MediaDrop

Trust and safety

Privacy and security when processing media

MediaDrop is designed for short-lived work: accept an authorised URL, process it inside controlled boundaries, and return a temporary file to the correct session.

From URL to download

  1. Input validation: the URL must use HTTPS, belong to an approved source, and not target a private network or blocked destination.
  2. Quarantine: source data is not trusted merely because it has a media extension.
  3. Malware scanning: the file is scanned before it can move into verified storage.
  4. Controlled delivery: the result is delivered through a session-authorised download flow, not a public object-storage bucket.
  5. Expiry: processed copies and links are temporary; operational policy removes transient data.

What MediaDrop does not do

  • It does not ask for video-platform passwords or sign in on a user's behalf.
  • It does not bypass DRM, paywalls, access controls, or another service's protections.
  • It does not expose object storage publicly.
  • It is not a permanent media library and cannot promise recovery after expiry.

Data on your device

The interface may keep limited recent-job information locally in your browser. Clearing site data or using private browsing affects that history. Browser history should never be treated as file storage.

What should you protect?

  • Do not submit URLs containing secrets or credentials in their query strings.
  • Avoid public computers for sensitive media.
  • After downloading, move the file into your own access-controlled, backed-up system.
  • Report a suspicious URL or behaviour through the reporting channel.

Privacy is not permission

Secure transport does not grant the sender permission to copy a work. Technical protection and content rights are separate layers; you remain responsible for selecting an accurate rights basis and following applicable law.

Related guides

Use MediaDrop