How it stays private

    Your data, encrypted
    before it leaves your browser.

    Every message you send is encrypted on your device using a key that only you and your phone possess. Dropr's servers never see your content — they only relay sealed data between your devices.

    How the key is shared.

    The encryption key never touches any server. It travels directly — from your laptop screen to your phone camera.

    Your computer

    Generates a unique key in your browser

    QR code

    Key embedded, never sent to a server

    Your phone

    Receives the same key via camera scan

    Your message “Hello!”

    a7f2c1…9e3b

    Decrypted “Hello!”

    Strong encryption, by default.

    Every session uses AES-256-GCM — a trusted standard used by financial institutions and governments worldwide. It guarantees both confidentiality and message integrity. No configuration needed.

    The server never holds the key.

    The encryption key exists only in your browser's memory. It's embedded in the QR code URL as a fragment — a part of the address that browsers never include in network requests. It never leaves your device.

    Four guarantees, every session.

    Confidentiality

    Only the devices in your session can read what you share. The key never touches any server.

    Integrity

    Every message carries a cryptographic tag. Any alteration in transit is detected and rejected.

    Ephemerality

    Keys live only in browser memory. Close the tab and they're gone — nothing is ever stored.

    Zero knowledge

    Dropr's servers relay encrypted data but can never read it. Your key is yours alone.

    Encrypted by default.
    Always.

    You don't need to configure anything. Every session is private from the first message.