Limits

Free to use.
Not unlimited.

One AES-256-GCM pipeline, the same for every drop. These are the numbers it works inside.

Size per drop

500 MBat most

Counted per drop, not per file.

Any number of files in one drop
No cap on how many drops you make
Anything larger goes out as several drops

Link lifetime

You choose1 hour, 24 hours or 7 days

Picked before cloaking, counted from the moment the drop is created. 24 hours if you do not change it.

Opening a link needs no account and no sign-in
Clearing site data takes the stored chunks with it
A fresh drop starts its own clock

Does your file fit in one drop?

Largest single drop: 297 MB

10 MB100 MB500 MB2 GB
Fits Under the 500 MB limit — this goes in one drop.

Every limit, written out

LimitValue
Transfers
Where a link opensOnly in the browser that created the drop. There is no relay yet, so a forwarded link shows an error on someone else’s device
Max size per drop500 MB
Files in one dropNo limit
Number of dropsAs many as this browser has room for
Links
Link lifetime1 hour, 24 hours or 7 days
ChosenBefore cloaking, per drop
Extend a linkNot from the app — but the clock is yours
Once the time has passedThe link stops opening
Encrypted chunks after expiryRemoved next time you open the app — including drops whose encryption was interrupted
Delete a drop earlyYes, from the app
Password on a dropOptional, set before cloaking
Account or sign-inNever
Security — one pipeline, every drop
AES-256-GCM, end to end
Server involvedNone
Encrypted filenames

The same numbers for every drop, always.

“Know the limit before you hit it.” That is why the numbers sit on this page instead of in an error message halfway through an upload — including the one this build actually enforces. What runs underneath never changes: AES-256-GCM, with a key that never leaves your browser.

Questions about the limits

Why is there a size limit at all?
Every drop is encrypted in your browser and has to fit in this browser’s own storage until you hand the link over. 500 MB covers ordinary handovers; anything bigger goes out as several drops, and the number of drops is not capped.
Why 500 MB and not more?
Every chunk of a drop is encrypted and then kept in this browser’s own storage until you hand the link over. 500 MB is what one browser holds and gives back reliably — past that, storage limits and memory start deciding instead of you. It is the same number the drop zone shows, and since it is checked again before anything is encrypted, removing the button’s disabled state no longer gets you past it.
What happens when the time is up?
The link stops opening, and the next time you open the app the drop is deleted for real — record and every encrypted piece. Until that next visit the pieces are still on your disk, so expiry is not an instant shredder. Two things it is not: the check compares against a timestamp stored in your own browser, so anyone who can open your browser profile can edit it and get back in before the cleanup runs. It keeps a link from being useful later; it does not keep anyone out of your own machine. If the files are still needed, create a fresh one.
Can I put a password on a drop?
Yes, and it changes what the link is. Without a password the link carries the key itself — whoever forwards it forwards the files. With one, the key is wrapped (PBKDF2-SHA256, 600,000 rounds) and the link alone opens nothing; the password has to travel some other way. Nobody can recover it for you, including us: it is never sent anywhere and never stored. Lose it and the drop is gone, which is the point.
Can I have several drops open at the same time?
Yes. The number of drops is not limited. Each one carries its own key and its own clock, and the 500 MB applies to each drop separately, not to everything you have open.
What counts as one drop?
Everything you hand over in one go. The number of files inside is not limited; they are sealed as a single encrypted bundle, so it is their combined size that has to stay under 500 MB.
Can I use this at work — data protection, liability, a processing agreement?
Straight facts, not legal advice. In this build nothing you cloak reaches a server: the encryption, the storage and the decryption all happen in your browser, and you can confirm that in the network tab. There is no operator holding your files, which is why there is nothing for us to hand over, lose, or be compelled to produce — and also why a processing agreement has nothing to attach to yet. That changes the day the relay exists, because then someone does store ciphertext for you, and we will say so here before it goes live rather than after.

What this page cannot do is answer for your situation. Whether a browser-only tool is enough for client files, patient records or anything under Article 9 is a judgement your own obligations decide, not our feature list. The binding statements — who operates this, under which law, and what they are liable for — belong in the imprint and the privacy notice, and those are being completed. Until they are, treat this as something to try, not something to rely on at work.
Can a link be extended or removed early?
Extended, no: the lifetime is fixed the moment the drop is created, and there is no way to add time afterwards. Removed early, yes — every drop has a delete button, in the finished view and in the list of stored drops, and it removes the record and every encrypted piece in one transaction. Clearing site data still works too, and takes everything at once.

Try it with a real file