Send sensitive files. Once.
Encrypted in your browser before upload. Delivered with a one-time link. Permanently deleted after download. We never possess the key and cannot read your files.
AES-256 in your browser, via WebCrypto. Recipients need no account. Every sender is card-verified.
How it works
Encrypt locally
Your browser generates a key and encrypts the file with AES-256 before a single byte is uploaded. The key never leaves your device except inside the link you share.
Share one link
You get a single link that carries the key in a part of the URL browsers never send to servers. Share it however you like — your recipient needs no account and no password.
Downloaded once, then destroyed
The first click opens a one-hour download window, and the link can never be opened a second time. When the window closes — or the link expires unused — the encrypted file is deleted, and the deletion is verified.
What we can and cannot see
Zero-knowledge is an architecture, not a slogan. Here is the honest inventory.
We can see
- Your account email address
- How large each transfer is
- When a transfer was created, downloaded, and deleted
We cannot see
- The contents of your files
- Filenames — they are encrypted before upload
- The decryption key — it exists only in your link
The threat model, in plain English
Exactly what protects your files, what our servers store, and where the honest limits are.
Read the security page →
Verified configuration, published daily
An automated check confirms every day that our storage still matches our promises — and publishes the result, pass or fail.
See the trust page →