Encryption
Encrypted on your device
File contents and the original filename are encrypted before upload. The file payload goes directly to object storage; the API coordinates the transfer without receiving the plaintext.
File transfer
Streamed to storage, never through our API. Share a file or a folder with browser encryption and a lifetime you control.
client-handoff.zip
Illustrative handoff
Shared link
secretpaste.com/s/a3bCz1Key stays in the fragment
#29K4azt81Ygo1BtI…File transfer
Private documents and project files need a way to reach their recipient without sitting in a shared folder indefinitely. SecretPaste separates the file delivery from the conversation around it.
Encryption
File contents and the original filename are encrypted before upload. The file payload goes directly to object storage; the API coordinates the transfer without receiving the plaintext.
Recipient
Use Add files or Add folders on the homepage. Review the selection before creating the link; folders preserve relative paths inside the transfer.
After delivery
The recipient explicitly reveals and downloads the file. Expiry and view controls govern future access through the link, even though a downloaded copy remains theirs.
A straightforward handoff
Add a file or folder, then review the names and sizes. The composer shows the current upload allowance.
Select Create link. Your browser prepares the encrypted payload and uploads it directly to storage.
Send the complete link. The recipient reveals the transfer and their browser decrypts the download.
“The recipient gets the secret. Our servers never get the plaintext or the decryption key.”
— The SecretPaste browser encryption boundary
Before you share
The composer displays the upload limit for your current plan. Visit pricing to compare file allowances; files are checked against the same plan limits before upload.
The encrypted file payload uploads directly to storage. The API handles permissions and transfer metadata, but does not receive the browser plaintext or decryption key.
No. Expiry and burning remove access through the service. They cannot remove a file the recipient has already downloaded.
Encrypted in your browser, gone after one view. Send a password, a token, or an environment file without leaving its contents in a message thread.
Explore featureOne atomic claim per view, then the ciphertext is gone. Give sensitive text or a file a clear end to its availability.
Explore featureKnow when, where and on what device it was opened. See delivery events and the coarse context available for a reveal, without keeping the secret itself.
Explore featureShare text or a file with a link that has an ending. Start with the browser composer.
Share a file