सामग्री पर जाएँ
HexaTransfer
ब्लॉग पर वापस
तुलना और विकल्प

फ़ाइल ट्रांसफर प्राइवेसी: कौन सी सेवा आपकी बेहतर सुरक्षा करती है

प्रमुख फ़ाइल ट्रांसफर सेवाओं का गहन प्राइवेसी विश्लेषण जिसमें डेटा संग्रह, ट्रैकिंग नीतियाँ, एन्क्रिप्शन और थर्ड-पार्टी डेटा शेयरिंग का परीक्षण है।

2026 में फ़ाइल ट्रांसफर प्राइवेसी के लिए सबसे मज़बूत सुरक्षा देती हैं: HexaTransfer (E2EE AES-256-GCM, कोई account नहीं, EU hosting), Proton Drive Share (OpenPGP E2EE, Swiss), Tresorit Send (XChaCha20-Poly1305, Swiss zero-knowledge), Internxt Send (libsodium on Storj, Spain), और OnionShare (कोई सर्वर ही नहीं)। प्राइवेसी पर सबसे कमज़ोर: WeTransfer (server-side encryption, analytics SDKs, Bending Spoons ownership), Dropbox Transfer (US-hosted, CLOUD Act exposure), और Google Drive sharing (account-tied ad profile)। प्राइवेसी पाँच axes पर rank होती है: encryption model, metadata handling, tracking, jurisdiction, और third-party data flows।

पाँच प्राइवेसी आयाम

Encryption model: server-side का अर्थ provider आपकी keys रखता है; end-to-end का अर्थ केवल आप और आपका recipient। Metadata handling: filename, size, sender IP, recipient IP, timestamps। Tracking: analytics SDKs, advertising cookies, Facebook Pixel, Google Analytics। Jurisdiction: GDPR-enforceable EU, Swiss FADP, US CLOUD Act exposure। Third-party data flows: सेवा advertisers, processors, या partners के साथ क्या share करती है। वास्तव में private सेवा सभी पाँच पर अच्छा score करती है।

HexaTransfer: डिज़ाइन से न्यूनतम डेटा संग्रह

HexaTransfer सेवा function के लिए required minimum collect करता है। कोई account नहीं, कोई ईमेल नहीं, कोई password नहीं, कोई identity नहीं। सर्वर ciphertext (browser-side AES-256-GCM एन्क्रिप्टेड), एक file size, और एक session identifier देखता है जो आपके browser tab के साथ rotate करता है। कोई Google Analytics नहीं, कोई Facebook Pixel नहीं, कोई advertising SDK नहीं। Sender IP को rate-limiting के लिए briefly log किया जाता है फिर truncate। Filenames client-side एन्क्रिप्ट होते हैं और सर्वर को opaque रहते हैं। EU hosting सब कुछ GDPR Articles 5-22 के तहत enforceable rights के साथ रखता है।

Proton Drive: Account के साथ Zero-Knowledge

Proton को account चाहिए (email या existing Proton Mail inbox से tied)। Account एक ledger entry बनाता है, लेकिन बाकी सब zero-knowledge है: files, filenames, thumbnails सब OpenPGP (Curve25519 ECC + AES-256-CFB session keys) से device छोड़ने से पहले एन्क्रिप्ट होते हैं। Proton ने वर्षों से transparency reports प्रकाशित की हैं जो दर्शाती हैं किसी भी authority को कोई file नहीं सौंपी गई (क्योंकि zero-knowledge का मतलब वे कर भी नहीं सकते)। Swiss jurisdiction, SEC Consult द्वारा ऑडिट, open-source clients। HexaTransfer की तुलना में trade-off: account tying — लेकिन long-term file management मज़बूत।

Tresorit Send: Auditable और Private

Tresorit Send content encryption के लिए XChaCha20-Poly1305 का उपयोग करता है और audit logs को भी खुद एन्क्रिप्ट करता है, इसलिए Tresorit admins भी नहीं पढ़ सकते कि किसने क्या access किया। Privacy policy कोई advertising partners और डेटा का secondary use नहीं बताती। Swiss parent (Swiss Post since 2021), EU hosting (Germany, Ireland, Switzerland)। Free Send tier पर 5 GB के लिए email address चाहिए; paid Business tier अधिक privacy controls और custom data residency देता है।

Internxt Send: Spanish, Decentralized

Internxt का Send product Storj decentralized storage network पर चलता है। प्रत्येक file libsodium secretbox (XSalsa20-Poly1305) से अपलोड से पहले एन्क्रिप्ट होती है, फिर independent Storj nodes में 80 chunks में distribute होती है (reconstruction के लिए 29 पर्याप्त)। कोई single node पूरी file नहीं रखता; प्रत्येक node केवल ciphertext देखता है। Spanish legal jurisdiction (GDPR)। Internxt transparency reports और open-source clients प्रकाशित करता है। Bandwidth centralized services की तुलना में multi-node coordination के कारण धीमा है।

OnionShare: Privacy की चरम सीमा

OnionShare web service नहीं, desktop application है। यह आपकी machine पर एक ephemeral Tor hidden service spawn करता है; recipient आपके laptop से सीधे Tor के through download करता है। कोई third-party server कभी file नहीं छूता। आपका IP Tor के पीछे hide है; recipient का IP Tor के पीछे। Minimal metadata क्योंकि कोई central log नहीं। पत्रकारिता source protection, activist work, और adversarial threat models के लिए डिज़ाइन। व्यावहारिक सीमाएँ: laptop online रहना चाहिए, bandwidth Tor पर 10-20 Mbps typical।

WeTransfer: वे क्या Collect करते हैं

WeTransfer की privacy policy sender और recipient email, file metadata, IP addresses, browser fingerprint, device identifiers, और analytics events collection प्रकट करती है। Third-party processors में Google Analytics, Facebook Pixel, Adobe Analytics, और DPA में नाम अन्य शामिल हैं। Bending Spoons ने 2024 में WeTransfer अधिग्रहित किया और product analytics और advertising के लिए data use विस्तृत किया। Encryption server-side AES-256 at rest plus TLS 1.3 in transit है; WeTransfer staff और admin access वाले partners आपकी files पढ़ सकते हैं।

Dropbox Transfer: US-Based Exposure

Dropbox San Francisco में US-headquartered है, जो इसे CLOUD Act (Clarifying Lawful Overseas Use of Data, 2018) के तहत रखता है। US authorities Dropbox को globally कहीं भी रखा गया data produce करने के लिए compel कर सकती हैं, जिसमें EU data residency tiers भी शामिल। Dropbox के transparency reports प्रति वर्ष सैकड़ों से हज़ारों law enforcement requests और partial compliance दर्शाते हैं। Encryption server-side AES-256 at rest है; Dropbox keys रखता है। GDPR-regulated data flows के लिए यह laws का conflict बनाता है।

Google Drive Sharing: Account-Tied

Google Drive sharing transfer service नहीं है — file आपके Google Drive में Google के standard content policy के तहत रहती है। Google CSAM (mandatory), copyright infringement, और (ToS के अनुसार) "safety" के लिए content scan करता है। File आपके Google account से tied है जो आपके ad profile, search history, Android device fingerprint, YouTube history, और Gmail corpus से connected है। Technically आपके और recipient के बीच private, लेकिन Google का design द्वारा full access है।

तुलना तालिका

| सेवा | एन्क्रिप्शन | Metadata | Tracking | Jurisdiction | |---|---|---|---|---| | HexaTransfer | E2EE AES-256-GCM | Minimal | कोई नहीं | EU (GDPR) | | Proton Drive | E2EE OpenPGP | Account-tied | कोई नहीं | CH | | Tresorit Send | E2EE XChaCha20-Poly1305 | Encrypted | कोई नहीं | CH | | Internxt Send | E2EE libsodium | Minimal | कोई नहीं | ES (GDPR) | | OnionShare | TLS over Tor | कोई नहीं | N/A | Local | | WeTransfer | Server-side | Full collection | GA, FB Pixel | US (on AWS) | | Dropbox Transfer | Server-side | Full collection | Multiple SDKs | US | | Google Drive | Server-side | Ad-profile tied | Google stack | US |

Filename और Metadata Leakage

Filenames metadata हैं। "Q4_2025_layoff_list.xlsx" catastrophically leak होता है भले ही bytes encrypted रहें। HexaTransfer, Proton Drive, और Tresorit filenames एन्क्रिप्ट करते हैं। WeTransfer, Dropbox, और Google नहीं। File size भी context leak करता है: 2.3 MB .pdf "document" है, 6 GB .mov "video export" है। कोई encryption layer इसे perfectly नहीं छुपाता, लेकिन 10 MB increments पर manual padding basic size-based profiling disrupt करती है।

Third-Party Processor का प्रश्न

प्रत्येक सेवा third-party processors (hosting, payment, email) का उपयोग करती है। DPA (Data Processing Agreement) पढ़ें। देखें: named sub-processors, उनके locations, contract obligations, breach notification timelines। EU-only sub-processor lists वाली EU-hosted services सबसे clean हैं। DPDP Act 2023 के तहत, भारतीय data fiduciaries को significant data fiduciary categories के लिए data localization requirements हो सकती हैं — US-based analytics या advertising SDKs (Google Analytics, Mixpanel, Facebook Pixel) वाली सेवाएँ behavioral data उन processors को leak करती हैं।

व्यावहारिक प्राइवेसी Stack

Sensitive one-off sends के लिए HexaTransfer (E2EE, कोई account नहीं, कोई tracking नहीं)। E2EE के साथ ongoing team collaboration के लिए Proton Drive। State actors या network adversaries वाले threat model के लिए OnionShare। Confidential किसी भी चीज़ के लिए WeTransfer, Dropbox, या Google कभी नहीं। Non-sensitive कारणों से server-side service ज़रूरी हो (size, recipient familiarity) तो age या VeraCrypt से pre-encrypt करें। Links एक channel पर और passwords दूसरे (Signal) पर share करें।

hexatransfer.com पर आज़माएं — मुफ्त, बिना अकाउंट, 10 GB तक।

एंड-टू-एंड एन्क्रिप्शन के साथ बड़ी फ़ाइलें सुरक्षित रूप से भेजें

एंड-टू-एंड एन्क्रिप्शन के साथ 10 GB तक की फ़ाइलें मुफ़्त में ट्रांसफ़र करें। अकाउंट की आवश्यकता नहीं। अपलोड से पहले आपकी फ़ाइलें ब्राउज़र में एन्क्रिप्ट की जाती हैं — कोई और उन्हें पढ़ नहीं सकता।

फ़ाइल भेजें