Skip to main content

Files

Send a file securely — one download, then it’s gone

Google Drive links live until you remember to revoke them. Email attachments live in everyone’s inbox forever. SnapSend creates a one-time, encrypted download link — once the recipient grabs the file, it’s permanently deleted from our servers. For files bigger than 100 MB, switch to peer-to-peer Nearby where the file never touches our servers at all.

No account required AES-256-GCM Self-destructs after reading

How to do it

01

Drop the file

Drag and drop, or click to select. Files up to 100 MB go through hosted upload; larger files automatically use peer-to-peer.

02

It’s encrypted in your browser

AES-256-GCM happens locally. We upload only ciphertext — we never see what you sent.

03

Send the link

Copy the encrypted download link and send it however you like. The recipient can be on any device — no app needed.

04

Self-destructs on download

When the recipient downloads, the file is wiped from our blob storage. No backups, no archive — verifiably gone.

The problem with emailing sensitive files

Email was never designed to be a secure vault, yet it’s where most sensitive documents end up — contracts, ID scans, medical records, payroll files. An attachment doesn’t just travel to your recipient; it’s stored in your Sent folder, their inbox, both providers’ servers, and every backup and connected device along the way. Delete your copy and the others remain. Months later that file is still one compromised inbox away from exposure.

The usual workarounds aren’t much better. Consumer file-sharing services keep a copy on their servers and often generate links that work for anyone, indefinitely, with no way to guarantee the file is gone once the recipient has it. Size limits then push people toward whatever free uploader is closest, with no thought to who can access it.

How self-destructing file links work

SnapSend encrypts your file in your browser before it uploads, using AES-256-GCM. The decryption key is placed in the link’s URL fragment — the part after the # that browsers never send to a server — so we only ever store ciphertext we cannot read. The recipient opens the link, the file is decrypted on their device, and the encrypted copy is then permanently deleted from our side. No account, no lingering public URL, and no plaintext copy sitting on anyone’s server.

For very large or highly sensitive files, you can skip the server entirely with a direct device-to-device transfer, so the bytes never touch our infrastructure at all. Either way the goal is the same: the file reaches exactly the person you sent it to, once, and then it’s gone.

Encrypted in your browser

AES-256-GCM happens on your device. The key never reaches our servers.

Read once, then deleted

Self-destruct on first read. No backups. No archive. Just gone.

Free, no signup

No email. No tracking. Open the page, encrypt, share the link, done.

Frequently asked

Related tools

Try it now

No signup, no credit card, no email. Just a link.

Send a file now