Privacy Policy
Last updated: July 9, 2026
1. Who we are
This privacy policy explains how epic downloader ("we", "us", "the service") processes information when you use this website. The service is operated by the site owner, who acts as the data controller for the processing described here. You can reach us at epicdownloader.com@hotmail.com.
The short version: this service needs almost no personal data to work, we do not create user accounts, we do not sell data, and the media you download passes through our server transiently and is deleted immediately after it is served to you.
2. What we process, and why
- Links you paste. The URL you submit is processed in memory to locate the requested media on the source platform. Links are not associated with your identity. To avoid repeating identical lookups, the technical result of a lookup (the list of available formats) may be kept in server memory for a few minutes; it is never written to disk and expires automatically. Links may also transiently appear in technical logs (below).
- Downloaded files. Depending on the format, the file either travels straight from the source platform's network to your browser (see section 5), or is relayed through our server as a transient stream that is never written to disk, or — for format conversions — is fetched to temporary storage (on our server or, on larger deployments, a private object-storage bucket we control in the EU), converted, and deleted as soon as you download it (or automatically within about half an hour if you never do). In every case we keep no library or archive of downloaded media.
- Technical server logs. Like virtually every website, our infrastructure records basic request data: IP address, date and time, requested path, response status and user-agent string. We use this exclusively for security, abuse prevention and debugging (legal basis: our legitimate interest in operating a secure service, Art. 6(1)(f) GDPR). Logs are routinely rotated and are not used to build profiles.
- Rate-limiting data. To prevent abuse, the server keeps request counters per IP address in short-lived server-side storage (memory, or our own Redis instance) for approximately one minute. They expire automatically and are not used for anything else.
- Your cookie choice. Your consent decision from the cookie banner is stored in your own browser's local storage. It is not transmitted to us.
- Ad-free subscription data. If you take the optional paid ad-free subscription, payment is processed entirely by Stripe (Stripe Payments Europe, Ltd.) — we never see or store your card details. We receive from Stripe only a pseudonymous customer and subscription identifier, which is stored in a signed cookie in your browser so the service stays ad-free for you (legal basis: performance of a contract, Art. 6(1)(b) GDPR). The email address you use at checkout is held by Stripe and is used only to manage the subscription and to log you in: at your request we email a short-lived sign-in link (valid for about 30 minutes) that activates your ad-free access on the device you open it on. The address you type into the login form is processed transiently for that lookup and is not stored by us — only a hashed, automatically-expiring rate-limiting entry is kept briefly to prevent abuse of the email sender.
3. What we do not do
- No user accounts, registration or profiles.
- No sale, rental or sharing of personal data with third parties for their own purposes.
- The service funds itself with a small number of advertisements. Under a "consent or pay" model you can either accept advertising (advertising partners may then set cookies and personalise ads) or take the paid ad-free subscription, in which case no advertising code loads at all and no advertising cookies are set. No advertising code runs before you make a choice in the banner.
- If you accept advertising, our advertising and measurement partners may — under their own privacy policies and for their own purposes — process data such as your IP address, device information and ad-interaction events, set cookies or similar identifiers, build statistics, and share such data with third parties for advertising and analytics (legal basis: your consent, Art. 6(1)(a) GDPR). We do not run our own data brokerage: this processing happens inside the partners' tags, which only load after you accept, and stops for new visits once you withdraw consent via "Cookie settings" in the footer.
4. Cookies and local storage
We show a consent banner before any non-essential cookies are set.
The banner offers a genuine choice ("consent or pay", as contemplated by
the Spanish supervisory authority's cookie guidance): accept advertising,
or use the service without any advertising for a small subscription fee.
Until you choose, the service uses only strictly necessary browser storage: a
local-storage entry that remembers your cookie choice, and a small cookie
(epic_lang) that remembers your language preference so we can show the site in
your language. Both stay on your device and are not used for advertising.
If you accept, third-party advertising partners may set cookies or similar
identifiers and process data (such as your IP address) to serve and measure ads, under their
own privacy policies. If you subscribe, no advertising code loads and no
advertising cookies are set; the service places one strictly necessary, signed cookie
(epic_pro) whose only purpose is to remember that your browser has an active
subscription. It contains a pseudonymous subscription reference (a Stripe customer and
subscription identifier) — no browsing history and no advertising identifiers — and it is
never shared with advertisers or used to follow you across sites. You can change or withdraw
your choice at any time via the “Cookie settings” link in the footer — this
reopens the banner, and no advertising or analytics loads until you choose again (subscribers
can restore their ad-free access afterwards).
Ad-blocker detection. If you accepted advertising, the page checks locally in your browser whether an ad blocker is hiding the ads (using a hidden test element). This check runs entirely on your device and transmits nothing to us or to anyone else.
5. Requests to source platforms
When you resolve a link, our server — not your browser — contacts the source platform (for example YouTube, TikTok, Instagram, Facebook or X) to fetch the publicly available media data; for that lookup your IP address is not forwarded to the platform by us. For the download itself, whenever the platform's content delivery network allows it your browser retrieves the file directly from that network — exactly as it does when you view the post on the platform itself — in which case the platform will see your IP address and browser characteristics, and its own privacy policy applies. The same is true for media previews (such as thumbnails). Where direct retrieval is not possible (for example format conversions), the file is relayed through our server instead.
6. Hosting and international transfers
The service is hosted on servers operated by Hetzner Online GmbH in the European Union. We do not transfer the data described in this policy outside the European Economic Area, with one exception: if you take the ad-free subscription, Stripe processes payments as described in its own privacy policy and may transfer data to the United States under the EU-U.S. Data Privacy Framework and standard contractual clauses.
7. Data retention
- Pasted links: processed in memory; lookup results cached server-side for a few minutes, then discarded.
- Downloaded/converted files: never stored — streamed transiently, or (conversions) deleted on download, at the latest about half an hour after completion.
- Rate-limiting entries: about one minute, in short-lived server-side storage.
- Technical logs: retained briefly for security purposes and then rotated; not more than 30 days in the ordinary course.
- Subscription identifiers: in a cookie in your own browser for up to one year (renewed while the subscription is active); billing records are kept by Stripe and by us as long as tax and accounting law requires.
8. Your rights
Under the GDPR (in Spain, together with the LOPDGDD) you have the right to request access to, rectification or erasure of your personal data, restriction of or objection to processing, and data portability, where those rights apply to the limited processing we perform. You also have the right to lodge a complaint with a supervisory authority — in Spain, the Agencia Española de Protección de Datos (aepd.es) — or the authority of your place of residence.
To exercise any of these rights, email epicdownloader.com@hotmail.com. Because we hold essentially no identifiable data about visitors, we may need to ask you for enough context (for example your IP address and the approximate time of your visit) to locate anything at all.
9. Children
The service is not directed at children. If you are under 14 (or the equivalent minimum age in your country), please do not use the service without the involvement of a parent or guardian.
10. Security
All traffic to the service is encrypted in transit (HTTPS). We minimize the data we handle by design: no accounts, transient processing, and immediate deletion of media files after delivery.
11. Changes to this policy
We may update this policy as the service evolves (for example if analytics or advertising are introduced). The "Last updated" date at the top reflects the current version, and material changes will be announced on this page.
12. Contact
Questions about privacy or this policy: epicdownloader.com@hotmail.com.