How we handleyour data
Last updated: August 22, 2026
TL;DR — what this policy covers
This Privacy Policy explains what personal data Downer ("we", "us", or "the service") processes when you use downer.app or any sub-path under it. Downer is a free, browser-based video downloader. We do not require an account, we do not ask for your name, and we do not set tracking cookies on your browser. The short version: URLs you paste are processed in memory and discarded. Cookies you upload for private-content downloads are used once and discarded. We do not keep logs of what you download.
The longer sections below spell out exactly which third-party services we use to operate the site, what each of them receives, and the rights you can exercise under data-protection law (including GDPR and CCPA). If any of those rights matters to you, the relevant contact address is listed in the "Contact and requests" section at the bottom.
We never store your URLs
The video URL you submit is processed in memory and on a per-request basis. We do not log, persist, or share the specific URLs you paste. The download itself is streamed once and discarded.
Aggregate counters (number of requests, response codes) are kept to monitor service health — these never include your URL, the content owner, or any identifying payload.
Instagram cookies are one-shot
When you upload a cookies.txt for Instagram, it is sent to our backend as a base64-encoded header on a single request. The backend writes it to a temporary file (permissions 0600) used by yt-dlp andgallery-dl, then unlinks it as soon as the response is sent.
We never persist cookies to disk, never log their values, and never share them with third parties. If you clear your browser's localStorage, the cookies are gone from the client side too.
Analytics
We use Google Analytics 4 (GA4) and Google Tag Manager to measure traffic. GA4 records anonymized page views and download attempts (success/failure category) but never records the URL you submitted. You can opt out via your browser's "Do Not Track" signal or any standard content blocker.
Your controls
You can remove the saved Instagram cookies at any time onthe cookies setup page.
To request deletion of any data we may hold about you (typically none beyond what your browser already knows), email the address listed on our GitHub repository.
Placeholder notice
Third-party services we rely on
Operating Downer uses a small set of infrastructure providers, each of which receives only the minimum needed to deliver the service:
- Cloudflare Pages hosts the website and proxies every request. Cloudflare sees your IP address, the URL you requested, and standard request headers. Their privacy policy applies to anything they log.
- Fly.io runs the backend that resolves video URLs and streams media. Fly sees the same request metadata as Cloudflare plus any cookies you upload for a single request.
- Google Analytics 4 (GA4) measures aggregate page views and download success/failure rates. GA4 does not receive the URL you submitted, the platform, the file, or any identifier.
None of these providers receives your URL submissions, downloaded files, or cookie payloads at rest. Each operates under its own privacy policy and data-processing terms.
Children's privacy
Downer is a general-audience utility and is not directed at children under 13 (or under 16 in jurisdictions that raise that threshold, such as parts of the EEA). We do not knowingly collect personal data from children. Because the service does not require accounts, does not ask for an email, and does not log download history, there is no realistic surface for child data to land on. If you believe a child has uploaded content you would like removed, contact us at the address listed in the GitHub repository and we will assist.
Your rights under GDPR / CCPA
Depending on where you live, you may have the right to: (a) request access to personal data we hold about you; (b) request correction or deletion of that data; (c) object to processing or restrict how we use it; (d) request a portable copy of the data; (e) lodge a complaint with a supervisory authority.
Because we do not store URL submissions or downloaded files, the answer to most of these requests is "no data is held". To exercise any right or to make a request, email the address linked in the project's GitHub repository. We respond to verifiable requests within 30 days.
California residents: we do not sell personal information, and we do not share it for cross-context behavioural advertising. The "Do Not Sell or Share My Personal Information" toggle is therefore effectively always on for this service.
Contact and requests
Questions about this Privacy Policy, requests under GDPR / CCPA, or notices about content you would like reviewed can be sent to the email address published on the project's GitHub repository. We read and respond to each request within 30 days.
We may revise this policy as the service evolves. Material changes (changes to what we log, how long we keep it, or who we share it with) will be reflected here with an updated "Last updated" date above. Continued use of the service after such changes constitutes acceptance of the revised policy.