Unomed

CLEARLY EXPLAINED

Your files. Your control.

Unomed Transfer provides temporary file sharing. These notes explain the service and the limits of deletion.

Who operates the service

Unomed AG provides this service. Contact and address details are in the legal notice; general information about your rights is in the Unomed privacy policy. Please contact Unomed using the links below with any questions about transfers.

What data is processed

Your browser encrypts file contents using AES-256-GCM before upload. Filenames, file sizes and file types are also sent to the server as readable metadata. The server stores encrypted contents, a random transfer ID, document metadata, chunk sizes, expiry time, completion status and a hash of the management credential. No email address or account is required. Filenames may contain personal information.

The decryption key is in the sharing link fragment, after the # symbol. This part is not sent to the server in HTTP requests. The transfer application uses no analytics, advertising or third-party scripts and sets no cookies. Connection data is technically necessary for network transmission. For abuse protection, salted IP address hashes and counters are held only in memory, for at most one hour plus a cleanup interval.

Permanent usage log

For operational traceability and usage analysis, Unomed maintains a separate CSV log on the transfer server. It contains timestamps, IP addresses, browser identifiers (User-Agent), a pseudonymous transfer reference, filenames, file sizes, file types, expiry times and events such as upload, access, chunk download and deletion. Authorised operators can read IP addresses and filenames. An IP address does not reliably identify a person.

This log has no automatic deletion period and is retained permanently. The seven-day limit and private deletion link apply to transferred files and their active availability, not to the separate log. Encrypted file contents, decryption keys, management credentials and complete sharing links are not stored in the CSV. Contact Unomed using the links below for access or deletion requests.

Sharing links and deletion links

Anyone with the complete sharing link can download the files. The service does not verify recipients’ identities. The private deletion link also permits immediate deletion of the hosted files; the separate usage log remains. Do not send that link to recipients. Links may be saved in browser history, clipboards, emails or messages. Unomed cannot remove these copies or recover lost links.

Seven days and automatic deletion

The seven-day period starts when the upload completes successfully. From the expiry time, the server rejects further access. During normal operation, a background process removes encrypted files and active transfer data at its next run, every minute. Incomplete uploads expire after one hour and are discarded on restart. Expired transfers are cleaned up before the server starts. During an outage, physical cleanup may be delayed until operation resumes.

The application does not create file backups. The separate CSV usage log described above is retained permanently. Access logging and tracing for this service are disabled on the configured reverse proxy. Forensically traceless deletion from storage media, infrastructure snapshots or external logs is not guaranteed. Downloaded files remain with recipients. The application does not overwrite disk sectors.

Hosting environment and medical records

This free service runs on transfer infrastructure provided by Unomed. No guarantee is made of exclusively Swiss hosting, a particular certification or a specific level of availability. It is not a patient archive and does not replace retention obligations or an approved clinical communication solution.

Before using the service for personal medical records, your organisation must check suitability, recipient authorisation and applicable data protection operating conditions. Contact Unomed for managed use with agreed contractual and hosting conditions. Use anonymised sample files for your own tests.

Terms of use

Each transfer supports up to 50 files and 250 MB in total. Only upload content you are authorised to transmit. Unlawful content, malware and automated abuse are prohibited. Recipients should only open files from trusted sources: because the server cannot decrypt content, it does not perform server-side content or malware scanning. The free service may limit new uploads when capacity is constrained. Keep your own copies of important originals.

Back to file transfer →