Absolute privacy
May·Secret is built around one fundamental principle: we cannot read your files. Not as a policy choice, but as a technical impossibility.
A zero-knowledge architecture
In a zero-knowledge architecture, the server only ever receives data it's mathematically unable to decrypt. Your files are encrypted in your browser, before they even reach the network. May Software holds no key that could give access to your data. Even under a court order, we can only hand over unreadable encrypted content.
How the encryption works
Generating your key pair (at signup)
When you sign up, your browser locally generates an asymmetric key pair. The public key is sent to the server to encrypt your future files. The private key never leaves your device in a readable form.
Protecting the private key with your password
Your private key is itself encrypted with a key derived from your password, using an industry-standard algorithm (Argon2id) deliberately made expensive to compute in order to resist brute-force attempts, including from specialized hardware. The server only ever stores that encrypted version — never your password in clear text, nor a fingerprint that could be used to recover it.
Encrypting each file
On every upload, a unique random symmetric key is generated for the file. The content is encrypted with an authenticated encryption algorithm, which guarantees both confidentiality and the detection of any tampering: a file modified afterwards is rejected on decryption rather than silently corrupted.
Protecting the file's key (asymmetric encryption)
The file's symmetric key is itself encrypted with your public key. Only your private key — which only you hold — can decrypt it. The server thus stores the file's key in encrypted form, without ever being able to use it.
Download and in-memory decryption
On download, your browser fetches the encrypted file, decrypts its key with your private key (held only in memory), then decrypts the file locally. The clear-text file never travels over the network. Your decrypted private key is never written to disk — it disappears when the tab is closed.
What May Software can and can't see
✕ We cannot see
- The content of your files
- The original name of your files
- The name of your folders
- Your private key
- Your password (nor its hash)
- Your files' encryption keys
✓ We can only see
- Your email address
- The size of your files
- The upload date
- The MIME type (image, PDF…)
- Your used storage quota
- Your subscription plan
Stateless authentication
Authentication relies on a digitally signed token, verified on every request without any session being stored server-side. An intercepted token still doesn't grant access to your files — you'd also need your decryption private key, which is never transmitted to the server.
Its lifetime is limited to your browsing session and it disappears when the tab is closed, reducing the exposure window if your browser were ever compromised.
Important consequence: losing your password
The guarantee of absolute confidentiality has a cost: if you forget your password, your files are unrecoverable. May Software has no private key recovery mechanism — that would be technically incompatible with a zero-knowledge architecture. Keep your password somewhere safe (a password manager is recommended).
Frequently asked questions about security
Can you really not read my files?
Can you really not read my files?
That's right. libsodium encryption happens in your browser before upload: we only ever receive and store already-encrypted data, and your private key never leaves your device.
Can I access my files from several devices (phone, new computer)?
Can I access my files from several devices (phone, new computer)?
Yes. Your private key, encrypted with your password, is synced with your account. On a new device, just sign in with your usual password: the key is then decrypted locally, just like on your other devices.
Where is my data hosted?
Where is my data hosted?
In France, at o2switch (Clermont-Ferrand), in compliance with GDPR.
Do you use recognized encryption standards?
Do you use recognized encryption standards?
Yes, libsodium, an open-source, widely audited cryptography library used by many privacy-focused services.
Are my file and folder names also encrypted?
Are my file and folder names also encrypted?
Yes, like file content, metadata (names, folder structure) is encrypted client-side before being stored.
Do you offer two-factor authentication?
Do you offer two-factor authentication?
Yes, email-based two-step verification is available to secure sign-in to your account.
What happens if I forget my password?
What happens if I forget my password?
Because encryption is end-to-end, no one — not even us — can decrypt your files without your password. Keep it safe or use a password manager.
Wondering who we are or what happens if the service shuts down? Check out our "Why trust May·Secret" page. For more technical detail, our Blog: encryption, GDPR, comparisons and guides by profession.
Ready to store your files with full confidentiality?