PRIVATE BY DESIGN
Share freely.
Leave nothing
behind.
A little less internet. A lot more privacy. Send files, code, and notes with encryption that starts in your browser. No account needed.
Encrypted 629,025 files
PRIVATE BY DESIGN
A little less internet. A lot more privacy. Send files, code, and notes with encryption that starts in your browser. No account needed.
Encrypted 629,025 files
You choose what to share. Your browser encrypts it. We store only ciphertext under a random ID. The key travels in the #fragment of the link — browsers never send fragments to servers.
01
Paste code, write text, or drop files. All metadata is removed from Images and PDFs.
02
A fresh AES-256 key seals the payload in your browser. We never see plaintext.
03
Send the link. By default the blob is wiped after 24 hours — or keep it active for 3 or 5 days.
Secure file sharing with no sharing accounts and automatic 24-hour self-destruction by default — or keep a link active for 3 or 5 days. Built for journalists, sources, and anyone who values their data and privacy.
We still need to stop spam and disk flooding. The controls below are designed to do that without building profiles or attaching identity to what you share.
Your browser seals files, code, and messages before upload. We store ciphertext — not readable content — so abuse checks never need to inspect what you shared.
The decryption key lives in the link’s #fragment. Browsers do not send that part to us, so limiting uploads does not give us a way to open your shares.
File and code shares wipe after 24 hours by default, or after 3 or 5 days if you choose. Secure contact pages last 5 days. Even a flooded disk clears itself on a short clock.
Uploads are capped (up to 5 GB). New shares are rate-limited per network to block mass spam. Those counters stay in memory only — not written into share records or access logs.
ZeroLink’s own analytics uses no cookies. We count page views, estimated visitors, countries, referring domains and share sizes in hourly aggregates retained for up to five years. IP addresses are processed briefly for country lookup and visitor estimates; raw IPs, full referrer URLs, and browsing histories are not stored.
Shares are random IDs plus ciphertext and an expiry time. We do not store your IP, email, or device info on the encrypted object itself.
Don't take our word for it — check in your browser. Encryption, cookies, and network requests you can inspect yourself.
01
Open DevTools → Application → Cookies and Local Storage. The TrustedSite trustmark on this homepage uses cookies and browser storage to measure visits and manage its display. ZeroLink’s own analytics is cookie-free. Administrator sign-in uses a necessary session cookie.
02
After you create a link, look at the address. Everything after # is the decryption key. Open DevTools → Network and confirm requests do not include that fragment — browsers never send it to servers.
03
Share a small test file while Network is open. The upload body is encrypted binary, not readable PDF or text. Plaintext never leaves your browser.
04
In the Network panel, filter by domain. This homepage loads TrustedSite’s third-party script, configuration and trustmark from cdn.ywxi.net and Amazon S3; its verification window loads trustedsite.com. The widget is not loaded on admin or shared-content pages. A trustmark does not certify that no data is stored.
Tip: press F12 (or Ctrl+Shift+I / Cmd+Option+I) to open DevTools, then use the Application and Network tabs above.
To protect your privacy we communicate using an encrypted key just like sharing files. This key gives you access to a temporary secure page. Check the page often for a response to your message from the creator. The link and page are deleted after 5 days.