Documentation (14 pages)
Getting Started
Send your first encrypted file in under a minute — no installation required.
Send a file (browser)
Open the homepage send module and:
- Drag your files or folders into the drop zone (or tap to browse).
- Share the generated room code (for example
U93DGU) or the link with the receiver. - When the receiver accepts, the files stream to them end-to-end encrypted.
In End-to-end mode, the relay only ever sees ciphertext (Transport-only mode is relay-carried). When the room closes, nothing is left on our side.
Receive a file (browser)
- Open the link you were given (a short link, or
/?join=<code>), or go to the homepage, choose Receive, and type the room code. - Accept the transfer — files save straight to your device.
Prefer the command line?
A Rust CLI lives alongside the web app, but there is no published release yet — no Homebrew formula, no Scoop bucket, no release binaries. If you want to build it from source, see Installation; the day the release lands, that page becomes the install guide.
What Happens Under the Hood
- Your files are split into chunks and encrypted on your device
- A hybrid ML-KEM-1024 + X25519 key exchange establishes a shared secret
- Each chunk is encrypted with AES-256-GCM (counter-based nonces)
- Chunks are sent through the relay to the receiver
- The receiver decrypts and reassembles the original files
- Each chunk is authenticated with an AES-GCM tag bound to its index; on the CLI lane a BLAKE3 Merkle tree adds whole-file verification
The relay server never sees your plaintext data.
Next Steps
- Sending in the Browser — The full browser transfer flow
- Security Model — How Tallow protects your files
- Installation — Build the CLI from source (release pending)