End-to-end encrypted · zero knowledge · zero logs

Secure Files & Secrets. Ephemeral. Burned.

Share end-to-end encrypted files, notes, or passwords. Set self-destruct timers and passcodes with zero logs.

Drag & drop files here or click to browse

Up to 50MB encrypted • Auto-expires • No sign-up

    Archives and video are relayed to a storage partner so this site can run on a small host — those uploads are not end-to-end encrypted. Everything else is sealed in your browser and never leaves this server in readable form. You will always be told which one you are getting.

    ⚡

    Lightning Fast

    Drop, configure, and get your ephemeral link in seconds. No accounts, no queues, no friction.

    🛡️

    Sealed In Your Browser

    Secrets, images and documents are encrypted with AES-256-GCM before they are sent. Large archives and video are relayed to a storage partner to keep the footprint small, and say so up front.

    🔥

    Burn After Read

    Deletion is issued the moment the limit or the timer is reached — for offloaded files, the download button itself triggers the destroy call.

    How it works

    Your browser holds the key. The server holds a box.

    For anything small, your browser generates an AES-256-GCM key, encrypts the payload, and uploads only ciphertext. The key travels inside the link fragment — a part of the URL browsers never send to servers. Add a passcode and the key is derived with PBKDF2 instead, so the link alone is useless.

    Archives and video are the exception, on purpose: they are relayed to 1cloudfile and Streamtape so the site itself can live on a cheap host. Those bytes are not encrypted by us, the recipient has to be trusted with the link, and burning means calling that provider's delete endpoint. The share screen tells you which case you are in before you upload.

    1
    Seal
    Encrypted locally with AES-256-GCM.
    2
    Share
    A short link with a self-destruct timer.
    3
    Burn
    Deleted forever on first read or at expiry.
    4
    Vanish
    No IP log, no analytics, no recovery.
    vault://x7f9a2b
    $ curl -X POST /api/vault.php \
        -H "X-Vault-Meta: {…}" \
        --data-binary "@ciphertext.bin"
    
    201 Created  id=x7f9a2b  expires=24h
    
    # plaintext? never existed on the wire
    # key?      lives in the URL fragment
    # logs?     there are none