Send a big file from your phone. Straight to theirs.
Pick a file, get a link, send the link however you like. When your friend opens it, the file travels from your phone to theirs. No upload to a cloud, no account, no size limit beyond what your phones can hold.
The Android app and receiving in the browser are in development. The protocol, the servers and the command-line tools are finished and open source.
Three steps, one link.
-
Pick a file
Your phone makes a random key and a link that carries it. Nothing is uploaded; the file stays where it is.
-
Send the link
Text it, email it, show the QR code. Anyone who opens the complete link, and only them, can receive the file.
-
It crosses directly
Your friend's phone connects to yours and the file streams between them, sealed with the key from the link.
The sender decides who gets the file, and for how long.
Password on the link
Folded into the encryption key itself, so the server has nothing to check and your phone does the checking.
Approve each download
See that someone is asking before a single byte leaves your phone, and say no if it isn't who you expected.
Expiry and stop
Limit a link to a number of downloads or a span of time, or stop sharing at any moment. The link dies instantly.
Relay only
Normally the two phones connect directly and learn each other's address. Turn this on and yours is never revealed.
What this server sees
The key is the part of the link after the #. Browsers never send that part to any server, so it stays between the two phones. Everything the server relays is encrypted with it.
- The fileNever. It moves phone to phone.
- The file's name or sizeNever. They're encrypted too, and padded so even the length tells nothing.
- The key or passwordNever. The key lives after the #; the password is checked by your phone, not by us.
- What it does seeThat two phones want to meet, and their addresses, for the few seconds it takes to introduce them.
Roughly one connection in ten hits a network that won't allow a direct path. Then the encrypted stream is relayed through Cloudflare's TURN service, which can't read it either. The full picture is in the privacy policy and in the protocol specification.
From the command line, on any computer.
The same protocol the phone app will speak, as two small tools. Install with Go, send from one machine, receive on another.
# install
go install github.com/gabeazar/latchway/cmd/latchway-send@latest
go install github.com/gabeazar/latchway/cmd/latchway-receive@latest
# on your machine: prints a link and waits for one download
$ latchway-send holiday.mp4
https://latchway.app/s/…#…
# on theirs
$ latchway-receive 'https://latchway.app/s/…#…'
Receiving holiday.mp4 (2.1 GiB)
Saved holiday.mp4
Add --password, --approve, --downloads 3, --expire 2h or --relay-only to the sender. Both tools take --rendezvous to use your own server.
Open source, GPL-3.0
Every piece, from the phone app to this server, is in one repository with its specification and test vectors. Read it, build it, audit it.
Run your own
The rendezvous is a single Go binary or a free Cloudflare Worker. Point the app at your server from its settings and this one is out of the picture.