failure or delay in performing our obligations where such failure or delay results from events beyond our reasonable control, including but not limited to natural disasters, war, terrorism, riots, embargoes, acts of civil or military authorities, fire, floods, accidents, strikes, or shortages of transportation, facilities, fuel, energy, labor, or materials.

Applicable Law

These terms are governed by Swiss law (Swiss Code of Obligations). Any disputes shall be subject to the exclusive jurisdiction of the courts of St. Gallen, Switzerland.

Privacy Policy

Legal Basis for Processing

We process your data based on legitimate interest (GDPR Art. 6(1)(f) / Swiss nDSG Art. 31(1)). Our legitimate interests include: operating and maintaining the service, preventing abuse and fraud, ensuring security, and complying with legal obligations. We have balanced these interests against your rights and freedoms and concluded that our processing is proportionate and does not override your interests. We maintain a documented Legitimate Interest Assessment (LIA) demonstrating this balancing test. You may request a copy by contacting legal@plaintray.com.

What We Collect

We store only what is necessary to operate the service: encrypted text blobs, encrypted file blobs, and minimal metadata (tray ID, file sizes, and timestamps). If you create an account, we also store your email address and optional display name (see Account Data below). We collect and retain IP addresses for abuse prevention and legal compliance. IP addresses are stored for the lifetime of the tray (7 days for free trays, up to 180 days for future Pro trays) and may be retained in backups for up to 30 days after tray deletion. All content is encrypted on your device before it reaches our servers — we cannot see what you store or share.

What We Don't Collect

We do not collect identifying information beyond IP addresses. We do not track your browsing behavior, usage patterns, or build user profiles. We do not use third-party analytics services. There are no ads.

Cookies

PlainTray uses three strictly functional cookies: PARAGLIDE_LOCALE to remember your language preference, pt-verified to confirm you have passed our bot protection (CAPTCHA), and pt-session to maintain your authentication session if you are logged in (HttpOnly, 30-day expiry). No tracking cookies, no third-party cookies, no fingerprinting.

Account Data

If you create a PlainTray account, we store your email address and optional display name in cleartext to provide the service. Your tray content remains zero-knowledge encrypted — we cannot read your text or files. Account passwords are hashed with PBKDF2-SHA256 and never stored in plaintext. You can delete your account at any time from the Account Settings page.

Infrastructure & Subprocessors

PlainTray runs on Cloudflare's infrastructure (Workers, D1 database, R2 storage). Cloudflare processes technical metadata (such as IP addresses) as part of providing the underlying platform. Because all your content is encrypted on your device before it reaches our servers, Cloudflare only ever sees unreadable ciphertext — they cannot decrypt your trays. Cloudflare operates globally and may process data outside Switzerland; they maintain Standard Contractual Clauses for international data transfers.

We use Resend (resend.com), a US-based email service provider, to send transactional emails (account verification, password resets, account deletion confirmations). Resend receives only the recipient email address and email content necessary to deliver these messages — they never receive or process your tray content. Resend maintains Standard Contractual Clauses for international data transfers.

Data Sharing

We do not sell your data or share it with third parties for marketing purposes. We share email addresses with Resend, our transactional email provider, solely to deliver account-related emails (verification, password resets, deletion confirmations). Beyond this necessary subprocessor relationship, the only exception is when we are legally compelled to disclose data by a valid Swiss court order or law enforcement request. In such cases, we can provide metadata (including IP addresses) and encrypted content — however, the encrypted content remains unreadable without your tray code, which we do not possess.

Transparency

We are committed to transparency about government and legal requests. We will publish an annual transparency report summarizing the number of legal requests received, the types of requests, and our responses (to the extent permitted by law).

Your Rights

Under GDPR and Swiss nDSG, you have the right to: access your personal data (though we can only provide metadata since content is encrypted); rectification of inaccurate data; erasure (trays are automatically deleted after 7 days, or you can delete them immediately); data portability (download your encrypted content via the tray interface); object to processing based on legitimate interest; and lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or your local supervisory authority. To exercise these rights or ask questions about your data, contact us at legal@plaintray.com.

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Swiss FDPIC within 72 hours and inform affected users without undue delay, as required by Swiss nDSG and GDPR. Due to our zero-knowledge architecture, breached content would remain encrypted and unreadable without your tray code.

Security

We implement appropriate technical and organizational measures to protect your data, including encryption at rest and in transit, access controls, and regular security assessments. If you discover a security vulnerability, please report it responsibly to security@plaintray.com. We appreciate your help in keeping PlainTray secure.

Operator

Folleon GmbH

CHE-341.490.689

Flurhofstrasse 10

9000 St. Gallen, Switzerland