Feature

Secure Send

The landlord needs your ID, the accountant needs a statement. Email attachments live forever in someone's inbox. A Secure Send link decrypts once, then it's gone.

The problem

The moment you email a document, you lose it: it sits in the recipient's inbox, their provider's servers and every backup in between, forever. WhatsApp and Drive links are no better — most are never revoked, and "anyone with the link" means anyone, indefinitely.

How Keepsake solves it

✉️Share from any platform

Pick a document, get a link. Windows, Android and the web app all seal the file locally before anything is uploaded.

🔥Burn after read

Links expire after one download or a time limit you choose (an hour to seven days), whichever comes first. An optional PIN adds a second channel — send the link by email, the PIN by text.

🕶️Zero-knowledge, even to us

The relay stores only ciphertext. The decryption secret lives in the URL fragment (after the #), which browsers never transmit to servers — ours included.

Under the hood — the send protocol

  • The file is framed as KPS2 AEAD; its key is derived via HKDF-SHA256 from a random 128-bit secret carried only in the URL fragment.
  • The optional PIN is mixed into the key derivation itself — the server-side PIN check is just a gate; even a fully compromised relay cannot decrypt without the PIN.
  • Five wrong PIN attempts burn the blob. Downloads are one-shot: the ciphertext is deleted as it is served.
  • Decryption happens in the recipient's browser via WebCrypto on a page with no third-party scripts — the recipient needs no account and no app.

Trust through specificity: the full crypto design is documented on the security page.

Questions

What does the free tier include?

Three Secure Sends per month, up to 10 MB each — counted locally on your device. Premium removes the monthly cap.

Can Keepsake see what I share?

No. Files are encrypted before upload and the key never reaches us — it travels in the URL fragment, which is not sent in HTTP requests.