Secure file sharing

Share sensitive files without leaving them exposed.

Encrypt files in your browser, then choose when the link expires, limit it to one successful access, manually disable it, or add an optional password for another layer of protection.

Client-side encryption · Expiring links · One-time access · Optional passwords

Encrypted before upload

Your file is encrypted inside your browser before the protected data is uploaded.

One-time access

Create a link that permanently stops working after the first successful reveal or download.

Expiry controls

Choose a preset expiry, set a custom date or manually disable access whenever required.

Optional password protection

Add a password for another layer of protection. The recipient must enter the correct password before the encrypted file can be accessed.

How it works

Secure sharing without the complexity

  1. 1

    Select and encrypt

    Choose a file and Uploadir encrypts it locally in your browser using a unique encryption key.

  2. 2

    Share the private link

    Send the generated link to the intended recipient through your preferred messaging service.

  3. 3

    Access under your rules

    The recipient can access the file until it expires, is disabled or is consumed as a one-time share.

Expiring secure link

Best when someone may need to open the file more than once, but access should only remain available for a limited period.

  • Preset or custom expiry
  • Can be opened until it expires
  • Can be manually disabled
  • Original account file remains available to its owner
Maximum control

One-time secure link

Best for information or files that should only be supplied successfully once.

  • The landing page does not consume the link
  • The recipient must deliberately reveal or download it
  • The first successful claim permanently consumes the link
  • Refreshing or reopening the same URL will not retrieve the file again
Technical security

Built to keep readable files out of the storage layer

Uploadir does not simply hide a normal download behind a button. Secure files are encrypted before upload and only decrypted locally after an authorised recipient successfully accesses them.

Client-side encryption
Protected files are encrypted in the sender’s browser using authenticated encryption before upload.
AES-256-GCM
AES-256-GCM provides both encryption and integrity checking, preventing modified ciphertext from being silently accepted.
Unique cryptographic keys
Each secure share receives a new random encryption key rather than reusing a password or account-wide secret.
Key stored in the URL fragment
The decryption key is carried after the # in the secure URL. Browser URL fragments are not normally included in requests to the server.
Hashed claim tokens
For one-time shares, Uploadir uses an unguessable internal claim token and stores its cryptographic hash rather than the raw token. This is separate from any optional password chosen by the sender.
Atomic one-time claim
The server uses an atomic claim operation so that two simultaneous requests cannot both retrieve the same one-time payload.
No reusable download URL
One-time access does not expose a reusable signed storage URL that could continue working after the claim.
Restricted caching and logging
Protected responses use no-store behaviour, and sensitive keys or readable file contents must not be included in analytics or application logs.

What secure sharing can — and cannot — do

Secure Sharing controls how Uploadir supplies the protected file. It cannot prevent an authorised recipient from saving, copying, photographing or recording content after it has been revealed. It also cannot protect a device that is already compromised.

For one-time links, strict single access means a failed connection or closed browser tab may require the sender to create a new link.

Common questions

Frequently asked questions

Does opening the page consume a one-time link?

No. The recipient must deliberately select Reveal, View or Download. The link is consumed when the secure claim succeeds.

Does link expiry delete my original file?

No. Expiry disables that shared link. It does not delete the original file from the owner’s Uploadir account.

Can Uploadir recover the decryption key?

The key is carried in the private fragment of the secure URL and is not intended to be stored by Uploadir. Losing the complete URL may therefore make the file impossible to decrypt.

Can a recipient save a one-time file?

Yes. One-time access prevents Uploadir from supplying the encrypted payload again, but it cannot control what the recipient does after viewing it.

Can I add a password?

Yes. Password protection is optional and can be added alongside an expiry date or other secure-sharing controls. The recipient must enter the correct password before the file can be accessed.

Ready to share something securely?

Create an encrypted share, choose your access controls and send one private link.