Accepted file types
There is no allowlist. Every file type is accepted except the short list below, which is refused at upload on every channel: the web uploader, the desktop app, the CLI, ShareX and the REST API.
Not accepted
| File type | Reason |
|---|---|
.exe .scr .com .pif | Windows executables. These were the majority of the malware we had to remove, and hosting them got our download domain flagged by Google Safe Browsing, which breaks downloads for every user on the service. |
.apk .ipa | Android and iOS app installers. Refused since 15 August 2026. This one is temporary, and the reason is below. |
The check runs on our servers, so it applies the same way whichever tool you upload with. A refused upload answers with:
.apk files can't be shared on storage.toThese types also stopped being served: links to files of these types that were already uploaded return "This file type is not available for download" from the same date. If a link of yours stopped working on 15 August 2026, this is why.
Why app installers are refused
In August 2026 a group used us to distribute banking-trojan Android apps at scale, in a form our malware scanning could not reliably catch.
Google found them before we did, and flagged the domain we serve downloads from. That does not just break the bad files: a flagged domain shows a red warning page for every file we host, from every user. Refusing the two types stopped the campaign the same day.
Better scanning for this kind of file is being built now, and app installers are accepted again when it ships. There is no date to promise yet.
Still accepted
Everything else, including the categories people most often ask about:
- Archives -
.zip.rar.7z.tar.gz.iso - Installers other than the four above -
.msi.dmg.pkg.deb.appimage - Developer files -
.jar, source archives, database dumps - Video, audio, images, documents, spreadsheets, CAD, game saves, backups, anything else
Other reasons an upload is refused
A refusal is not always about the file type:
- Size - 25 GB per file on the free tier, higher on paid plans. See limits at a glance.
- Daily quota - 100 GB per 24 hours without an account. Signing in removes the cap.
- Daily file count - 50 files per 24 hours from the API, CLI, desktop app or ShareX without an account. Signing in removes the cap.
- Known-bad content - A file that matches confirmed malware or illegal content is refused whatever its extension, and removed if it is already uploaded.
- Acceptable use - Content that breaks the Terms of Service is removed and the account is closed.
Refused something legitimate?
Email support@storage.to with the file name and what you were sharing. We read every one, and we would rather hear about a wrong refusal than not.