frequently asked questions.
find quick answers to common questions about toss-it.
getting started
what is toss-it?
a way to receive files directly into storage you already use. you connect your Google Drive, create a link, and anyone can upload files straight into the folder you chose, no account required on their end.
how is this different from emailing a file or using WeTransfer?
there's no attachment size ceiling and no third party holding a copy of the file in between. files go straight from the sender's browser into your own Google Drive, and you keep control of the link: expire it, pause it, or revoke it whenever you want.
does the person sending me a file need an account?
no. senders never sign up for anything. they open your link, choose files, and upload, that's the whole flow.
what's the difference between quick toss and a structured request?
quick toss is a single link that accepts any files. a structured request is a named checklist: you list the specific documents you need (e.g. "passport", "proof of address"), and the sender sees exactly which items are still outstanding as they fill each one in.
what's a collection campaign?
a way to send the same request to a whole list of people at once. add recipients, and each one gets their own unique link, tracked individually as pending, opened, or completed, with a one-click reminder for whoever's still outstanding.
can i share toss-it with my team?
yes. a workspace lets your whole team share one connected drive and manage links and campaigns together. roles, owner, admin, member, decide who can manage what; invite teammates from your workspace settings.
sending files
can i control what uploaded files get named in my drive?
yes, optionally. a link can carry a naming template using {date}, {sequence}, and {originalName} tokens, so incoming files land already organized the way you want.
is there a limit on file size or how many files a link accepts?
you set those limits yourself when you create a link: a maximum total size, an optional per-file size cap, and which file types are accepted.
storage & delivery
what storage providers can i connect?
Google Drive today. it's the only supported destination right now.
what happens when a link expires?
it stops accepting new uploads immediately. anything already delivered stays exactly where it landed in your drive, expiry only affects future uploads.
can i pause a link without losing it for good?
yes. pausing is reversible, it stops new uploads temporarily and you can resume it later. revoking is the permanent, one-way version of the same idea. both take effect immediately.
do you store the files people send me?
no. files stream directly from the sender's browser into your connected Google Drive. toss-it never keeps a permanent copy of file contents on its own servers at any point.
security & privacy
what do you store, then?
account information, your Google Drive credentials (encrypted), and metadata about your links and transfers, names, sizes, timestamps, and status. see the privacy page for the full breakdown.
how are my Google credentials protected?
they're encrypted at rest with AES-256-GCM, and the OAuth grant itself is the narrowest scope Google offers for this use: per-file write access to what the app creates, not read access to your existing drive.
how are passwords stored?
hashed with scrypt, and checked against the Have I Been Pwned breach database before we accept a new one, using an API that only ever receives a few characters of a hash, never your actual password or email.
do you scan uploaded files for malware?
not yet. because files stream directly into your storage rather than landing in a holding area first, there's currently no point in the pipeline where a scan could run before delivery. this is a known, disclosed limitation, see the security page.
how long do you keep security and activity logs?
automatically for 180 days, after which they're deleted on a rolling basis.
can someone with one of my links see anything else in my account?
no. a sender using your link can only push files into the one folder you selected for that specific link, they never see your drive contents, your credentials, or any other account data.
how do i report a security issue?
email security@toss-it.online with what you found and how to reproduce it. see the security page for our full disclosure policy.
account & billing
does toss-it cost anything?
it's free while the project is under active development. if that ever changes, existing users will be notified before any charge applies, see terms for the specifics.
can i delete my account and everything tied to it?
yes, from your account settings. deleting your account removes your upload links, transfer records, and connected-storage credentials immediately, it's a real deletion, not a deactivation.