Privacy notice
MyShare’s official website is sharemydemo.com. The service is provided by BUHUIPAO LTD. This notice covers the MyShare website, browser extensions and previews opened through the service.
Updated: 2026-09-14
Shared content and authentication
Your selected local addresses, files and visitor requests pass through MyShare’s Cloudflare gateway. Public connections use HTTPS/WSS; local services use the HTTP/HTTPS configuration you provide. The gateway processes requests and responses, so this is not end-to-end encryption that hides content from the service.
Local page and file bodies are used for relaying, not stored as long-term hosted copies. Requests may be temporarily buffered during transfer. Only files you select are read; copies held by the sharing page or extension remain in local memory.
Bearer, Basic and Cookie sign-in relay each visitor’s own credentials. The extension or project adapter isolates visitor cookies without reading or reusing the owner’s native sign-in. Application logs do not record request bodies, Cookie or Authorization values, passcodes or share-control credentials. Optional feedback records are described below.
Accounts, billing and domains
Registration processes your email and password; passwords are stored as hashes. We record your email verification status and use Resend to send 8-digit email verification and password reset codes. MyShare provides Resend with the recipient address, sender details and message content including the code to deliver these account emails. We do not send your password or shared content to Resend. MyShare stores a keyed hash of each code; codes expire after 10 minutes and become invalid after use. Account details, subscription state, Stripe customer/subscription identifiers and reserved domain records support sign-in, billing, entitlements and domain management.
Payment details are handled on Stripe’s checkout and billing pages. MyShare does not receive or store full payment-card numbers. Stripe, Cloudflare and Resend also process data required to operate their services under their own terms: Stripe privacy policy, Cloudflare privacy policy and Resend privacy policy.
If you choose an enabled Google, GitHub, X or Facebook sign-in option, we obtain your account identifier, available email and its verification status from that provider. We keep the provider and account identifier association to sign you in to MyShare. X sign-in reads only the identifier and available email of the account you authorize; it does not read timelines or direct messages, or publish posts. We do not request GitHub repository access or retain provider access tokens. Each sign-in method uses a separate account, even with the same email. SSO needs no email verification. Account linking and unlinking are unavailable; email password recovery only applies to email and password accounts.
Essential cookies and local storage
The website uses cookies for anonymous share ownership and account sign-in, plus essential cookies lasting up to 10 minutes to bind provider sign-in checks. Preview access uses a dedicated passcode header or URL parameter; the browser retains its Service Worker registration. Feedback preferences are stored separately. Your project sets its own sign-in cookies, which are mapped to the corresponding preview origin. Language preference is kept in local storage; share recovery state stays in the relevant tab or the extension’s private session storage.
These support authentication, limits, access control and recovery. Clearing browser data may sign you out, remove control of an existing share or require another unlock. Project cookies and storage at saved addresses may carry over to later shares, so use different names for different projects.
Google Analytics on this website
This website uses Google Analytics 4 cookies to measure visits to public pages, visit timing and basic device information. Visitors in the European Economic Area, the UK, Switzerland or an unrecognized region must choose “Allow analytics” first; analytics is enabled by default elsewhere. Cloudflare determines the region from the request’s network location. A previous refusal is honored in every region.
Use “Analytics settings” in the footer to turn analytics off at any time. This stops further collection and clears this integration’s analytics cookies without affecting sharing, sign-in or subscriptions, or interrupting an active share. It does not automatically delete data already sent.
Page addresses we send exclude query strings and fragments. We do not provide referring page addresses, account identifiers, email addresses, share passcodes, local addresses, file contents or form inputs. Automatic form, outbound-link and site-search collection, Google Signals and ad personalization are disabled. This integration runs only on our website, not in shared previews, the replay player or extensions.
Analytics cookies belong only to the website host and last up to 180 days. Your acceptance or refusal is saved locally for 180 days. Google also receives device and network information when handling analytics requests; see the Google privacy policy. Website analytics and the preview feedback choices below are independent.
Visitor choices: analytics, comments and replay
Visitor features are off by default for the owner. When enabled, visitors choose whether to allow page paths, click counts, time spent and named custom events to be recorded. Studio replay needs a separate choice. Declining does not prevent browsing or commenting.
Replays record masked page structure and interactions, not screen video. Text and form inputs are masked by default; private areas, passwords and embedded pages are blocked. Network bodies, authentication credentials, console output and keystrokes are not recorded. URL query strings and fragments are removed, but paths and structure can still reveal project information. Share only content you are entitled to disclose.
Replay is limited to 5 minutes and 5 MiB per visitor. Withdrawing consent stops collection on the current page immediately. Once the server saves that choice, the visitor’s saved replays are deleted. Retry after an offline failure to complete server deletion; existing aggregate analytics may remain.
Visitors submit comments voluntarily. Comments are visible to the owner and other visitors. Do not include passwords or sensitive personal information. The owner can delete comments.
Retention
- Share access expires when stopped or timed out. Content bodies are relayed; selected files are released with their local context.
- Share details and feedback are cleaned up after the share ends: 30 days for Pro and 90 days for Studio. Free-share usage details are scheduled for cleanup 30 days after ending.
- Creation records, usage and connection outcomes use a 90-day cleanup window. Active shares are retained while running; record and summary windows may start at different times.
- Email codes expire after 10 minutes, with expired records scheduled for cleanup. Account sign-in sessions last 30 days. Account, billing and reserved-domain records have no single automatic expiry period.
- Anti-abuse limits use irreversible HMAC identifiers derived from IP addresses. Share rate-limit counters last at most one hour; authentication limits use short-lived counters. Cloudflare Turnstile processes signals needed for security checks.
Contact and privacy requests
To ask about, access, correct or delete account-related data, contact support@sharemydemo.com with your account email and request. Do not send passwords, email codes, full card numbers or share-control credentials. Data deletion and subscription cancellation are separate actions; use account billing management to stop future renewal charges.