Temporary by design

A place between here and there.

Scapuff lets you leave a file, note, or link in a temporary encrypted vault and pick it up once, elsewhere.

01

How it works

  1. Leave something. Your browser prepares and encrypts it before upload.
  2. Keep the pickup details. The vault number identifies the vault. The pickup phrase opens it.
  3. Open it elsewhere. Enter both details in another browser. Once pickup begins, nobody else can start. After the browser receives and decrypts it, the server copy is scheduled for deletion.

02

What the server keeps

The server keeps encrypted bytes, the vault number, a hardened value derived from the pickup details, and the creation and expiry times.

During retrieval, it also keeps a short-lived record that prevents two pickups from completing at once.

Scapuff is designed so the original file contents, note text, filename, and pickup phrase are not intentionally sent to the server in readable form.

03

What happens to the data

When pickup begins, the vault is claimed and cannot be opened by anyone else.

After the browser receives and decrypts the item, the encrypted server copy is scheduled for deletion. The person collecting it can clear the copy immediately, or let Scapuff remove it after a short pickup window.

If the transfer is interrupted before completion, the vault is not reopened. The encrypted copy is deleted after the claim deadline.

One pickup means one claimant and one short pickup session. It cannot stop the receiving device from saving or copying the item afterward.

04

Safety, without theatre

Browser-side encryption prevents the server from reading the contents during normal operation.

The pickup phrase still controls access. One generated word is intended for brief, low-consequence transfers. Add random words for anything that will stay longer or matters more.

Avoid familiar sayings, personal facts, reused passwords, and anything another person could predict.

05

What Scapuff cannot promise

Compromised application code could expose content before encryption or during pickup.

A compromised server could observe connection metadata, such as network addresses, timing, and transfer size. It could also retain encrypted copies or test weak phrases.

Hosting providers, proxies, operating systems, and networks may keep external logs. Deletion by the application does not prove erasure from backups, snapshots, or caches.

A compromised sending or receiving device can expose the content before it is encrypted or after it is opened.

06

No identity by default

This deployment has no user accounts, advertising, analytics, third-party scripts, application cookies, or browser-storage history. It uses short-lived, pseudonymous network counters to limit abuse.

That makes Scapuff accountless. It does not make a network connection invisible.

About me

I created Scapuff because I needed to move a file to a shared or public computer, and I did not want to sign in to any of my accounts.

I wanted a simpler way to leave the file temporarily, pick it up once, and move on without leaving an account or session behind.

The simple version

Leave it. Keep the details. Pick it up once.

Leave something