[Self] Veil — Tor-only, no-JS ephemeral file/note drop (24h free)

I built Veil: a small onion service for short-lived sharing without accounts or browser JavaScript.

What it does

  • Tor only
  • Free uploads expire after 24 hours (optional Monero extensions for longer retention)
  • No accounts, no analytics cookies for tracking visitors
  • Max ~5 MB

Three modes (be honest which you use)

  1. Already encrypted (recommended) — you encrypt locally first; Veil stores the bytes as received and never asks for your key.
  2. Your view key — text/image; server-side encryption. Veil handles plaintext and the key during upload/view. Not end-to-end.
  3. Generated view key — same trust model as 2; Veil creates a random key. Not end-to-end.

Modes 2 and 3 are convenience only. For anything sensitive, use mode 1.

Privacy posture (high level)

  • Strict CSP, no JavaScript
  • No application/nginx access logs of visitor IPs (ops/SSH/hosting logs still exist — details on the privacy page)
  • Content rules + report link on live uploads
  • Full limits and payment notes are on /privacy

Onion (Tor Browser): http://veilju6lzn5p6jcxzaieo56pj3lmgrev5kv5vukny5smgaorerjtjnad.onion/

Happy to answer threat-model questions. Not trying to replace SecureDrop or OnionShare — different job (tiny sealed packets, short TTL, no install).

I think you should use JS for browser encryption.

I deliberately went the no JS route, to appeal to the audience that would never allow JS in the browser, but perhaps it could be done on a separate page with JS. Thanks for the suggestion.