← Back to FileX Radical transparency

How FileX Send works — and what we can and can't see

Every other tool in FileX runs entirely in your browser, so the honest answer to "what can you see?" is "nothing." FileX Send is the one exception, and it deserves a straight answer rather than a marketing claim. A link you share has to keep working later, possibly on someone else's device — which means the file has to rest somewhere in between.

This page describes exactly what that costs you. The short version: your file is encrypted in your browser before any upload begins, the decryption key never leaves your device, and we store ciphertext we have no way to read.

The key is never transmitted. It lives in the part of the link after the # — a URL fragment, which browsers do not send to any server as part of an HTTP request. We receive the routing ID before the # and nothing after it.

What we cannot see

What we do see

Being specific matters more than sounding reassuring. For every transfer we hold:

We do not build a profile from any of this, and there is no account to attach it to — see the privacy policy for how the rest of the site handles data.

Retention policy

Every link has a deadline, set when you upload it and enforced on every download request:

TierMax sizeLink expiryDownloadsPassword
Free10 MB24 hours1 — self-destructs
Pro & Lifetime250 MB7 daysUnlimited until expiry
Team2 GB30 daysUnlimited until expiryRequired

Deletion is not a scheduled sweep that might lag: the moment a link is expired or has been consumed, that request itself triggers removal of both the encrypted object and its metadata record together. A Free-tier link is gone immediately after its single download. Nothing is archived, backed up for recovery, or retained after expiry.

Free-tier senders are also limited to 3 uploads per day per IP address, enforced on our side rather than only in the browser. This exists so Send cannot be turned into a free file-distribution network — it is an abuse control, not a usage meter.

Abuse and takedown

Because we cannot read what is stored, we cannot proactively screen content. What we can do is act on a report: given a link, we can delete the stored object immediately.

To report abuse, email abuse@cybxsan.com with the full link. Please do not include the part after the # — we do not need it, and sending it would hand us the decryption key.

FileX is operated by CybXSan from India, and we respond to valid legal process under Indian law. Note what that means in practice: we can produce the ciphertext and the metadata listed above, and nothing else. We cannot decrypt a file, because we have never held the key.

How FileX Send compares

The distinction that matters is not "is it encrypted" — nearly everything is encrypted in transit and at rest. It is who holds the key. If the provider does, then their staff, a breach of their systems, or a legal order can expose your file.

Service Encrypted client-side Server can read content Max retention Requires account Open format
FileX Send Yes No 30 days (Team) No Yes — documented
WeTransfer No Yes Varies by plan Not on free tier No
Bitwarden Send Yes No 31 days Yes — to send Yes — open-source
Firefox Send Discontinued by Mozilla in 2020 after sustained malware abuse. Listed because it is still widely recommended — it no longer exists.

Third-party details reflect each service's publicly documented behaviour and can change without notice — verify against their current documentation before relying on them.

If this trade-off isn't right for you

Sometimes the honest answer is "don't use this tool." If you would rather nothing of yours ever rests on our infrastructure, two fully local alternatives produce a file you can deliver over any channel you already trust:

Send a file securely →