I built Veil: a small onion service for short-lived sharing without accounts or browser JavaScript.
What it does
- Tor only
- Free uploads expire after 24 hours (optional Monero extensions for longer retention)
- No accounts, no analytics cookies for tracking visitors
- Max ~5 MB
Three modes (be honest which you use)
- Already encrypted (recommended) — you encrypt locally first; Veil stores the bytes as received and never asks for your key.
- Your view key — text/image; server-side encryption. Veil handles plaintext and the key during upload/view. Not end-to-end.
- Generated view key — same trust model as 2; Veil creates a random key. Not end-to-end.
Modes 2 and 3 are convenience only. For anything sensitive, use mode 1.
Privacy posture (high level)
- Strict CSP, no JavaScript
- No application/nginx access logs of visitor IPs (ops/SSH/hosting logs still exist — details on the privacy page)
- Content rules + report link on live uploads
- Full limits and payment notes are on
/privacy
Onion (Tor Browser): http://veilju6lzn5p6jcxzaieo56pj3lmgrev5kv5vukny5smgaorerjtjnad.onion/
Happy to answer threat-model questions. Not trying to replace SecureDrop or OnionShare — different job (tiny sealed packets, short TTL, no install).