End-to-end encryption — when should you use it?
What you gain and what you give up with end-to-end encryption, so you can choose for each transfer.
With end-to-end encryption (E2E), files are encrypted in your browser before they're uploaded, and only the recipients can open them. The keys are created on and stay on your phones, not with us, so we can't read the files either.
Without E2E, files are also encrypted, both in transit and while they're stored with us. The difference is who holds the key. E2E requires Pro for the sender.
Advantages
- No one but the recipients can read the files. Not us, and not anyone who might gain access to our servers.
- The key is locked to your phone. On iPhone it's also locked with Face ID.
- You confirm who you're sending to. Before the first encrypted transfer, you and the recipient verify each other's keys. If a recipient's key changes later, nothing is sent to them until you've verified again.
Drawbacks and what you give up
- Files aren't virus-scanned. We can't open them, so we can't check them. The recipient is told so on the download page. The browser normally blocks program files disguised as documents.
- Every recipient needs an account and keys. If a recipient has no keys, or their key isn't verified, you're told before you send, and that person doesn't get the files. If none of the recipients have keys, nothing is sent.
- You can't send to just anyone. Each recipient has to be verified once, by one of you scanning the other's key with your phone, or by getting the link by text message.
- Lose the key, lose the files. We have no copy. Without a backup or another phone with the keys, you have to create new ones, and whatever was encrypted for the old ones becomes unreadable to you.
- Large files in Firefox and Safari. The file is decrypted in the browser. If it's too big for the browser, the recipient has to use Chrome or Edge.
- Video, audio and PDF don't play directly. They have to be decrypted in the browser first.
- Encrypted folders have fewer ways to share. A share link doesn't open the files, only signed-in members with keys can. The folder can't receive files via a link, so Request files doesn't work into an encrypted folder.
When we recommend it
- Client documents under confidentiality, health information and anything else no outsider should be able to read.
- Regular recipients whose keys you've verified.
- When the recipient trusts the sender and doesn't need the virus scan.
When you can skip it
- The recipient has no account, or you're sending to someone for the first time.
- You're sending files from someone you don't know, where virus scanning matters more than us not being able to read them.
- Photos and videos meant to be shown with a share link.
Password, verify recipient and burn on delivery give good protection without E2E as well. See Send sensitive files securely.
How to turn it on
- Open Account → Profile on your computer. Under End-to-end encryption (E2E) you'll see a QR code.
- Scan the code with your phone's camera and open the link (in Safari on iPhone). Log in with the same account if your phone asks you to.
- Tap Make keys on this phone. On iPhone, tap Create keys with Face ID, which requires iOS 18 or later. Your computer unlocks right away.
- Tap Make a backup. Keep the file safe, and store its password in your password manager.
- Verify your recipients: tap Show my key, and let the other person scan the code with their phone. Once per person.
- On the send page, turn on End-to-end encryption (E2E) under Options before you send.
On another computer, scan the QR code with the phone that has the keys, and choose how long the key should be remembered there. If you want to encrypt everything by default, turn on End-to-end encryption by default under Account → Profile.
Read more: Send sensitive files securely, Security and privacy and Shared folders.