Skip to content
HexaTransfer
Back to blog
Comparisons & Alternatives

File Transfer Link Expiration Policies Compared

Compare file transfer link expiration policies across services, including auto-deletion timelines, customizable expiry, and download limits.

Link expiration policies range from three days to permanent across major file transfer services. WeTransfer auto-deletes free-tier files after 7 days; Smash lasts 14 days by default and up to 30 on paid plans; SwissTransfer offers 1–30 days; Dropbox Transfer expires after 7 days unless extended to 90. Download caps vary too: free WeTransfer allows unlimited downloads within the window, while some services cap at a single recipient. HexaTransfer sets a 7-day default with no download count limits and automatic secure deletion thereafter.

Why Short Expiration Is a Security Feature, Not a Limitation

Expiration windows are a form of automatic data minimization under GDPR Article 5(1)(e) (storage limitation principle). The shorter a file sits on a server, the smaller the exposure window for credential theft, subpoena, or misconfigured bucket incidents. The March 2023 ToddyCat APT campaign specifically targeted long-lived file share URLs harvested from compromised mailboxes — a risk that evaporates when links self-destruct.

For regulated industries, expiration also simplifies records management. HIPAA's Security Rule doesn't prescribe a retention period for transmission copies of ePHI, but HHS guidance treats ephemeral copies differently from stored records. A link that dies in 7 days is much easier to defend as ephemeral than one that lives for a year.

WeTransfer: 7 Days Free, 1 Year Pro, Permanent Portals

WeTransfer's free tier holds files for 7 days. The Pro plan extends this to 1 year, and Premium offers indefinite retention for portal links. There's no per-download limit — anyone with the URL can grab the file as many times as they want until expiration. Files top out at 2 GB free, 200 GB Pro.

The downside is that their "permanent" portal links create a standing target. If a recipient's inbox gets compromised, that link is a liability until someone manually revokes it. WeTransfer added a password option in 2019, but it's optional and often skipped.

Smash: Customizable 1–30 Days With Granular Controls

Smash takes the most flexible approach. Free users get 14 days; Team plans allow 1–30 day windows set at upload time. Smash also offers per-recipient tracking: you can see who downloaded and when, and revoke access mid-flight. Files can be up to 2 GB free or unlimited on paid plans.

This granularity matters for contract negotiations. Send a draft on Monday with a Friday expiration, and the link dies before the weekend without you remembering to clean up. The French data protection angle (OVH hosting, SecNumCloud-aligned) doesn't change expiration, but it does layer jurisdictional minimization on top of temporal minimization.

SwissTransfer: 1 to 30 Days, No Account Required

SwissTransfer, run by Infomaniak, lets you pick 1, 7, 15, or 30 days at upload. No account needed. The 50 GB file size cap is the largest of the free services. Expiration is strict — files are permanently deleted from Swiss data centers at the chosen time, with no grace period.

The service added optional password protection and download notifications in 2023. Expired links return a 410 Gone response, which is semantically correct and avoids leaking the fact that a file ever existed at that URL.

Dropbox Transfer: 7 Days Free, 90 Days Paid

Dropbox Transfer (distinct from Dropbox sharing) defaults to 7 days and maxes at 90 days on paid tiers. File size caps hit 2 GB free and 100 GB on Dropbox Professional. Expiration is per-transfer, not per-file, so you can't set different lifetimes for items in the same bundle.

Dropbox logs expiration events in the admin audit trail, which helps enterprise customers demonstrate GDPR Article 32 controls. Regular Dropbox sharing links, by contrast, never expire unless manually revoked — a frequent source of accidental long-term exposure when employees leave.

Pixeldrain, Wormhole, and Other Niche Players

Pixeldrain, a Dutch service, keeps files for 180 days by default, which is unusually long for a free tier. Wormhole, built on magic-wormhole protocol principles, offers 24-hour expiration and client-side encryption — opposite philosophy, much tighter window.

Firefox Send (discontinued 2020) pioneered the combination of short expiry (up to 7 days) plus download limits (up to 100) plus client-side encryption. Its DNA lives on in open-source forks and services like HexaTransfer that adopted the same principles.

HexaTransfer: 7-Day Default, Deleted Means Deleted

HexaTransfer sets a 7-day expiration, after which files are cryptographically erased (the decryption key was never on the server to begin with, but the ciphertext gets securely overwritten). There's no download count cap in the current free tier — recipients can download as many times as needed within the window. No account required, 10 GB file size limit.

The architecture uses AES-256-GCM for file encryption, with the key embedded in the URL fragment (after the #), meaning the server never sees it. Expiration deletion therefore involves destroying the ciphertext; the plaintext was never reconstructable server-side regardless.

Comparison at a Glance

| Service | Default Expiry | Max Expiry | File Size Cap | Download Limits | |---------|---------------|------------|---------------|-----------------| | WeTransfer Free | 7 days | 7 days | 2 GB | Unlimited | | WeTransfer Pro | 7 days | 1 year | 200 GB | Unlimited | | Smash Free | 14 days | 14 days | 2 GB | Unlimited | | Smash Team | 14 days | 30 days | Unlimited | Tracked | | SwissTransfer | 30 days | 30 days | 50 GB | Configurable | | Dropbox Transfer | 7 days | 90 days | 100 GB | Unlimited | | HexaTransfer | 7 days | 7 days | 10 GB | Unlimited |

Matching Expiration to Use Case

For an invoice you want the recipient to pay within a week, 7 days is perfect — it creates a natural deadline. For a contract under negotiation that may take three rounds of redlines, 30 days is more practical. For a one-time photo share with a client, 24 hours is plenty.

Resist the temptation to always pick the longest window "just in case." The longer the link lives, the more places it ends up: forwarded emails, Slack channels, screenshots, password managers. Short expiration forces recipients to act promptly and reduces the blast radius of any future breach. If you genuinely need persistent access, use a real cloud storage solution with identity-based access control, not an ephemeral transfer link.

Download Counters as a Second Line of Defense

A few services combine expiration with download counters. Set a file to expire in 7 days OR after 3 downloads, whichever comes first. This mitigates the scenario where a legitimate recipient downloads once, the link ends up on a phishing page, and attackers grab a fourth copy. If the counter is at zero, the link is dead.

HexaTransfer currently uses time-only expiration, which matches the majority of the market. For download-count enforcement, Smash Team and Dropbox Transfer Professional are the main options.

Try it at hexatransfer.com — free, no account, 10 GB max.

Send large files securely with end-to-end encryption

Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.

Send a file