Private file delivery

Send the file. Keep the key private.

ZipPigeon seals sensitive files in your browser before they leave your machine, then delivers them to exactly one recipient, for exactly as long as you choose. No broad shared folders to unwind. No attachments living forever in inboxes.

Encrypted before upload Recipients don’t need an account Access expires on your schedule

Dispatch manifest ZP-7F2K-0N1H
From Amara Osei counsel@osei-law.com
To One verified recipient account-bound · key fingerprint pinned
Contents
settlement-agreement-v4.pdf2.1 MB exhibit-index.xlsx340 KB signature-pages.zip5.8 MB
Access Expires in 72 hours 1 download · revocable until opened
key a4:9f:1c:7e:b2:6d · raw key not sent to the server Sealed
Sealed in the sender’s browser · server stores ciphertext only
Encrypted before uploadYour browser locks every file before it leaves your machine. ZipPigeon stores ciphertext and coordinates delivery, status, expiration, and audit events - never readable contents.
Delivered to a personInvite an account-bound recipient you know, or hand a guest a one-time secure link. Either way, you choose who gets in - not a folder permission tree.
Over when it is overTransfers expire on your schedule, links die after use, and future ZipPigeon-mediated access closes without leaving a shared-folder permission to chase.
Anonymous sends stay small on purposeUse anonymous send only for short-lived one-time handoffs that do not need a sender dashboard or audit history.
  • Anonymous one-time sends: 50 MB total, 5 files, 80 encrypted parts, one download, and a 24-hour maximum expiry by default.
  • Anonymous default expiry: 6 hours unless the sender chooses a shorter or longer allowed window.
  • Anonymous file policy: high-risk executable, script, installer, and active-content extensions are blocked before upload.

How it works

Three steps. One controlled handoff.

STEP 1

Seal in your browser

Drop in the files. They are encrypted on your machine before a single byte is uploaded — the raw file key is not uploaded with them.

encrypting locally… XChaCha20-Poly1305
STEP 2

Send to the right person

Invite a known recipient by account, or hand a guest a secure one-time link. Either way, you decide who — not a folder’s permissions.

share granted → 1 recipient
STEP 3

Let it expire

Set the access window when you send. When it closes — or you revoke early — the handoff is simply over.

expired · future access closed

The honest security model

What we can’t read — and what we still see.

Most tools say “secure” and stop. We would rather show you the exact boundary.

Out of our reach

  • Your file contentsEncrypted in your browser; we store unreadable chunks.
  • Your file keysGenerated locally and wrapped per recipient; raw file keys are not sent to the server.
  • Your account private keysProtected by your password with Argon2id. We hold the lockbox, not the key.
  • Secure-link fragmentsThe unlock half of a link lives after the #, which never reaches our servers.

Still visible to us

  • Delivery metadataWho sent to whom, when, file sizes, and transfer status — delivery needs it.
  • Account & audit recordsEmails, sign-ins, download events, and abuse-prevention signals.
  • Names you chooseFilenames and notes are not secrets by default — keep sensitive details out of them.
  • Completed downloadsExpiry stops future access. It cannot recall a file someone already saved.

No “military-grade” hand-waving, no compliance badges we have not earned. Read the full security model — including what is still on the roadmap.

Who it’s for

Built for the professionals who can’t just email it.

A handoff tool — not another shared drive.

WeTransfer moves big files. Dropbox syncs teams. ZipPigeon does one narrower job: get a sensitive package to a specific person, then end the access. Here is exactly where each fits.

Frequently asked questions

What is private file delivery?

It is a simple way to send sensitive files to the right person, with an access window, instead of leaving copies in email threads or shared folders.

Is ZipPigeon end-to-end encrypted?

ZipPigeon encrypts files in the browser before upload and stores encrypted file data. The security page explains what remains visible and what is still on the roadmap.

Can ZipPigeon read my files?

During normal delivery, ZipPigeon should not receive plaintext files or raw file keys. It still handles delivery details such as accounts, recipients, timestamps, and transfer status.

Do recipients need an account?

No. Use account access for people you know, secure links for guest access, or the anonymous send flow for a short-lived one-time handoff with tight limits.

How is ZipPigeon different from cloud storage?

Cloud storage is for ongoing collaboration. ZipPigeon is for sending a sensitive package to a specific person and closing access when the job is done.

How is ZipPigeon different from email attachments?

Email attachments spread into inboxes, backups, forwards, and downloads. ZipPigeon gives you a separate send flow with encryption, expiration, and recipient access.

Who is ZipPigeon for?

ZipPigeon is for legal, accounting, HR, consulting, agency, startup, security, and freelance teams that send sensitive files to people outside their usual workspace.

The next sensitive file deserves better than “see attached.”

Seal it, send it, and let it expire — free while we can sustain it.

Send a private file