File Transfer Privacy: Which Services Protect You Best
In-depth privacy analysis of major file transfer services examining data collection, tracking policies, encryption, and third-party data sharing.
For file transfer privacy in 2026, the strongest protections come from HexaTransfer (E2EE AES-256-GCM, no account, EU hosting), Proton Drive Share (OpenPGP E2EE, Swiss), Tresorit Send (XChaCha20-Poly1305, Swiss zero-knowledge), Internxt Send (libsodium on Storj, Spain), and OnionShare (no server at all). The weakest on privacy are WeTransfer (server-side encryption, analytics SDKs, Bending Spoons ownership), Dropbox Transfer (US-hosted, CLOUD Act exposure), and Google Drive sharing (account-tied ad profile). Privacy ranks on five axes: encryption model, metadata handling, tracking, jurisdiction, and third-party data flows.
The Five Privacy Dimensions
Encryption model: server-side means the provider holds your keys; end-to-end means only you and your recipient do. Metadata handling: filename, size, sender IP, recipient IP, timestamps. Tracking: analytics SDKs, advertising cookies, Facebook Pixel, Google Analytics. Jurisdiction: GDPR-enforceable EU, Swiss FADP, US CLOUD Act exposure. Third-party data flows: what the service shares with advertisers, processors, or partners. A genuinely private service scores well on all five.
HexaTransfer: Minimal Data Collection by Design
HexaTransfer collects the minimum required for the service to function. No account means no email, no password, no identity. The server sees ciphertext (AES-256-GCM encrypted client-side), a file size, and a session identifier that rotates with your browser tab. No Google Analytics, no Facebook Pixel, no advertising SDKs. Sender IP is logged briefly for rate-limiting then truncated. Filenames encrypt client-side and stay opaque to the server. EU hosting puts everything under GDPR Articles 5-22 with enforceable rights.
Proton Drive: Zero-Knowledge With an Account
Proton requires an account (email or tied to an existing Proton Mail inbox). The account itself creates a ledger entry, but everything else is zero-knowledge: files, filenames, thumbnails all encrypt with OpenPGP (Curve25519 ECC + AES-256-CFB session keys) before leaving your device. Proton has published transparency reports for years showing zero files ever produced to authorities. Swiss jurisdiction, audited by SEC Consult, open-source clients. The trade-off vs HexaTransfer: account tying, but stronger long-term file management.
Tresorit Send: Auditable and Private
Tresorit Send uses XChaCha20-Poly1305 for content encryption and encrypts audit logs themselves, so even Tresorit admins can't read who accessed what. Privacy policy states no advertising partners and no secondary use of data. Swiss parent (Swiss Post since 2021), EU hosting (Germany, Ireland, Switzerland). The free Send tier at 5 GB requires an email address; the paid Business tier offers more privacy controls including custom data residency.
Internxt Send: Spanish, Decentralized
Internxt's Send product runs on Storj, a decentralized storage network. Each file encrypts via libsodium secretbox (XSalsa20-Poly1305) before upload, then splits into 80 chunks distributed across independent Storj nodes (29 sufficient for reconstruction). No single node has a full file; every node sees only ciphertext. Spanish legal jurisdiction (GDPR). Internxt publishes transparency reports and open-source clients. Bandwidth is slower than centralized services due to multi-node coordination.
OnionShare: The Privacy Extreme
OnionShare is a desktop application, not a web service. It spawns an ephemeral Tor hidden service on your machine; the recipient downloads through Tor directly from your laptop. No third-party server ever touches the file. Your IP hides behind Tor; the recipient's IP hides behind Tor. Minimal metadata because there's no central log. Designed for journalism source protection, activist work, and adversarial threat models. Practical limits: laptop must stay online, bandwidth capped by Tor at 10-20 Mbps typical.
WeTransfer: What They Collect
WeTransfer's privacy policy discloses collection of sender and recipient email, file metadata, IP addresses, browser fingerprint, device identifiers, and analytics events. Third-party processors include Google Analytics, Facebook Pixel, Adobe Analytics, and others named in their DPA. Bending Spoons acquired WeTransfer in 2024 and has expanded data use for product analytics and advertising. Encryption is server-side AES-256 at rest plus TLS 1.3 in transit; WeTransfer staff and partners with admin access can read your files.
Dropbox Transfer: US-Based Exposure
Dropbox is US-headquartered in San Francisco, which places it under the CLOUD Act (Clarifying Lawful Overseas Use of Data, 2018). US authorities can compel Dropbox to produce data held anywhere globally, including EU data residency tiers. Dropbox's transparency reports show hundreds to thousands of law enforcement requests per year with partial compliance. Encryption is server-side AES-256 at rest; Dropbox holds the keys. For GDPR-regulated data flows, this creates conflict of laws.
Google Drive Sharing: Account-Tied
Google Drive sharing isn't really a transfer service; it leaves the file in your Google Drive under Google's standard content policy. Google scans content for CSAM (mandatory), copyright infringement, and (per ToS) "safety." The file is tied to your Google account, which is connected to your ad profile, search history, Android device fingerprint, YouTube history, and Gmail corpus. Technically private between you and recipient, but Google has full access by design.
Comparison Matrix
| Service | Encryption | Metadata | Tracking | Jurisdiction | |---|---|---|---|---| | HexaTransfer | E2EE AES-256-GCM | Minimal | None | EU (GDPR) | | Proton Drive | E2EE OpenPGP | Account-tied | None | CH | | Tresorit Send | E2EE XChaCha20-Poly1305 | Encrypted | None | CH | | Internxt Send | E2EE libsodium | Minimal | None | ES (GDPR) | | OnionShare | TLS over Tor | None | N/A | Local | | WeTransfer | Server-side | Full collection | GA, FB Pixel | US (on AWS) | | Dropbox Transfer | Server-side | Full collection | Multiple SDKs | US | | Google Drive | Server-side | Ad-profile tied | Google stack | US |
Filename and Metadata Leakage
Filenames are metadata. "Q4_2025_layoff_list.xlsx" leaks catastrophically even if the bytes stay encrypted. HexaTransfer, Proton Drive, and Tresorit encrypt filenames. WeTransfer, Dropbox, and Google do not. File size leaks context too: a 2.3 MB .pdf is "document," a 6 GB .mov is "video export." No encryption layer hides this perfectly, but padding to 10 MB increments (manually before upload) disrupts basic size-based profiling.
The Third-Party Processor Question
Every service uses third-party processors (hosting, payment, email). Read the DPA (Data Processing Agreement). Look for: named sub-processors, their locations, contract obligations, breach notification timelines. EU-hosted services with EU-only sub-processor lists are cleanest. Services using US-based analytics (Google Analytics, Mixpanel, Amplitude) or advertising (Facebook Pixel, Google Ads) leak behavioral data to those processors. Privacy-focused services explicitly avoid this.
Practical Privacy Stack
Use HexaTransfer for sensitive one-off sends (E2EE, no account, no tracking). Use Proton Drive for ongoing team collaboration with E2EE. Use OnionShare when your threat model includes state actors or network adversaries. Never use WeTransfer, Dropbox, or Google for anything confidential. Pre-encrypt with age or VeraCrypt if you must use a server-side service for non-sensitive reasons (size, recipient familiarity). Share links over one channel and passwords over a second (Signal).
Try it at hexatransfer.com — free, no account, 10 GB max.
Send large files securely with end-to-end encryption
Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.
Send a file