Secure file transfer with end-to-end encryption

Files are encrypted in your browser before they leave your device. Our servers only ever store unreadable data, and the decryption key stays in the link you share.

End-to-end encryption on by default

Hosted in France

Open source

How your transfers are protected

Encrypted in your browser

Every file is encrypted with AES-256-GCM using your browser's Web Crypto API before upload. This is on by default for every account, including the free plan.

The key stays off the server

The decryption key lives in the part of the link after #key=. Browsers never send that part to the server, so the server cannot read your files.

Links that expire

Each share expires on the date you pick, within your plan's limit, and its files are then deleted. You can also cap the number of downloads.

Passwords and download alerts

Add a password to a link and get notified whenever a recipient downloads your files.

HTTPS vs encryption at rest vs end-to-end encryption

Almost every transfer service says it encrypts files. What matters is who holds the key, because whoever holds it can read the file.

ProtectionWhat it coversWho holds the keyCan the provider read the file?
HTTPS (TLS)The connection between your browser and the serverThe serverYes, once the file arrives
Encryption at restThe provider's disks and backupsThe providerYes, it decrypts on demand
End-to-end encryptionThe file, from the sender's browser to the recipient'sThe sender and whoever holds the linkNo, the server never gets the key

PrivCloud uses all three. To see why the second one is not enough on its own, read why encryption at rest falls short.

Send confidential files without exposing them to your provider

Contracts, payslips, medical or legal records, financial data: once the content is sensitive, a plain public link is not good enough. With end-to-end encryption, what sits on our servers is just a stream of encrypted bytes.

Even if someone gained unauthorised access to storage, the content would stay unreadable without the key. That key only exists in the sender's browser and in the link given to the recipient.

  • Create your account and drop your files in. Encryption happens automatically.
  • Set an expiry date, a password and, if you need one, a download limit.
  • Share the full link. For highly sensitive files, send the link without its #key= part and pass the key through another channel, such as Signal or a phone call.

Access controls on top of encryption

Encryption protects the content. Access controls decide who can fetch the file, and for how long.

  • Expiry: the link stops working on the chosen date and the files are deleted.
  • Password: it gates access to the link. It does not replace the encryption key, it adds to it.
  • Download limit: the share closes once the allowed number of downloads is reached.
  • Account protection: two-factor authentication with TOTP codes is available on every account.

Secure file sharing for businesses

Teams get shared spaces that are end-to-end encrypted. A file dropped into a team folder is always encrypted: without a key, the upload is refused rather than sent in the clear.

To collect documents from clients or partners, an upload link lets someone outside your organisation send you files without creating an account. It is end-to-end encrypted as soon as your key is active, which is the default.

Paid plans handle up to 250 GB per transfer. A data processing agreement (DPA) covers business use. For personal data obligations, see our page on GDPR file transfer.

What end-to-end encryption does not hide. The server still knows file names, sizes and dates, as well as technical connection data. Anyone who gets hold of the full link can open the files, so send it through a channel you trust.

Frequently asked questions

Send your first encrypted file

Create a free account: end-to-end encryption applies from your very first transfer.

Further reading