Skip to main content
Security

End-to-end encrypted file transfer: that Dropvi cannot read

Every Dropvi transfer is end-to-end encrypted. Your browser encrypts the files, their names, the title and the message with AES-256-GCM before upload, using a key that is part of the link after the # sign. Browsers never send that part to Dropvi, so Dropvi stores only encrypted data and cannot open it. The Dropvi command-line tool does the same on your own computer.

It is on for every plan, including Dropvi Free, which sends up to 50 GB per transfer. Your recipient opens the link in a browser, with no account and no app to install.

Updated 28 September 2026.

How other services describe their encryption

Each value comes from the service's own pages, checked on 27 September 2026. The numbers link to the sources at the foot of the page. Services whose pages do not say whether they encrypt end to end are left out.

What Dropvi and other file transfer services say about end-to-end encryption, with a source number for each other service
ServiceWhat its own pages say
DropviEvery transfer is end-to-end encrypted, in the browser or by the command-line tool, on every plan.
WeTransferWeTransfer calls its encryption end-to-end. Its help centre says files are encrypted with TLS 1.2 or 1.3 in transit and with AES-256 at rest.[1][2]
SmashSmash says its transfers are all end-to-end encrypted. Its help centre says files are encrypted in transit and at rest with AES-256, and protected by SSL/TLS between the Smash application and its servers.[3][4]
TransferNowIts file request page mentions end-to-end encryption. Its help centre says transfers are encrypted with SSL/TLS 1.3 or later in transit and with AES-256 at rest. Paid plans can add SSE-C, which encrypts stored files with a key derived from a passphrase only you know.[5][6][7]
FilemailOptional, on the Business plan. You choose it for a transfer and set a key that Filemail never receives. Recipients need the key and the free Filemail Desktop app to decrypt.[8][9]
Google DriveClient-side encryption, which Google says its servers cannot decrypt, on the Frontline Plus, Enterprise Plus, Education Standard and Education Plus editions of Google Workspace.[10]
crocEnd-to-end, with a key agreed from a code phrase (PAKE). Both computers run croc.[11]
magic-wormholeEnd-to-end, with keys derived from a short code (SPAKE2). Both clients run until the transfer finishes.[12]

Scroll sideways to see all columns.

A service's description of its own encryption is not a test of it, and none of these values, Dropvi's included, comes from an independent audit.

How it works

  1. You add files at dropvi.com. Your browser makes a random key for the transfer.
  2. Before anything is uploaded, your browser encrypts each file, its name and type, the title, the message and the sender name with AES-256-GCM. Each file's SHA-256 and CRC-32 checksums are encrypted too.
  3. The key goes in the link after #k=. Browsers do not send the part of a link after the # sign to servers, so Dropvi never receives the key.
  4. Dropvi stores only the encrypted data, in Cloudflare R2.
  5. Your recipient opens the full link. Their browser reads the key, fetches the encrypted files and decrypts them. Single files, the Download all ZIP and previews are all decrypted in the recipient's browser.
  6. After decrypting, the download page shows each file's SHA-256, so your recipient can check the file with the checksum verifier.

What is and is not encrypted

Encrypted before upload

  • File contents
  • File names and file types
  • The title, the message and the sender name
  • Each file's SHA-256 and CRC-32 checksums

Not encrypted: Dropvi still processes these

  • Recipient email addresses, so that Dropvi can send the emails
  • File sizes and the number of files
  • Creation and expiry dates, and download counts
  • IP addresses in request logs
  • Your email address and account, when you are signed in or send by email
  • Your branded subdomain, for a transfer sent from one
  • The PIN, which Dropvi receives to check it. Dropvi cannot decrypt the files with the PIN alone, without the link.

Sending by email

An emailed link does not contain the key. Send the key to your recipients another way, such as by message or phone. The email tells them that you will give them a key to open the files.

If you lose the key, Dropvi cannot recover it. If you were signed in when you sent the transfer and it has no PIN, your dashboard can copy the full link again, but only in the same browser and on the same site you sent from, because that browser keeps the key: a transfer sent from a branded subdomain is not shown with its key on dropvi.com. It does not work for a transfer with a PIN, in another browser or after you clear Dropvi's site data. Otherwise only the full link or the key you saved can open the files.

PIN protection

On Business Pro and above, you can add a PIN or password of at least 6 characters. It is also part of the key, so someone with the full link but not the PIN cannot decrypt the files. Give the PIN to your recipient separately from the link.

Dropvi also checks the PIN before a download starts. It receives the PIN when you set it and when a recipient enters it, and stores it only as a salted hash.

Browser support

  • Downloads and the Download all ZIP are decrypted as they stream, by a service worker in the recipient's browser.
  • In browsers without a service worker, such as Firefox private windows, single files up to 2 GiB are decrypted in memory instead. Larger files need another browser, such as Chrome or Firefox in a normal window.
  • Download all needs a browser window where the service worker runs, so not a Firefox private window. Files can still be downloaded one at a time there.

Using the command line

The Dropvi command-line tool encrypts every transfer it sends on your own computer before upload, and dropvi send prints the full link with the key. With --to, Dropvi emails your recipients a link without the key, and the tool prints the key on a line of its own so you can send it another way.

dropvi get decrypts a transfer on your own computer. It takes the key from the full link, from standard input with --key-stdin or from the DROPVI_KEY environment variable.

If you prefer not to rely on code served by dropvi.com, the command-line tool runs on your own computer at the version you install. Dropvi accepts new transfers only from version 0.2.0 or later.

What it does not protect against

  • Anyone who has the full link, or the link and the PIN when a PIN is set, can open the files.
  • Recipients can share the files onwards once they have downloaded them.
  • The details listed above as not encrypted are still visible to Dropvi.
  • The website runs code that dropvi.com sends to your browser. If that code were changed, it could send keys elsewhere.

Frequently asked questions

Can Dropvi read my files?

No. Your browser, or the Dropvi command-line tool, encrypts the files, their names, the title and the message before upload, and the key stays in the link after the # sign, which browsers do not send to Dropvi. Dropvi still sees recipient email addresses, file sizes, the number of files and dates.

What happens if I lose the key?

Without the key the files cannot be decrypted. If you lose the key, Dropvi cannot recover it. If you were signed in when you sent the transfer and it has no PIN, your dashboard can copy the full link again, but only in the same browser and on the same site you sent from, because that browser keeps the key: a transfer sent from a branded subdomain is not shown with its key on dropvi.com. It does not work for a transfer with a PIN, in another browser or after you clear Dropvi's site data. Otherwise only the full link or the key you saved can open the files.

Can I send an end-to-end encrypted transfer by email?

Yes. Dropvi emails your recipients a link without the key, and you send the key to them another way, such as by message or phone.

Does my recipient need an app or an account?

No. Your recipient opens the full link in a web browser and the files are decrypted there. They do not create an account or install anything.

Does it cost extra?

No. End-to-end encryption is on for every transfer, on every plan, including Dropvi Free.

Send an encrypted transfer

Up to 50 GB per transfer on the free plan, encrypted in your browser before upload.

Sources

Checked on 28 September 2026.

  1. [1]WeTransfer: password-protected file transferwetransfer.com
  2. [2]WeTransfer Help Centre: how we process and protect your data and fileswetransfer.com
  3. [3]Smash: Send Anywhere vs Smash comparisonfromsmash.com
  4. [4]Smash help centre: is Smash secure?fromsmash.com
  5. [5]TransferNow: request and receive large fileswww.transfernow.net
  6. [6]TransferNow help centre: is TransferNow secure?support.transfernow.net
  7. [7]TransferNow: secure file transfer, encryption, 2FA and privacywww.transfernow.net
  8. [8]Filemail: end-to-end encryptionwww.filemail.com
  9. [9]Filemail Help Center: end-to-end encryption with Filemailsupport.filemail.com
  10. [10]Google Workspace: about client-side encryptionknowledge.workspace.google.com
  11. [11]croc repository (schollz/croc on GitHub)github.com
  12. [12]magic-wormhole documentation: welcomemagic-wormhole.readthedocs.io