Files, shared securely

Privacy

Last updated 9 October 2026.

The short version

Zeti Share lets Zeti staff share files with people outside Zeti, each behind its own link and password. We keep what that needs. Until you answer the cookie bar we count how the site is used, without cookies and without your name, to improve it. We only use analytics cookies or record how pages are used if you say yes. If you say no, all analytics in your browser stops, and everything works either way. People who open a shared file are never asked for or identified by their name or email, and we don't sell data or use advertising identifiers.

Who's responsible

The data controller is Zeti Limited, registered in England and Wales. Privacy questions go to support@zeti.group.

If you work at Zeti and have an account

We store your work email address, your name (people you share a file with see it), a securely hashed password (we couldn't read it if we wanted to), your signed-in sessions and when you last signed in. We keep a record of what you do with files: creating one, uploading a new version, changing its password, showing it, switching its link off or on, and deleting it, with the same daily-changing one-way reference to your network address that file opens carry (see below), so that what happened to a shared file can always be explained.

The emails we send you are the ones you'd expect: a link to set your password, password resets you ask for, a note when your password changes, a note when one of your links is first opened or when someone seems to be guessing its password, and now and then a link to confirm it's still you.

What we store for each file

The HTML file you upload and any earlier versions you replaced, its title, and its password. The password is kept twice: once hashed, to check what a reader types, and once encrypted, so that you can see and copy it again later. Zeti Share's admins can't see it unless the file is first moved to them, and that move is recorded.

If you open a shared file

You don't need an account and we never ask who you are. For each link we count how many times it was opened and when, and how many wrong passwords were typed and when. With each of those we keep a one-way reference made from your network address that changes every day (it can't be turned back into the address), and which family of browser you used. None of this identifies you.

The person who shared the file sees the number of opens, when it was last opened and the number of wrong passwords. They don't see who opened it.

Cookies and similar storage

A few are strictly necessary for Zeti Share to work and are always set when you use the part they belong to. The rest are only used if you choose Accept on the cookie bar. Until you answer, only the cookie-free counts described below run, and they use no cookies or other storage. If you choose Reject, nothing that measures how you use the site runs in your browser.

Strictly necessary
NameWhat it is forHow long
__Host-ZetiSessionKeeps a member of staff signed in. Set only when you sign in.14 days, or 24 hours unused
__Secure-ZetiShareReaderRemembers that this browser entered a file's password, so you are not asked again each time. Sent only to that link.7 days
zeti-share-consent (local storage)Remembers your answer to the cookie question, so we don't ask on every page.Until you clear it or change your answer
Only if you accept
NameWhat it is forHow long
ph_… (cookie and local storage)PostHog: tells one visit from the next so we can see how Zeti Share is used. Set on this website only, not on other zeti.group sites.Up to 1 year
__hstc, hubspotutk, __hssc, __hssrcHubSpot: page views on the home, legal and staff pages. HubSpot sets these on the whole zeti.group domain and shares them with the zeti.group website. Never on a shared file's page.Up to 6 months (__hssc: 30 minutes; __hssrc: the browser session)

The zeti.group website runs HubSpot too. If you visited it before, it may already have set HubSpot cookies on the zeti.group domain; those are the website's, are governed by its privacy and cookie policy, and are outside Zeti Share's control.

Without your consent we still count file opens and wrong passwords on our own servers, as described above, and our servers send anonymous counts to PostHog (for example, that a link was opened or a file published). These use no cookies and are never linked to a person.

Counts before you answer

Until you answer the cookie bar, PostHog counts which pages are visited and what is done in Zeti Share (for example, that a file was published or a link was opened), so we can improve the service. This uses no cookies and stores nothing in your browser, so a new visit can't be linked to an earlier one. Nothing is recorded and your name and email are never attached. Like any website you visit, PostHog receives your internet (IP) address with each count; we keep it, and the approximate location PostHog works out from it, to understand where and by which organisations Zeti Share is used and to spot misuse. What happens inside a shared file is never counted this way.

You can object at any time: choose Reject on the cookie bar, or in . Reject stops these counts too, and from then on nothing that measures how you use the site runs in your browser.

Session recordings

If you accept, PostHog records how pages are used: where you click and scroll and what the page showed. On a shared file this includes the file itself, so a recording contains the file's own text and figures as they were displayed. Passwords you type are never recorded, and every text field is masked. If you open a file and accept afterwards, that file is recorded from the next time you open it.

When staff who accepted are signed in, their recordings and events are linked to their account and work email address, so we can follow up on a problem they hit. Readers are never identified: their events carry only which link and file they belong to.

Who helps us run it

Each does one job: Microsoft Azure hosts Zeti Share and stores everything above in the UK (UK South) and the Netherlands (West Europe); PostHog (EU servers) gives us product analytics (cookie-free counts until you answer the cookie bar) and, only with consent, session recordings; HubSpot (EU servers) counts page views on our home, legal and staff pages, only with consent; SendGrid delivers our emails to staff. We don't sell or share your data with anyone else, and nothing here is used for advertising. We don't collect where a visit came from (search engines, campaigns or adverts).

How long we keep things

These are the longest each can last:

  • File opens and wrong passwords: 13 months.
  • The record of what was done with files and accounts: 24 months.
  • A deleted file and its versions: 30 days, plus up to 30 more in our storage provider's deletion safety net.
  • A replaced version's file: 30 days after it was replaced, plus up to 30 more in the same safety net.
  • Backup copies of account and file records, including the encrypted and hashed file passwords: 90 days.
  • Accounts stay while they are in use. If you want your account and its data gone, email us and we'll delete it.
  • Analytics and recordings: as set in PostHog and HubSpot.

Your rights

UK GDPR gives you the right to see the data we hold about you, correct it, take it away, or have it erased. Ask at the address above. You can withdraw your consent to analytics at any time from (also at the foot of every page, on your account page and in a shared file's menu). Choosing Reject switches all analytics in your browser off, including the counts made before you answer, and removes its cookies. If we've let you down, you can complain to the Information Commissioner's Office (ico.org.uk), though we'd appreciate the chance to fix it first.

Zeti's wider privacy and cookie policy is at zeti.group/privacy-and-cookies.

The rules for using Zeti Share live in the terms.