Privacy & compliance

What file transfer sites load before you click anything

By Hein de Wilde··3 min read

Key takeaways

  • Seven of 14 file transfer homepages contacted advertising, analytics or session-recording services before the visitor clicked anything; seven contacted none.
  • Six of those seven showed a consent banner, and the requests went out while it was still unanswered.
  • A request is not proof personal data was collected, but it shows how many companies your browser talks to on the way to sending a file.
Contents
  1. How we measured
  2. What the results show
  3. What this does and does not prove
  4. Yungle's own result
  5. Check it yourself

We loaded the homepages of 14 file transfer services on 1 October 2026 and logged every request each one made before we touched anything. Seven of them contacted at least one advertising, analytics or session-recording service before the visitor had clicked, scrolled or answered a cookie banner. The other seven contacted none. The range runs from zero to 18 such services on a single page load.

The full results are in the table below, and every number in this article can be checked against the raw data.

How we measured

Each homepage was opened in a fresh Chromium browser profile, from a residential connection in the Netherlands, with no cookies and no cache. The page was given ten seconds to settle after loading. We recorded every request it made, the cookies present afterwards, and whether a consent banner was on screen. Nobody clicked anything, so no consent was given.

We ran the whole thing twice and counted only what appeared in both runs. Rotating ads and A/B tests make a single page load noisy, and a published number should not depend on which load we happened to keep.

A third party is any domain that is not the site's own company. SwissTransfer loading files from infomaniak.com is first party, because Infomaniak runs SwissTransfer. Each third-party domain was then sorted into a category from a fixed list: advertising, analytics, session recording, consent tools, support widgets, or infrastructure such as fonts, CDNs and payments. A domain not on the list was left uncategorised rather than guessed at.

What the results show

7 of 14

Homepages that contacted an advertising, analytics or session-recording service before the visitor clicked anything.Yungle's measurement of 14 file transfer homepages, 1 October 2026

Send Anywhere contacted the most: 18 advertising, analytics or recording domains, including several ad exchanges and Lucky Orange, a session-recording service. MASV contacted 13, most of them HubSpot and LinkedIn marketing services. WeTransfer contacted 8, including Google's ad services and Microsoft Clarity, a session-recording and heatmap tool. TransferNow contacted 5, Smash 4, Filemail 3 and Dropbox Transfer 2.

Seven contacted none: SwissTransfer, pCloud Transfer, MyAirBridge, Tresorit Send, Proton Drive, Wormhole and Yungle. Some of them still set their own first-party cookies, which the table counts.

Six of the seven sites that contacted these services also showed a consent banner. The requests went out while that banner was still unanswered.

What this does and does not prove

A request to an advertising or analytics domain is not, on its own, proof that personal data was collected. Some tools send a cookieless "ping" until consent is given; Google's Consent Mode works this way. A site may also have a legal basis other than consent for some of what it loads. This audit cannot see what was in each request or what happens to it on the other side.

What it does show is how many outside companies a visitor's browser talks to on the way to sending a file, before that visitor has decided anything. For a tool you use to hand over client work, contracts or medical records, that number is worth knowing. The table also makes it easy to compare. Seven well-known services manage the same job with none.

Yungle's own result

I run Yungle, so it was measured with the same script as everyone else, and here is what the result means. Our homepage contacted no third-party domains. It did set one cookie: a session cookie, deleted when the browser closes, that remembers which page a visit started on so that a sign-up can be attributed. We do count page views. The script is served from yungle.co, and our own server forwards cookieless counts to Simple Analytics without your IP address. Your browser never contacts Simple Analytics directly, which is why it does not appear here as a third party. The privacy policy lists it.

Check it yourself

The method is simple enough to repeat. Open a private window, open your browser's developer tools on the Network tab, and load the homepage. Every domain that isn't the site's own is a third party. Our raw results, with every domain we saw for every site, are published as JSON. If you run the comparison and get a different answer, we would like to hear about it. Yungle vs WeTransfer and the alternatives compared cover the rest of what separates these services.

Hein de Wilde

I build and run Yungle, and I write everything here. Comparisons name competitors and credit them, every claim about another company comes from that company’s own documentation, and where we fall short it says so. More about who is behind this.

Read next