Privacy
OurStick has no accounts and no servers of its own that see your files. A stick's files go from the sender's computer to the receiver's, encrypted on the sender's computer with a key that only the link carries.
How it is encrypted
Each stick has its own key, made at random on your computer when you make the stick. It is kept in your computer's own safe for secrets (the Keychain on a Mac, Credential Manager on Windows, the keyring on Linux) and leaves it only inside the link you send.
- The files. Every file is encrypted on your computer, in pieces of 64 KB, before it is sent (XChaCha20-Poly1305). Each piece is sealed so that it cannot be changed, cut off, reordered or swapped for a piece of another file without the receiver noticing.
- The list of what is on the stick. The names of files and folders, their sizes and dates are encrypted the same way. Without the link, nobody sees what a stick holds.
- What is current. Each new version of the stick is signed by your computer (Ed25519). A receiver accepts only versions you signed, never an older one, so nobody can pass off another list or an old one as yours.
- On the way. The connection between the two computers is encrypted too (QUIC with TLS 1.3), and the receiver checks that it is talking to the computer the link names. A relay, when one is needed, passes on data it cannot read.
- The receiver's reports of how far they have come are encrypted with the stick's key and signed by the receiver, so only you can read them and nobody can send them in their name.
What this does not hide: anyone who has the link can read the stick, and can pass it on. Someone watching the network can see that two computers exchange data, how much and when, never what. The encryption has not yet been reviewed by an independent auditor.
What passes through others
OurStick uses iroh, a networking library made by n0. To find each other, the computers ask n0's public discovery service and relays where the other one can be reached. When two computers cannot reach each other directly, the encrypted data goes through one of n0's relays. These see the computers' network addresses and identities, when they connect and how much data passes, never what it is.
A sharing link
Everything in a link after “#” is the stick: its key, and where OurStick finds the sender (their computer's identity and network addresses). Browsers never send that part to any website, so when a link is opened in a browser, this website and its host see only that someone opened a link, not whose or which. Anyone who has the link can read the stick and sees the sender's addresses. Like every address you open, the whole link stays in your browser's history, which your browser may sync to your other devices.
This website
This site sets no cookies, has no analytics, and loads nothing from other sites. It is served by Cloudflare, which sees the address of whoever visits it and which page, as every web host does. It never sees what comes after “#” in a sharing link: the stick's key and where to find the sender.
What a sender sees
The OurStick app tells a sender how far each computer that has their stick has got (“A Mac has all of it, up to date”), never that computer's name unless its user writes one, and never what is missing from it.