Secure Send
The landlord needs your ID, the accountant needs a statement. Email attachments live forever in someone's inbox. A Secure Send link decrypts once, then it's gone.
The problem
The moment you email a document, you lose it: it sits in the recipient's inbox, their provider's servers and every backup in between, forever. WhatsApp and Drive links are no better — most are never revoked, and "anyone with the link" means anyone, indefinitely.
How Keepsake solves it
✉️Share from any platform
Pick a document, get a link. Windows, Android and the web app all seal the file locally before anything is uploaded.
🔥Burn after read
Links expire after one download or a time limit you choose (an hour to seven days), whichever comes first. An optional PIN adds a second channel — send the link by email, the PIN by text.
🕶️Zero-knowledge, even to us
The relay stores only ciphertext. The decryption secret lives in the URL fragment (after the #), which browsers never transmit to servers — ours included.
Under the hood — the send protocol
- The file is framed as
KPS2AEAD; its key is derived via HKDF-SHA256 from a random 128-bit secret carried only in the URL fragment. - The optional PIN is mixed into the key derivation itself — the server-side PIN check is just a gate; even a fully compromised relay cannot decrypt without the PIN.
- Five wrong PIN attempts burn the blob. Downloads are one-shot: the ciphertext is deleted as it is served.
- Decryption happens in the recipient's browser via WebCrypto on a page with no third-party scripts — the recipient needs no account and no app.
Trust through specificity: the full crypto design is documented on the security page.
Questions
What does the free tier include?
Three Secure Sends per month, up to 10 MB each — counted locally on your device. Premium removes the monthly cap.
Can Keepsake see what I share?
No. Files are encrypted before upload and the key never reaches us — it travels in the URL fragment, which is not sent in HTTP requests.