Trust and safety
Privacy and security when processing media
MediaDrop is designed for short-lived work: accept an authorised URL, process it inside controlled boundaries, and return a temporary file to the correct session.
From URL to download
- Input validation: the URL must use HTTPS, belong to an approved source, and not target a private network or blocked destination.
- Quarantine: source data is not trusted merely because it has a media extension.
- Malware scanning: the file is scanned before it can move into verified storage.
- Controlled delivery: the result is delivered through a session-authorised download flow, not a public object-storage bucket.
- Expiry: processed copies and links are temporary; operational policy removes transient data.
What MediaDrop does not do
- It does not ask for video-platform passwords or sign in on a user's behalf.
- It does not bypass DRM, paywalls, access controls, or another service's protections.
- It does not expose object storage publicly.
- It is not a permanent media library and cannot promise recovery after expiry.
Data on your device
The interface may keep limited recent-job information locally in your browser. Clearing site data or using private browsing affects that history. Browser history should never be treated as file storage.
What should you protect?
- Do not submit URLs containing secrets or credentials in their query strings.
- Avoid public computers for sensitive media.
- After downloading, move the file into your own access-controlled, backed-up system.
- Report a suspicious URL or behaviour through the reporting channel.
Privacy is not permission
Secure transport does not grant the sender permission to copy a work. Technical protection and content rights are separate layers; you remain responsible for selecting an accurate rights basis and following applicable law.