ProtonURL
ProtonURL ProtonURL

Tool used to share information secret, private or non-private with a link whose content will be deleted on first reading.

protonURL is a service designed for the secure and confidential sharing of information (secret, private, or non-private) via a link.

The main features and characteristics of protonURL include:

  • Secure and confidential sharing.

  • End-to-end encryption (optional, by default your content is encrypted with a protonURL secret key). The content is encrypted with the AES-256-CBC algorithm. A different key and Initialization Vector (IV) are used for each content. The IV is stored separately from the encrypted data.

  • Single use: The content of the protonURL link is deleted upon the first reading or access. This feature is an important security measure to protect the confidentiality of the data and ensure it can only be viewed once, reducing the risk of leaks or misuse.

  • Automatic deletion:

    • The protonURL and its content are automatically and permanently deleted from their servers as soon as they are accessed.

    • There is a default automatic deletion policy for unaccessed links: they are deleted after 72 hours.

    • It is possible to modify the lifespan of the link in the advanced options. If the link is not accessed during the selected duration or within the default 72 hours, it will be permanently deleted.

  • No permanent storage: protonURL does not store shared data on its servers after it has been accessed. The data is temporarily stored on their servers only for the duration of the sharing link.

  • No tracking: protonURL does not store a copy of the shared data on its servers and does not track the activity of viewing sharing links. They do not keep any record of the shared content or of the people who have viewed the sharing links.

  • Secret key (optional): The user can activate an option to encrypt the content with a private key they define. This key is not saved by protonURL. It is crucial that the user saves this key and sends it to the recipient so that they can decrypt and display the content. Without this key, it will be impossible to retrieve the content. If a wrong key is used, the system will try to decrypt, the content will be displayed still encrypted, and then it will be deleted like a classic protonURL as soon as it is displayed.

  • Advanced options: Allow choosing the expiration duration of the link.

  • Secure servers in Europe: Encrypted data is stored on secure servers in Europe and is constantly monitored to ensure its security and confidentiality.

  • Proof of deletion: The service offers a "proof of deletion" that allows verifying the cryptographic trace of the deletion of data associated with a URL, either after access or upon expiration. By entering the URL, you can check this proof to ensure the confidentiality and integrity of the shared data.

  • Pre-filled links: It is possible to create protonURL links with the text field pre-filled using the prefilled parameter in the URL, whose content must be base64 encoded. This feature is intended for experienced users, and the base64 encoded pre-filled content is not encrypted. It should be used with care and only displayed to people who are already aware of the content or to whom this content is voluntarily sent, not to the public.

  • The service is particularly useful for avoiding sending passwords or sensitive content via email or SMS, as with protonURL, all that will remain in these inboxes is a link to content that no longer exists.

In summary, protonURL focuses on confidentiality, security, and the self-destruction of shared information after a single viewing and/or a limited period, using encryption and automatic deletion to ensure that data does not persist.