Skip to content
HexaTransfer
Back to blog
Comparisons & Alternatives

Mega vs HexaTransfer: Privacy and Encryption Compared

Head-to-head comparison of Mega and HexaTransfer privacy features, encryption implementation, data residency, and overall security approach.

Mega and HexaTransfer both use client-side encryption but target different workflows and sit in different jurisdictions. Mega is a New Zealand-based cloud storage platform with 20 GB free, AES-128 GCM encryption with RSA-2048 key exchange, and persistent accounts. HexaTransfer is a French ephemeral transfer service with 10 GB per transfer, AES-256-GCM encryption, 7-day expiration, and no account requirement. For long-term encrypted storage, Mega has the richer feature set. For one-off encrypted transfers without account overhead, HexaTransfer is simpler and stays within EU jurisdiction.

Encryption Details: AES-128 vs AES-256

Mega's client-side encryption uses AES-128 in CCM mode for file encryption and RSA-2048 for key exchange. The AES-128 choice has been defended by Mega as sufficient (128-bit AES remains computationally infeasible to brute-force). Critics note that AES-256 is the current industry standard. The Mega web client runs the encryption in JavaScript; desktop and mobile apps use native implementations.

HexaTransfer uses AES-256-GCM with PBKDF2 at 600,000 iterations for password-derived keys. The 256-bit key size matches current best practice (NIST SP 800-131A). Encryption happens in-browser via the Web Crypto API (SubtleCrypto.encrypt), which uses native platform implementations rather than pure JavaScript. This is faster and less vulnerable to timing attacks.

Trust Model Differences

Mega relies on user accounts with recovery keys. If you lose your password and your recovery key, your data is unrecoverable — which is the correct behavior for zero-knowledge but creates real support burdens. Mega has been accused historically of holding plaintext recovery capabilities via password change flows, with security researchers publishing concerns about specific protocol details.

HexaTransfer has no accounts, so there's no password reset mechanism to potentially abuse. The decryption key is either in the URL fragment or wrapped by a user-supplied password via PBKDF2. If you lose both, the file is unrecoverable — which matches the ephemeral transfer use case, where a 7-day expiration is going to delete the file anyway.

Jurisdiction and Data Residency

Mega is based in Auckland, New Zealand, with data centers in New Zealand, Netherlands, Canada, and other locations. New Zealand is a Five Eyes intelligence-sharing member, which concerns some privacy advocates. However, New Zealand's Privacy Act 2020 provides GDPR-equivalent protections, and the distributed hosting means EU users' files can route to Netherlands servers.

HexaTransfer hosts exclusively in France. No distributed global footprint, no Five Eyes involvement. GDPR applies directly. For EU users with strict data sovereignty requirements, the single-jurisdiction model is simpler to assess legally.

File Size, Storage, and Retention

Mega free tier offers 20 GB persistent storage with files retained indefinitely as long as you log in periodically (30-day idle suspension). Paid tiers offer up to 16 TB. File size per upload is effectively limited only by your quota.

HexaTransfer allows 10 GB per transfer with 7-day automatic expiration. No persistent storage — the service is purely for sending, not keeping. For a weekly 8 GB design delivery to clients, HexaTransfer works. For an archive of personal photos, Mega works and HexaTransfer doesn't.

Workflow Experience

Mega's web interface, desktop sync, and mobile apps provide a Dropbox-like experience with folders, versions, and sharing. You can have persistent shared folders with collaborators, set per-folder permissions, and maintain project structure over months.

HexaTransfer is deliberately single-purpose. Open the website, drop a file, get a link, send. No folders, no sync, no versions. The minimalism is the point — zero cognitive overhead, zero account management.

Comparison Matrix

| Feature | Mega | HexaTransfer | |---------|------|--------------| | Type | Persistent cloud storage | Ephemeral transfer | | Encryption | AES-128-CCM + RSA-2048 | AES-256-GCM + PBKDF2 | | Client-side encryption | Yes | Yes | | Free tier | 20 GB storage | 10 GB per transfer | | Max file size | Quota-limited | 10 GB | | Retention | Indefinite (30-day idle) | 7 days | | Account required | Yes | No | | Data location | NZ, NL, CA, others | France | | GDPR posture | Compliant | EU-resident | | Five Eyes exposure | Yes (NZ) | No | | Desktop apps | Yes | No | | Mobile apps | Yes | No (browser only) | | Folder sharing | Yes | No |

Security Audits and Transparency

Mega has published a source-available web client and commissioned third-party security audits. The 2022 academic paper "MEGA: Malleable Encryption Goes Awry" by ETH Zürich researchers identified five vulnerabilities in Mega's cryptographic protocol, all subsequently patched. The public response and fixes were prompt, which is the right behavior for a crypto service under scrutiny.

HexaTransfer's architecture is simpler (fewer protocols, no account recovery, no long-lived sessions), which reduces attack surface. The client code is inspectable in-browser. As a newer and narrower service, it hasn't been through the same level of academic scrutiny as Mega.

Business Model and Longevity

Mega's business model is freemium storage tiers, which generates revenue proportional to paid user counts. The service has been running since 2013 (originally as MEGA Limited, Kim Dotcom's successor to Megaupload). Longevity is reasonable.

HexaTransfer is a free service without paid tiers currently. Business model concerns for free services are legitimate — if the service isn't monetized, ensure it's sustainable before relying on it for business-critical flows. For one-off transfers, sustainability matters less than for archival storage.

When to Pick Each

Choose Mega for persistent encrypted cloud storage, team folder sharing, ongoing project archives, cross-device sync, and when you want a complete zero-knowledge cloud product. Accept the Five Eyes jurisdiction tradeoff for the feature richness.

Choose HexaTransfer for one-off encrypted transfers, EU-jurisdiction requirements, scenarios where accounts add friction (external deliveries, one-time recipients), and when 10 GB is enough. Accept the lack of persistent storage and collaboration features for the simplicity and jurisdictional focus.

Using Both

They're complementary rather than competitive. A privacy-focused individual might use Mega for ongoing personal cloud storage (photos, backups, documents they want to keep) and HexaTransfer for occasional encrypted sends to non-Mega recipients. The workflows don't overlap enough to create redundancy issues.

For a small business, Mega could serve as the internal collaboration vault while HexaTransfer handles external client deliveries. Clients don't need Mega accounts to receive HexaTransfer links, which reduces onboarding friction for one-time engagements.

Try it at hexatransfer.com — free, no account, 10 GB max.

Send large files securely with end-to-end encryption

Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.

Send a file