How it works
Short version: your browser does the encrypting, the key never leaves the link, and everything is deleted within a day. The details are below.
Encrypted on your device
Each file is encrypted in your browser before any of it is sent, in 64 KB records with AES-128-GCM as described in RFC 8188. Firefox Send worked the same way. The server and the storage company only ever hold scrambled data.
The key lives in the link
The part after the # is the secret. Browsers do not send that part of an address to a server, and the whole design rests on that. Anyone who has the complete link can open the files, so be as careful with the link as you would be with the files.
Straight from browser to browser
While the sender’s page is open, the two browsers also connect to each other directly, and encrypted pieces travel between them. That is why a download can start before the upload is done. To set up that connection the browsers exchange network details, IP addresses among them, through the service. None of that is stored.
Deleted on its own
A transfer is deleted after 24 hours or after the number of downloads you chose, whichever comes first. You can shorten that, or delete the transfer yourself. Deleting removes the encrypted files from storage, not just the link.
Where it runs
The encrypted files are stored at OVHcloud in the Paris region. There is no content delivery network, no analytics service and no ad network in between. During a direct transfer the encrypted pieces travel between the two browsers themselves, wherever those are.
What stays on your own device
The browser you send from remembers your transfers until they expire, key included. That is how you can come back to an upload, see whether someone is downloading, or delete a transfer after closing the page. While an upload runs it also holds the encrypted pieces. None of this leaves your device, and Forget on this device removes it.