Privacy Policy
Last updated: October 7, 2026
Valise ("the App") is an application for Mac and iPhone developed by Magenta Creations ("we", "us", "our"). It sets up a file-transfer service — an R2 bucket and a Worker — in your own Cloudflare account, and sends files through it. This policy explains what the App, the Worker it installs, and this website do with your information.
The App Sends Nothing to Us
Valise collects nothing and reaches no server of ours. It talks to two places
only: Cloudflare's API (api.cloudflare.com), to set up and check your bucket and
Worker, list your transfers and read your account's storage use; and your own Worker, to upload,
complete and delete transfers. Signing in with Cloudflare opens Cloudflare's own sign-in page.
There is no analytics, no telemetry and no advertising in the App.
Credentials and Setup Details
Signing in with Cloudflare gives the App an access grant for the permissions you approved; you type your Cloudflare password on Cloudflare's page, never into the App. That grant, or an API token you paste instead, is kept in the Keychain, your device's encrypted credential store, together with the upload secret the App generates for your Worker and the details of your setup (the account, bucket and Worker it uses). On iPhone, the App's share extension reads them through the App's own keychain group. They are:
- Never sent to us
- Sent only to Cloudflare (your credentials) and to your own Worker (the upload secret)
- Kept on the device that stored them, and not synced through iCloud Keychain
Your Files
Files you send go from your device to your own Worker, which stores them in the R2 bucket in your Cloudflare account. We never receive, see or store them, and we have no access to your account. Cloudflare stores and serves them as your provider, under your agreement with Cloudflare.
On iPhone, files shared to Valise are briefly copied, in parts, into storage that the App and its share extension share on your device, so the upload can continue in the background after the share sheet closes.
Files are not end-to-end encrypted: anyone holding a transfer's link can download it until it expires or you delete it, unless the transfer has a password. Each link carries 128 random bits, so it cannot be guessed. Every transfer expires after the 1, 7 or 30 days you chose; your Worker then refuses it, and lifecycle rules in your bucket delete its files.
Your Recipients
The download page your recipients open is served by your own Worker, not by us. It loads no scripts and no third-party resources, and sets no cookie — with one exception. On a password-protected transfer, once the recipient enters the right password, the Worker sets a single cookie that proves it for that transfer only: it is limited to that transfer's address, unreadable by scripts, sent only over HTTPS, and expires with the transfer. The password itself is never stored, by the Worker or by the App; the Worker keeps only a salted hash.
Requests to your Worker are handled by Cloudflare under your account, which may log them according to your Cloudflare settings. We have no access to those requests.
This Website
This website is separate from the App, and it does keep visitor statistics. It
uses Cloudflare Web Analytics, which sets no cookie and stores nothing on your device — no identifier between page loads, no localStorage, and no fingerprinting of your
browser or IP address. Because nothing is written to or read from your device, this needs no
consent banner under the ePrivacy Directive (in France, Article 82 of the loi Informatique et
Libertés), and there is none.
Sent on each page view: the page address, the address you came from, your browser and operating system, your screen size, and page load timings. Cloudflare derives an approximate country from your IP address and does not pass the address itself to us. We see aggregate totals only — never a profile, never an individual, and never anything across other websites. Our lawful basis is legitimate interest in understanding how our own site is used; Cloudflare acts as our processor under its Data Processing Addendum. Any content blocker stops the script loading.
Feedback Form
The feedback form on this website is the one place we collect anything, and only when you choose to fill it in and press send. The App never sends feedback itself: it opens a web address in your browser and stops.
We receive what you typed — the subject and the details — and your email address if you chose to give one. The address is optional; leave it blank and the report is anonymous.
Opening the form from inside the App also fills in four technical facts: your Valise version, your operating system version, your device's model identifier, and your language. They arrive in the web address itself, so you can read them in your browser's address bar before anything is sent, and the form shows them as ordinary editable fields you can change or clear. Nothing is hidden. That is the entire list — never your username, your device's name, your Cloudflare account, bucket or file names, a share link, or any identifier that would let two reports be recognised as coming from the same device.
Submissions are stored in a Cloudflare D1 database hosted in Western Europe and emailed to support@mgcrea.io so we can reply. We keep them for twelve months, then delete them. They are never used for marketing, never sold, and never shared. The form sets no cookie, and nothing in the code that handles your submission ever reads or stores your IP address. To have a submission deleted sooner, email support@mgcrea.io.
Purchases
Some features, such as password protection, are part of Valise Pro. When it is available, it is bought through the App Store and handled entirely by Apple; we receive no payment details.
Apple Crash Reporting
If you have opted into sharing analytics with app developers in your device's settings, Apple may provide us with anonymized crash reports. This is controlled entirely by your settings and is not something we can enable or configure.
Third-Party Services
- Cloudflare — its API and sign-in page, to set up and manage Valise in your account; and R2 and Workers, which store and serve your transfers under your own account. See Cloudflare's Privacy Policy.
- Apple App Store — for in-app purchases and restoring them, managed by Apple
Children's Privacy
Valise is not directed at children under the age of 13. We do not knowingly collect any information from children.
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be reflected on this page with an updated "Last updated" date.
Contact Us
If you have questions about this Privacy Policy, please contact us at support@mgcrea.io.