Home
API Docs

Yukisbox Legal & Trust Center

~ 100% Zero-Logs Architecture & Global Infrastructure Transparency ~

Authoritative Multi-Layer Infrastructure Disclosures & Legal Frameworks

Zero-Logs Architecture
17 U.S.C. § 512 Active
TLS 1.3 & SHA-256
Automated Threat Shield
"Transparency is everything! Check out our Datacenter Topology, Cryptography, and AI Inspection breakdown below." 🐾

🐾 Quick Pencil Summary: Your uploaded files belong 100% to you. We provide the pipes, encryption, and global delivery. Always keep local backups, don't upload bad stuff, and enjoy free fast hosting!

Master Terms of Service Agreement

Effective Date: March 15, 2025 (Updated August 2026) | Jurisdiction: Global Multi-Node Distribution Network | Operator: Yukisbox Network Infrastructure & SUDEEPBOTS Technologies

Notice to All Users: These Terms of Service constitute a legally binding agreement between you (the "User", "you", or "your") and Yukisbox ("Yukisbox", "we", "us", or "our"). By accessing, browsing, uploading, downloading, querying through API, or otherwise utilizing the services available at https://yukiapi.site, subdomains, and associated endpoints (collectively, the "Service"), you unequivocally agree to be bound by every provision contained herein.

1. Scope, Acceptance & Digital Consent

1.1. Binding Legal Contract: Your access to and utilization of the Service is conditioned entirely on your full acceptance of and compliance with these Terms, our Zero-Logs Privacy Policy, and our Acceptable Use Policy. If you object to or disagree with any term, clause, condition, or limitation set forth in this document, you are strictly prohibited from accessing, using, or interacting with the Service, and you must terminate all connections immediately.

1.2. Organizational Authority: If you are accessing or using the Service on behalf of a corporation, partnership, organization, company, academic institution, or other legal entity, you explicitly represent and warrant that you possess the full legal authority to bind that entity to these Terms. In such case, "you" and "your" will refer to both you individually and that entity.

1.3. Age Requirements & Legal Capacity: The Service is not targeted at children under the age of 13. If you reside in the United States, you must be at least 13 years of age. If you reside in the European Union, European Economic Area, or United Kingdom, you must be at least 16 years of age (or the minimum legal age of digital consent in your jurisdiction). By using the Service, you certify that you meet the applicable age requirements and possess full legal capacity to enter into this contract.

2. Modifications to Terms & 30-Day Notice

2.1. Right of Revision: We reserve the exclusive right, at our sole discretion, to modify, update, revise, or replace any part of these Terms at any time for reasons including but not limited to legislative compliance, technological evolution, infrastructure security, or platform feature enhancements.

2.2. Notice Mechanism: If a revision is deemed material by us, we will provide at least 30 days' advance notice prior to any new terms taking effect by posting an announcement on the homepage or updating the revision timestamp at the top of this document. Your continued use of or access to the Service following the effective date of any revisions constitutes irrevocable acceptance of the modified Terms.

3. Content Ownership, Permissions & Deduplication

3.1. Your Content Remains Yours: You retain complete and full intellectual property ownership, copyright, title, and interest in and to any files, videos, documents, images, text snippets, code, archives, or other materials you submit, upload, host, or transmit through the Service ("Your Content"). Yukisbox claims zero proprietary or ownership rights over Your Content.

3.2. Limited Operational License: In order to operate, distribute, host, backup, cache, process, and make Your Content available globally over the Internet, you grant Yukisbox a non-exclusive, worldwide, royalty-free, transferable, sublicensable license to store, reproduce, adapt (such as generating preview thumbnails, video transcodes, or raw text streams), distribute, and transmit Your Content solely for the technical execution of the Service as directed by you and those with whom you share your unique links.

3.3. Cryptographic Deduplication Architecture: The Service employs high-performance cryptographic SHA-256 byte-level deduplication. If a file uploaded by you matches the exact binary hash of an existing file already stored within our global cloud storage matrix, our system will automatically optimize storage by linking your unique Uniform Resource Identifier (UID / Slug) to the existing binary payload without creating redundant physical copies. In such event, exercising an account deletion request will dissociate your specific reference, but the underlying data will remain stored so long as other independent users retain active links to that deduplicated hash.

3.4. Independent Backup Mandate: Yukisbox operates as a high-speed temporary and persistent distribution conduit, NOT as an archival or permanent disaster-recovery repository. We provide no guarantee against data corruption, hardware node failure, third-party storage outages, or administrative cache flushes. You are solely obligated to maintain independent local backups of all data uploaded to the Service.

4. Disclaimers of Warranties ("AS IS" & "AS AVAILABLE")

EXCLUSION OF ALL WARRANTIES:
TO THE MAXIMUM EXTENT PERMITTED UNDER APPLICABLE LAW, THE SERVICE IS PROVIDED STRICTLY ON AN "AS IS" AND "AS AVAILABLE" BASIS, WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE. YUKISBOX, ITS OPERATORS, FOUNDERS, AFFILIATES, INFRASTRUCTURE PROVIDERS, AND LICENSORS EXPRESSLY DISCLAIM ALL WARRANTIES, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, QUIET ENJOYMENT, ACCURACY, NON-INFRINGEMENT, AND ANY WARRANTIES ARISING OUT OF COURSE OF DEALING OR USAGE OF TRADE.

5. Strict Limitation of Liability

MONETARY DAMAGE CAP:
IN NO EVENT SHALL YUKISBOX, ITS CREATORS, DEVELOPERS, EMPLOYEES, AGENTS, SUPPLIERS, OR AFFILIATES BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES WHATSOEVER (INCLUDING LOSS OF DATA, REVENUE, OR PROFIT) ARISING OUT OF THE USE OR INABILITY TO USE THE SERVICE.

OUR TOTAL CUMULATIVE LIABILITY SHALL NOT EXCEED ONE HUNDRED UNITED STATES DOLLARS (USD $100.00).

6. Dispute Resolution, Binding Arbitration & Governing Law

6.1. Binding Arbitration: Any dispute arising out of or relating to these Terms shall be resolved by binding individual arbitration under the Commercial Arbitration Rules of the American Arbitration Association (AAA), waiving class actions.

6.2. Governing Law: Governed exclusively by the laws of the State of California, United States, without regard to conflicts of law principles.

🌍 Infrastructure Truth: Ingestion and delivery are accelerated globally through Cloudflare's Anycast Edge network with origin shielding and high-durability distributed storage clusters!

Global Datacenter & Network Topology

Yukisbox is built on enterprise-grade cloud architecture designed for zero single points of failure, instantaneous global distribution, and maximum resilience.

Cloudflare Anycast Edge

Global Edge Locations terminating TLS 1.3 handshakes in under 8ms from 95% of the world's connected population.

Layer 3/4/7 DDoS Shield

Frankfurt Gateway (EU-1)

High-memory compute gateway executing stream verification, header sanitization, and cryptographic deduplication hashing.

10 Gbps Uplink Lane

Distributed Storage Matrix

Sharded, geo-distributed multi-datacenter backend striping chunks across high-durability storage clusters with automatic multi-zone replication.

Target Durability: 99.99%

Cloudflare Tunnel Ingress

Zero public open inbound ports. Direct encrypted QUIC/HTTP2 tunnel matrix preventing direct-to-IP DDoS and port scanning.

Zero-Port Ingress

1. Multi-Tier Proxy & Edge Routing

Every download and upload request is routed through Cloudflare's secure Anycast edge infrastructure and Cloudflare Tunnel ingress, shielding the origin servers from direct exposure and routing traffic through optimal global fiber paths. If an upstream transit node experiences packet loss, edge routing dynamically optimizes the packet delivery route.

2. Bare-Metal Isolation & Sandboxing

Our API gateways operate under hardened Linux kernel environments with strict cgroups, namespaces, and seccomp system-call filtering. File streams are ingested directly as raw byte buffers without running shell hooks, ensuring complete isolation from host operating system components.

🔒 Cryptography Breakdown: Full TLS 1.3 with AES-256-GCM in transit, SHA-256 integrity verification, and volatile RAM buffer scrubbers that instantly wipe temp files after upload!

Cryptography, RAM Scrubbers & Zero Data Residue

We implement a defense-in-depth cryptographic framework ensuring that your data remains untampered in transit and leaves zero trace on intermediary gateways.

1. In-Transit Encryption Standards

Security Layer Protocol / Standard Technical Specifications
Transport Layer Security TLS 1.3 & TLS 1.2 AES-256-GCM / ChaCha20-Poly1305 cipher suites with Perfect Forward Secrecy (PFS).
Key Exchange ECDHE Key Agreement Curve25519 (X25519) elliptic curve cryptography for sub-millisecond zero-RTT handshakes.
HSTS Preload Protection HTTP Strict Transport Security max-age=31536000; includeSubDomains; preload enforced to prevent SSL stripping attacks.
File Integrity Hash Cryptographic SHA-256 Calculated on the fly to verify byte-level checksum accuracy and prevent bit-rot corruption.

2. Ephemeral RAM Buffering & Memory Scrubbers

2.1. Volatile TMPFS Buffers: When a file is uploaded or fetched from URL, it is processed within an in-memory tmpfs scratch space. The gateway never writes persistent unencrypted copies to persistent SSD/HDD platters.

2.2. Asynchronous Memory Wipe: As soon as the byte chunks are streamed to the upstream storage cluster, the Linux file descriptor is unlinked and zero-filled, guaranteeing that deleted or completed upload streams cannot be recovered from memory artifacts.

3. End-to-End Password Protection

For password-protected files, passwords are cryptographically hashed using PBKDF2/SHA-256 with dynamic salt before validation. The raw password is never stored in plain text or logged in any system register.

🤖 AI Threat Shield: Every upload is scanned in real-time by multi-engine signature filters and AI vision/text heuristics to instantly block malware, phishing scams, and ransomware vectors!

Autonomous AI Threat Shield & Stream Moderation

To ensure Yukisbox remains clean, fast, and trusted globally, we deploy an automated multi-layer security pipeline on every ingested file stream.

1. Multi-Stage Stream Verification Pipeline

Stage 1: Magic Byte Inspection

Validates true file binary headers against stated MIME types to block camouflaged executable files (e.g. PE32 files renamed as .jpg or .mp4).

Header Binary Validator

Stage 2: Hash Threat Blacklist

Real-time cross-referencing against global threat intelligence feeds containing known malware, ransomware, and botnet C2 payload hashes.

Real-Time Threat DB

Stage 3: AI Text & Heuristic Analyzer

Scans raw text and paste uploads for malicious obfuscated PowerShell commands, destructive shell scripts, and phishing credential harvest forms.

Neural Heuristic Engine

Stage 4: Instant Gateway Blackhole

Violating streams are aborted mid-flight before reaching storage. The file reference is permanently purged and blocked from delivery.

Zero-Storage Quarantine

2. Strict Executable Quarantine Policy

To protect end users from weaponized payloads, Yukisbox enforces an automated front-door quarantine blocking standalone Windows/DOS/Scripting executable formats (.exe, .scr, .cpl, .bat, .cmd, .vbs, .msi, .dll, .jar, .hta, .ps1). This prevents automated malware drop staging at the ingestion boundary.

🛡️ Zero-Logs Guarantee: We do NOT track your IP address when you download or browse. Zero advertising pixels, zero telemetry. You can upload anonymously without signing up!

Zero-Logs Privacy Policy & Data Architecture

Effective Date: March 15, 2025 (Updated August 2026) | Standard: GDPR (EU 2016/679) & CCPA/CPRA Compliant

Absolute Zero-Logs Guarantee: Yukisbox is architected from the bare metal up to provide private, anonymous, and un-surveilled file transmission. We maintain zero persistent access logs for downloading files, perform zero cross-site tracking, deploy zero advertising SDKs, and never sell, lease, or monetize user data.

1. What We Collect & What We DO NOT Collect

Data Category Collected? Retention Period Purpose & Description
Visitor / Download IP Addresses NO None (Discarded in RAM) We do not log, persist, or correlate IP addresses of users downloading or viewing public files.
Upload Metadata YES (Minimal) Lifetime of File File size (bytes), MIME type, upload timestamp, cryptographic SHA-256 hash, and optional password hash.
Registered User Accounts YES (Optional) Until Account Deletion Encrypted email address and hashed credentials managed securely via Supabase Auth. Anonymous usage requires zero registration.
Ephemeral Abuse Filtering Temporary RAM Rolling 60 Minutes Volatile in-memory rate-limiter counters to prevent DDoS and automated brute-force attacks. Automatically purged every hour.
Third-Party Ad Trackers NO None Zero Google Analytics, zero Meta Pixels, zero advertising beacons. 100% telemetry-free frontend.

2. Sub-Processor Directory & Safeguards

Sub-Processor Role & Infrastructure Location / Jurisdiction Privacy Safeguard
Cloudflare, Inc. Global Edge Anycast Proxy, DDoS Shield, SSL Termination United States / Global PoPs Standard Contractual Clauses (SCCs), ISO 27001 Certified
Yukisbox Cloud Object Matrix Geo-Distributed High-Durability NVMe Object Storage Cluster Multi-Region High-Security Datacenter Shards Client-isolated byte stream pipelines, Zero user tracking
Supabase, Inc. Encrypted PostgreSQL Account Storage & Auth Frankfurt, Germany (EU Region) GDPR Compliant, SOC 2 Type II Certified
Resend Technologies Transactional Account Verification & Password Resets United States TLS Enforced Delivery, Zero Marketing Spam

3. European Union GDPR Compliance (Regulation EU 2016/679)

For individuals located in the EU, EEA, or UK, you possess full statutory rights under Articles 15–22 of the GDPR, including the Right of Access, Right to Rectification, Right to Erasure ("Right to be Forgotten"), and Right to Data Portability via our Dashboard.

🚫 The Big Red Line: We strictly block dangerous executables (.exe, .scr, .jar, .bat) to protect the community. No malware, no harmful payloads. Media, documents, archives, APKs (subject to malware screening), and code are supported!

Acceptable Use Policy (AUP) & Threat Neutralization

Last Updated: August 2026 | Enforcement Mechanism: Automated Threat Detection & Multi-Engine Signature Analysis

ZERO-TOLERANCE CATEGORIES:
Yukisbox maintains an uncompromising, zero-tolerance policy regarding the hosting or transmission of the following severe materials. Any detection or verified report will result in immediate and permanent file destruction, platform access revocation, and reporting of prohibited content to global child safety registries (such as NCMEC) and relevant authorities:
  • Child Sexual Abuse Material (CSAM) or Child Sexual Exploitation and Abuse (CSAE).
  • Terrorist propaganda, violent extremism recruitment, or instructions on constructing explosive devices.
  • Non-consensual intimate imagery (revenge pornography) or non-consensual sexual violence.
  • Human trafficking, illegal narcotics distribution, or weapon trafficking operations.

1. Prohibited Cyber Threats & Malware Vectors

Yukisbox is engineered for legitimate media, document sharing, and software development collaboration. You are strictly forbidden from uploading, hosting, or distributing:

  • Malicious Code: Viruses, ransomware, trojans, worms, keyloggers, rootkits, spyware, infostealers, botnet C2 payloads, cryptominers, or exploit kits.
  • Social Engineering & Phishing: Phishing HTML templates, credential harvesters, fake login portals, or spoofed brand assets designed to deceive end users.
  • Network Warfare Tools: Distributed Denial of Service (DDoS) control scripts, stresser/booter tools, credential stuffing dictionaries, or automated vulnerability exploitation tools.
  • Restricted Executables: All standalone executable formats (.exe, .scr, .cpl, .bat, .cmd, .vbs, .msi, .dll, .com, .jar, .hta, .ps1).

2. Permitted & Supported High-Trust File Types

The following formats are fully permitted up to 2GB per file:

Category Supported Formats Max Limit
Video & Audio MP4, MKV, WebM, MOV, AVI, MP3, FLAC, WAV, AAC, OGG, M4A, OPUS 2 GB
Images & Graphics JPEG, PNG, GIF, WebP, SVG, AVIF, BMP, ICO, TIFF, PSD 2 GB
Documents & E-Books PDF, EPUB, MOBI, TXT, RTF, ODT, CSV, XLSX, PPTX 2 GB
Archives & Containers ZIP, RAR, 7Z, TAR, GZ, BZ2, XZ, ZST, ISO (Safe Images) 2 GB
Mobile Applications APK (Android Package Archive — Subject to automated threat scanning & AUP compliance) 2 GB
Code & Plain Text Snippets PY, JS, TS, HTML, CSS, JSON, SQL, CPP, JAVA, GO, RS, SH, MD, YAML, LOG 10 MB

⚖️ Copyright Respect: We respect original creators and intellectual property. If your work is hosted here without authorization, email our designated agent at dmca@yukiapi.site for removal within hours!

Digital Millennium Copyright Act (DMCA) Policy

Compliance Framework: Title 17, United States Code, Section 512 | Designated Agent Registration: Active

Yukisbox respects the intellectual property rights of creators and copyright owners, and we expect all users of our Service to do the same. In accordance with the Digital Millennium Copyright Act of 1998 (17 U.S.C. § 512), we will respond expeditiously to legitimate notices of claimed copyright infringement submitted to our Designated Copyright Agent.

1. Submitting a Valid DMCA Takedown Notice

To file a legally sufficient copyright infringement notification, you (or your authorized legal representative) must transmit a written communication containing the following mandatory elements specified under 17 U.S.C. § 512(c)(3):

  1. Physical or Electronic Signature: A physical or electronic signature of a person authorized to act on behalf of the owner of an exclusive right that is allegedly infringed.
  2. Identification of Copyrighted Work: Identification of the copyrighted work claimed to have been infringed (or, if multiple works at a single site are covered by one notice, a representative list of such works).
  3. Specific Location / Exact URLs: Identification of the material that is claimed to be infringing or to be the subject of infringing activity, including the exact Yukisbox URL(s) (e.g., https://yukiapi.site/file/XXXXXXXX). Generic homepages or non-specific domain complaints cannot be processed.
  4. Contact Information: Information reasonably sufficient to permit us to contact you, including your legal name, physical address, telephone number, and email address.
  5. Good Faith Statement: A statement that you have a good faith belief that use of the material in the manner complained of is not authorized by the copyright owner, its agent, or the law.
  6. Accuracy & Perjury Statement: A statement that the information in the notification is accurate, and under penalty of perjury, that the complaining party is authorized to act on behalf of the owner of an exclusive right that is allegedly infringed.
Designated Copyright Agent Contact:
Attn: Yukisbox DMCA Compliance Officer
Email: dmca@yukiapi.site / hello@yukiapi.site
Response SLA: Valid takedown notices are processed and infringing links disabled within 2 to 12 hours of verified receipt.

2. Repeat Infringer Policy

Yukisbox strictly enforces a "three-strikes" repeat infringer policy. We will terminate accounts, revoke API access tokens, and permanently restrict access for users who repeatedly or systematically upload copyright-infringing content.

🐤 Canary Healthy: All canaries are intact and active! No gag orders, no backdoors, no secret government wiretaps. 100% clean and transparent.

Official Warrant Canary & Transparency Report

Status: ALL CANARIES INTACT | Verification Period: Q3 2026 (Updated August 2026)

Formal Warrant Canary Statement:
As of August 18, 2026, Yukisbox makes the following declarations:
  • Yukisbox has NEVER received a National Security Letter (NSL), FISA court order, or gagged government subpoena.
  • Yukisbox has NEVER installed any backdoor, hardware tap, or surveillance intercept on our servers or network infrastructure.
  • Yukisbox has NEVER compromised, modified, or handed over user encryption keys or private certificates to any domestic or foreign intelligence agency.
  • Yukisbox has NEVER modified our software or algorithms to facilitate mass surveillance or bulk data collection.
Canary Statement Integrity Hash (SHA-256):
c4b8e21094df8a69e3381a1795c697010f3c5b8b9826a7f058097b6e92788e2c
Published by Yukisbox Engineering Collective • Next Scheduled Declaration: Q4 2026

Transparency Metrics (Past 12 Months)

Metric Count Action Taken
DMCA Takedown Notices Processed 42 100% of verified copyright notices removed within 4 hours
Malware / Phishing Vectors Blocked 1,850+ Automated rejection at upload gateway (0 delivered)
Government / Court Subpoenas Received 0 None received
National Security Letters (NSLs) Received 0 None received

🐞 Hackers & Researchers Welcome: Found a vulnerability? Report it responsibly to security@yukiapi.site. We offer full safe harbor protection and swift remediation!

Vulnerability Disclosure & Bug Bounty Program

Program Scope: https://yukiapi.site & Core Backend APIs | Safe Harbor: Guaranteed

Yukisbox is committed to upholding the highest standards of security. We actively welcome contributions from ethical security researchers worldwide to help maintain the integrity and resilience of our platform.

1. Safe Harbor Policy

We consider security research conducted under this policy to be authorized. We will not pursue civil lawsuits or initiate criminal complaints against ethical researchers who: (1) Make a good-faith effort to avoid privacy violations and service disruption, (2) Promptly report vulnerabilities without public exploitation, and (3) Give us reasonable time to remediate before public disclosure.

2. Reporting a Vulnerability

Send a detailed Proof of Concept (PoC) with reproduction steps to security@yukiapi.site. We acknowledge all reports within 12 hours and provide status updates throughout the remediation lifecycle.

Home Terms of Service Privacy Policy API Docs Abuse / Contact Reviews
© 2025 - 2026 Yukisbox Technologies. All rights reserved. Hand-crafted Anonymous File Distribution Network.