The short version
- Your files are encrypted in your browser with AES-256-GCM before a single byte is uploaded.
- The key is created on your device and placed in the share link after the
#. Browsers never send that part of a link to any server, so we never receive it. - File names, types and your message are encrypted too. We see only sizes, the number of files and timing.
- When the link expires, the encrypted data is deleted. If you lose the link, nobody can recover the files, including us.
Anatomy of a share link
https://your-domain/d/Xk29fQp1aBcD7e#k=4Jt0…(43 characters)
The first part tells your browser which transfer to fetch. The highlighted part is the decryption key. It stays inside the browser of whoever has the link. Our pages also set Referrer-Policy: no-referrer, so it isn’t leaked to other sites either.
What happens when you send
- Your browser generates a random 256-bit link key.
- Each file is cut into segments (16–64 MB) and every segment is sealed with AES-256-GCM. The nonce and authenticated data bind each segment to its file and position, so segments can’t be reordered, dropped, truncated or swapped between files without detection.
- Names and metadata go into an encrypted manifest with a separate key derived from the same secret (HKDF-SHA256).
- Only ciphertext is uploaded to storage on Cloudflare R2.
Passwords
A password adds a second secret. Your browser stretches it with Argon2id (64 MB of memory, 3 passes) and mixes the result into the encryption key. The server stores only a hash of a separate proof value, so it can check the password, rate-limit wrong guesses (5 tries, then an increasing pause) and still never learn the password or the key. A leaked link alone can’t open a password-protected transfer.
Double encryption (Premium)
With double encryption your browser also creates a random server half of the key. We store it wrapped with a tenant key and release it only after the download is authorised (password, SMS code, region rules, download limit). Disabling the link therefore revokes access for real, even for someone who saved the full link.
SMS codes (Business)
The recipient must also enter a one-time code texted to the phone number the sender chose. Codes expire after 10 minutes and allow 5 attempts.
What we can see
- Size of the transfer, number of files, when it was uploaded and downloaded.
- Approximate location (country and city, from Cloudflare) and device type for download statistics. IP addresses are not stored: we keep only a salted hash that changes every day.
- Your email if you have an account or bought a one-time transfer.
What encryption can’t protect against
We prefer to be honest about the limits of encryption in a web page:
- The code that runs in your browser comes from our servers. If our site were compromised and served malicious JavaScript, it could steal keys. This is true of every web-based end-to-end encrypted service. We keep the client small and load no third-party scripts on download pages.
- A compromised device (yours or the recipient’s) can read files before encryption or after decryption.
- Anyone who has the full link can download the files, unless you also set a password.
- Losing the link means losing the files. We never had the key, so we can’t recover it.
Abuse and law enforcement
Because we can’t read files, our Trust & Safety team can only review content when someone reports a link including its key. We act on reports, can disable links and delete files, and record every staff action in a tamper-evident audit log. Report illegal content at /report.