Privacy notice

MyShare’s official website is sharemydemo.com. The service is provided by BUHUIPAO LTD. This notice covers the MyShare website, browser extensions and previews opened through the service.

Updated: 2026-09-14

Shared content and authentication

Your selected local addresses, files and visitor requests pass through MyShare’s Cloudflare gateway. Public connections use HTTPS/WSS; local services use the HTTP/HTTPS configuration you provide. The gateway processes requests and responses, so this is not end-to-end encryption that hides content from the service.

Local page and file bodies are used for relaying, not stored as long-term hosted copies. Requests may be temporarily buffered during transfer. Only files you select are read; copies held by the sharing page or extension remain in local memory.

Bearer, Basic and Cookie sign-in relay each visitor’s own credentials. The extension or project adapter isolates visitor cookies without reading or reusing the owner’s native sign-in. Application logs do not record request bodies, Cookie or Authorization values, passcodes or share-control credentials. Optional feedback records are described below.

Accounts, billing and domains

Registration processes your email and password; passwords are stored as hashes. We record your email verification status and use Resend to send 8-digit email verification and password reset codes. MyShare provides Resend with the recipient address, sender details and message content including the code to deliver these account emails. We do not send your password or shared content to Resend. MyShare stores a keyed hash of each code; codes expire after 10 minutes and become invalid after use. Account details, subscription state, Stripe customer/subscription identifiers and reserved domain records support sign-in, billing, entitlements and domain management.

Payment details are handled on Stripe’s checkout and billing pages. MyShare does not receive or store full payment-card numbers. Stripe, Cloudflare and Resend also process data required to operate their services under their own terms: Stripe privacy policy, Cloudflare privacy policy and Resend privacy policy.

If you choose an enabled Google, GitHub, X or Facebook sign-in option, we obtain your account identifier, available email and its verification status from that provider. We keep the provider and account identifier association to sign you in to MyShare. X sign-in reads only the identifier and available email of the account you authorize; it does not read timelines or direct messages, or publish posts. We do not request GitHub repository access or retain provider access tokens. Each sign-in method uses a separate account, even with the same email. SSO needs no email verification. Account linking and unlinking are unavailable; email password recovery only applies to email and password accounts.

Essential cookies and local storage

The website uses cookies for anonymous share ownership and account sign-in, plus essential cookies lasting up to 10 minutes to bind provider sign-in checks. Preview access uses a dedicated passcode header or URL parameter; the browser retains its Service Worker registration. Feedback preferences are stored separately. Your project sets its own sign-in cookies, which are mapped to the corresponding preview origin. Language preference is kept in local storage; share recovery state stays in the relevant tab or the extension’s private session storage.

These support authentication, limits, access control and recovery. Clearing browser data may sign you out, remove control of an existing share or require another unlock. Project cookies and storage at saved addresses may carry over to later shares, so use different names for different projects.

Google Analytics on this website

This website uses Google Analytics 4 cookies to measure visits to public pages, visit timing and basic device information. Visitors in the European Economic Area, the UK, Switzerland or an unrecognized region must choose “Allow analytics” first; analytics is enabled by default elsewhere. Cloudflare determines the region from the request’s network location. A previous refusal is honored in every region.

Use “Analytics settings” in the footer to turn analytics off at any time. This stops further collection and clears this integration’s analytics cookies without affecting sharing, sign-in or subscriptions, or interrupting an active share. It does not automatically delete data already sent.

Page addresses we send exclude query strings and fragments. We do not provide referring page addresses, account identifiers, email addresses, share passcodes, local addresses, file contents or form inputs. Automatic form, outbound-link and site-search collection, Google Signals and ad personalization are disabled. This integration runs only on our website, not in shared previews, the replay player or extensions.

Analytics cookies belong only to the website host and last up to 180 days. Your acceptance or refusal is saved locally for 180 days. Google also receives device and network information when handling analytics requests; see the Google privacy policy. Website analytics and the preview feedback choices below are independent.

Visitor choices: analytics, comments and replay

Visitor features are off by default for the owner. When enabled, visitors choose whether to allow page paths, click counts, time spent and named custom events to be recorded. Studio replay needs a separate choice. Declining does not prevent browsing or commenting.

Replays record masked page structure and interactions, not screen video. Text and form inputs are masked by default; private areas, passwords and embedded pages are blocked. Network bodies, authentication credentials, console output and keystrokes are not recorded. URL query strings and fragments are removed, but paths and structure can still reveal project information. Share only content you are entitled to disclose.

Replay is limited to 5 minutes and 5 MiB per visitor. Withdrawing consent stops collection on the current page immediately. Once the server saves that choice, the visitor’s saved replays are deleted. Retry after an offline failure to complete server deletion; existing aggregate analytics may remain.

Visitors submit comments voluntarily. Comments are visible to the owner and other visitors. Do not include passwords or sensitive personal information. The owner can delete comments.

Retention

Contact and privacy requests

To ask about, access, correct or delete account-related data, contact support@sharemydemo.com with your account email and request. Do not send passwords, email codes, full card numbers or share-control credentials. Data deletion and subscription cancellation are separate actions; use account billing management to stop future renewal charges.