Contact
We read everything. Pick the channel that matches your topic so it reaches the right process.
| Topic | Channel |
|---|---|
| Support & general questions | [email protected] |
| Security vulnerabilities | [email protected] — see the disclosure policy |
| Abuse or copyright | [email protected] — see abuse reporting |
| Privacy requests | [email protected] |
What to include in a support request
Because ShareDrop.org keeps no accounts and no transfer history, we cannot look your session up — everything we know about your problem is what you tell us. The fastest route to a fix is including, in any language you prefer (English or Chinese get the quickest answers):
- Browser names and versions on both devices (e.g. “Safari 26 on iPhone, Chrome 140 on Windows 11”);
- Network types on both sides — home Wi-Fi, office network, mobile data, VPN on or off;
- The exact message shown by the app, and the connection badge state (LAN direct / internet direct / encrypted relay / negotiating) if you got that far;
- Approximate file size, if the problem is transfer-related.
Our troubleshooting page explains what each message means and covers the most common fixes — many reports resolve in the two minutes it takes to read it.
Security disclosure policy
We welcome good-faith security research. If you find a vulnerability in ShareDrop.org — the transfer application, signaling service, relay configuration or this website — report it to [email protected].
- Include reproduction steps and impact; encrypted mail is welcome.
- Do not access other users' data, disrupt the service, or run automated attacks against production infrastructure at scale.
- Give us reasonable time to fix before public disclosure; we aim to acknowledge within 72 hours and keep you informed of progress.
In scope (highlights): bypasses of room access control (secrets, short codes, tokens, replay); safety-code weaknesses or MITM opportunities; integrity bypasses (accepting corrupted data as verified); relay abuse (open relay, internal-network access via TURN); injection via attacker-controlled fields (file names, paths, protocol frames). We do not currently run a paid bounty program; we do credit reporters (with permission) in release notes.
Response expectations
Security reports are acknowledged within 72 hours (see the disclosure policy for scope and guidelines). Support and abuse reports are typically answered within a few business days. We do not operate phone support, and we will never contact you first asking for files, codes or credentials — the product has no credentials to ask for.