NeonShare
Zero-knowledge · AES-256 · Open architecture

Share files securely.
Vanish after delivery.

Files are encrypted in your browser before they ever leave your device. Set passwords, expiry, and download limits — we'll auto-delete the rest.

AES-256
End-to-end
Temporary
Storage
None
Tracking
Features

Privacy, security, and speed — by default

Every share is encrypted, ephemeral, and yours to control.

End-to-end encryption

Files are encrypted in-browser with AES-256-GCM via the Web Crypto API.

Password protection

Optionally protect any link with a password — we only store a verification hash.

Expiring links

Choose from 10 minutes to 7 days. Expired files are wiped automatically.

Download limits

One-time, 5, 10, or unlimited downloads. Auto-deletes once the limit is reached.

QR sharing

Every link has a downloadable QR code for instant mobile transfers.

No tracking

No ads, no analytics, no profiling. Anonymous uploads supported.

How it works

Three steps. Zero compromises.

1

Drop your file

Pick any file, set expiry, downloads, and an optional password.

2

Encrypted in-browser

AES-256 happens in your browser. We never see the original file or key.

3

Share the link

Send the link or QR. After expiry or last download, the file is gone.

256-bit
AES encryption
PBKDF2
250k iterations
0
Files retained
∞
Files you can send
FAQ

Common questions

Can you see my files?

No. Files are encrypted in your browser before upload. The decryption key lives in the URL fragment (after #), which is never sent to the server. For password-protected files, only a verification hash is stored.

What happens when a file expires?

Files are automatically deleted from storage when they expire or hit their download limit. Metadata is purged too — there's nothing left to recover.

Do I need an account?

No. Anonymous uploads are supported. Create a free account if you want a dashboard to manage your active shares, extend expiry, or revoke links.

What file types and sizes?

Any file type. Practical limits depend on your browser's memory for encryption.

Is this open about its architecture?

Yes. We use AES-256-GCM via the Web Crypto API, PBKDF2 for password-derived keys, and store only encrypted blobs in temporary storage.