Preview 0.5: it says what it is doing
A screen reader test happened for the first time, and the result was blunt: no live regions anywhere, focus falling to the page body after every step, a wrong password that is never announced. The progress bar now reports itself, every state change takes the focus with it, error messages are announced, and four text styles that sat at 3.1:1 contrast were lifted over the required 4.5:1.
Input mistakes stay where you made them instead of throwing you into the recipient view and clearing your file selection. Running out of room no longer sends you to clean up a place that is already empty. Two files with the same name survive the archive as two files. A password link that got cut short says so, instead of blaming your password. And the front page now says above the fold what this build does not do yet.
Preview 0.4: A password on a drop, and an expiry you pick
A drop can now carry a password. The key is wrapped with PBKDF2-SHA256 over 310,000 rounds before it goes into the link, so the link on its own no longer opens anything — you send the password another way. This was the most-asked-for change by a distance, and it needed no server to build.
Alongside it: you choose how long a link lives instead of taking seven days, expired drops are now actually deleted from storage rather than just refused, and there is an overview that can delete a drop whose link you have lost. A tampered file now says so in plain words instead of flashing a button. The help centre is gone — sixteen articles repeating what the reference pages already said, so the reference pages won.
Preview 0.3: Dark mode, a blue identity, and motion
The whole site now ships a token-based dark theme with an Auto / Light / Dark toggle, the accent color settled on the logo blue with luminous touches, and motion got intentional — every section reveals itself as you scroll down to it.
The Limits page goes live
A real subpage in the same design system: Limits states what a drop can hold and how long a link stays valid — 500 MB per drop, checked in your own browser. The navbar grew Expo-style dropdown menus along the way.
Preview 0.2: The security section
The security section spells out how the encryption works, down to the IV of every single chunk. This build also put a browser-local sign-up screen in front of sending — that gate is gone again: it wrote an unsalted password hash into local storage and protected nothing. CloakDrop has no accounts and no sign-in.
Preview 0.1: The encryption engine
The core shipped first: AES-256-GCM through the browser’s WebCrypto API in 4 MB chunks with a unique IV per chunk, an encrypted manifest so even filenames stay private, and links that carry the key in the URL fragment. A key that doesn’t fit fails loudly instead of quietly handing back noise.
No entries match — try another search.