FlashDrop Pro Logo
← Back to Workspace

About This Site & Technology

FlashDrop Pro is a browser-based workspace for sending files and text directly between devices. This page explains how the product is built, what runs in your browser, and what (if anything) touches our infrastructure.

1. Hybrid architecture in plain terms

We use a hybrid model: your transfers are designed to stay peer-to-peer, while lightweight signaling helps browsers find each other without hosting your file payloads.

  • Data plane (your files & text): Intended to flow directly between browsers via WebRTC. We do not operate a “cloud inbox” for your drops.
  • Control plane: Session codes and connection metadata, separate from the transfer payload.

2. WebRTC and signaling

WebRTC establishes an encrypted media/data path between peers. A small amount of signaling (e.g. connection metadata) may pass through third-party infrastructure so two browsers can find each other. That signaling is not your file or message content and is not used as a substitute for storage of your drops.

  • No intentional file warehousing: The product is not designed for us to retain copies of what you send.
  • Ephemeral by design: Session state in the page is lost when you close the tab; treat sensitive material accordingly.
  • Network realities: Some networks block or impair P2P; in those cases a connection may fail—this is a limitation of the environment, not a claim of guaranteed delivery in every firewall scenario.

3. Signaling and service infrastructure

Infrastructure used for connection setup does not need—and is not given—access to your WebRTC payload as part of normal operation.

4. Optional AES-256-GCM — unified parameters

When you enable optional password-based protection, encryption runs in your browser using AES-256-GCM. Keys are derived with PBKDF2-HMAC-SHA256 using a fixed, high iteration count (600,000) on all supported devices so that phones and desktops use the same cryptographic profile—avoiding mismatches that could prevent the other device from decrypting.

Each encrypted payload includes a random salt and IV as part of the format; you must retain the password out-of-band. We cannot reset or recover file passwords.

5. AI-assisted features (local)

Heuristic prompts (e.g. filename hints, optional OCR) are intended to run locally in the browser where implemented. They are not a guarantee of compliance or exhaustive detection; they are assistive only.

6. Current product safeguards

The current workflow adds receiver-side metadata preview, explicit receive confirmation for files, short-lived security-code comparison, and local-only history controls. These features reduce mistakes before transfer starts; they do not turn FlashDrop Pro into cloud storage.

8. Collaboration features

  • 10-character codes: a-z0-9 session identifiers; peer IDs are derived for WebRTC signaling—anyone with the code can attempt to connect.
  • ECDH P-256 + AES-GCM control channel: encrypted, typed control messages; no plaintext fallback for session commands.
  • Multi-device broadcast: one sender, multiple receiver connections when download limits allow; each peer verified separately.
  • SHA-256 file integrity: computed in-browser; distinct from PBKDF2-HMAC-SHA256 used for AES key derivation.
  • Screen assist: getDisplayMedia video tracks over WebRTC; view-only—no OS-level input injection. One reverse-share slot at a time.
  • Receiver resume: local IndexedDB checkpoints with rotated resume tokens bound to the initial peer where implemented.

9. Transparency

As of January 2026, we have not published receipt of governmental content demands on this page; this is a general transparency statement and not legal advice. For legal requests, contact us using the details below.

Contact: Email [email protected]

关于本站与技术说明

FlashDrop Pro 是在浏览器中使用的文件与文字直传工具。本页说明产品架构:哪些处理发生在您的设备上,信令如何辅助连接,以及可选加密如何工作。

1. 混合架构概述

我们采用混合架构:传输设计为点对点(P2P);轻量信令帮助浏览器互相发现,但不托管您的文件载荷。

  • 数据面(文件与文字): 目标是在对端浏览器之间直接建立通道,而非由我们长期托管您的文件内容。
  • 控制面: 会话码与连接元数据,与传输载荷分离。

2. WebRTC 与信令

WebRTC 用于在两端之间建立加密通道。为实现联网设备互相发现,少量信令(连接元数据)可能经由第三方基础设施传递;信令不是您的文件正文,也不作为对您传输内容的“代存”。

  • 非网盘设计: 产品目标不是由我们长期保存您发送的文件副本。
  • 会话特性: 页面关闭后,浏览器内会话状态会丢失;敏感内容请自行妥善管理。
  • 网络环境: 部分网络会限制 P2P,可能导致无法连通,这是环境限制而非对“任意网络必达”的承诺。

3. 信令与服务基础设施

用于连接建立的基础设施在正常运行路径下并不需要也不应接触您的 WebRTC 传输载荷。

4. 可选 AES-256-GCM — 全设备统一参数

开启可选密码保护时,加密在您的浏览器本地完成,算法为 AES-256-GCM;密钥由 PBKDF2-HMAC-SHA256 派生,全平台固定 600,000 次迭代,避免手机与电脑使用不同强度导致无法跨设备解密。加密格式包含随机盐与 IV;密码需您自行保管,我们无法找回。

5. AI 辅助(本地启发式)

文件名提示、可选 OCR 等能力在实现上尽量本地执行,仅为辅助提示,不构成合规或穷尽检测保证。

6. 当前产品防护机制

当前流程加入了接收端元信息预览、文件接收确认、短时匹配码核对以及本地历史隐私控制。这些能力用于在传输开始前减少误收、误传与密钥错误,并不意味着 FlashDrop Pro 变成云端存储服务。

8. 协作功能

  • 10 位会话码: a-z0-9 标识;用于 WebRTC 信令——持有码者可尝试连接。
  • ECDH P-256 + AES-GCM 控制通道: 加密、类型化控制消息;会话指令无明文回退。
  • 多设备广播: 在下载次数允许时,一位发送方可连接多位接收方;各连接单独核对。
  • SHA-256 文件完整性: 浏览器内计算;与 AES 密钥派生用的 PBKDF2-HMAC-SHA256 不同。
  • 屏幕协助: getDisplayMedia 视频轨经 WebRTC 传输;仅观看——不向操作系统注入键鼠。反向共享同时仅一人。
  • 接收断点: 本地 IndexedDB 检查点,resume 令牌在实现上与初始 peer 绑定。

9. 透明度提示

截至 2026 年 1 月,本页未列示收到政府内容调取通知;该表述为一般性透明说明,不构成法律意见。正式法律请求请通过下列方式联系。

联系方式: 邮箱 [email protected]

本サイトと技術について

FlashDrop Proはブラウザ上でファイルやテキストを端末間で直接送るためのワークスペースです。本ページでは、データがどこで処理され、どの外部サービスがアカウント/決済に使われるか、また任意の暗号化がどのように動くかを説明します。

1. ハイブリッド構成の概要

転送はP2P(ピアツーピア)を原則とし、アカウントや課金は別系統のサービスで管理します。これにより「クラウド受信箱」としてファイルを長期保管する設計にはしません。

  • データプレーン: ペイロードはブラウザ間の直接経路を想定。
  • コントロールプレーン: 接続状態などの最小限のメタデータ。

2. WebRTC とシグナリング

接続確立のために少量のシグナリング(接続メタデータ)が経路を通る場合がありますが、これはファイル本文の代替ストレージではありません。タブを閉じるとセッション状態は失われます。一部のネットワークでは P2P が制限され、接続に失敗することがあります。

3. アカウント(Supabase)

Supabaseは認証と必要最小限のプロファイル情報に利用します。通常運用において WebRTC の転送内容そのものへアクセスする必要はありません。

5. 任意の AES-256-GCM()— 統一パラメータ

パスワード保護を有効にすると、AES-256-GCM をブラウザ内で適用します。鍵は PBKDF2-HMAC-SHA256 で派生し、全デバイスで反復回数 600,000 回に固定し、スマートフォンと PC で異なる強度にならないようにしています(復号不能な不一致を避けるため)。形式にはランダムなソルトと IV が含まれます。パスワードの再発行はできません。

6. AI 補助機能

ファイル名ヒントや OCR などは可能な限りローカルで動作する補助機能であり、網羅的なコンプライアンス判定を保証するものではありません。

7. 現在の保護機能

現在のワークフローには、受信前メタデータプレビュー、ファイル受信の明示確認、短時間のセキュリティコード比較、ローカル履歴のプライバシー制御が含まれます。これは転送前のミスを減らすためのもので、クラウド保存を意味しません。

8. 透明性

2026年1月時点の一般的な透明性表明です。法的な照会は下記までご連絡ください。

連絡先: メール [email protected]

À propos de ce site et de la technologie

FlashDrop Pro permet d’envoyer des fichiers et du texte directement entre appareils, dans le navigateur. Cette page décrit l’architecture, la gestion du compte/paiement, et le chiffrement optionnel.

1. Architecture hybride

Le transfert vise le P2P, tandis que le compte et la facturation sont gérés par des services séparés. Ce n’est pas un modèle de “boîte de réception cloud” qui stocke vos fichiers à long terme.

  • Plan de données : charge utile entre navigateurs.
  • Plan de contrôle : identité et état de connexion, au minimum nécessaire.

2. WebRTC et signalisation

Une petite quantité de signalisation (métadonnées de connexion) peut transiter pour permettre aux pairs de se trouver ; ce n’est pas un stockage du contenu. Fermer l’onglet termine généralement le contexte de session. Certains réseaux peuvent bloquer le P2P.

3. Compte (Supabase)

Supabase sert à l’authentification et à quelques champs de profil. En fonctionnement normal, il n’a pas besoin d’accéder à la charge utile WebRTC.

5. AES-256-GCM optionnel — paramètres unifiés

Le chiffrement par mot de passe applique AES-256-GCM dans le navigateur. La clé est dérivée via PBKDF2-HMAC-SHA256 avec 600 000 itérations fixes sur tous les appareils afin d’éviter des déchiffrements incompatibles entre mobile et PC. Chaque objet inclut un sel et un IV aléatoires. Nous ne pouvons pas récupérer votre mot de passe.

6. Aides “IA”

Les indices (nom de fichier) et l’OCR sont des aides, autant que possible locales, et ne garantissent pas une conformité exhaustive.

7. Protections actuelles

Le flux inclut : aperçu des métadonnées avant réception, confirmation explicite pour les fichiers, courte vérification de codes de sécurité, et contrôles de confidentialité de l’historique local. Cela réduit les erreurs avant transfert ; ce n’est pas du stockage cloud.

8. Transparence

Déclaration générale (janvier 2026). Pour les demandes formelles :

Contact : Email [email protected]

Über diese Seite und die Technik

FlashDrop Pro ist ein Browser‑Workspace, um Dateien und Text direkt zwischen Geräten zu übertragen. Diese Seite erklärt Architektur, Konto/Zahlung und optionale Verschlüsselung.

1. Hybride Architektur

Die Übertragung ist auf P2P ausgelegt, während Konto und Abrechnung über separate Dienste laufen. Es ist kein “Cloud‑Posteingang”, der Dateien langfristig speichert.

  • Datenebene: Nutzdaten zwischen Browsern.
  • Kontrollebene: Identität und Verbindungsstatus – minimal nötig.

2. WebRTC und Signalisierung

Für den Verbindungsaufbau kann eine geringe Menge Signalisierungsdaten (Verbindungs‑Metadaten) über Drittinfrastruktur laufen; das ersetzt keine Speicherung der Inhalte. Wird der Tab geschlossen, endet der Sitzungskontext typischerweise. Manche Netzwerke blockieren P2P.

3. Konto (Supabase)

Supabase wird für Authentifizierung und minimale Profildaten genutzt; im Normalbetrieb ist kein Zugriff auf den WebRTC‑Payload erforderlich.

5. Optionales AES-256-GCM — einheitliche Parameter

Passwortschutz nutzt AES-256-GCM im Browser. Der Schlüssel wird über PBKDF2-HMAC-SHA256 abgeleitet und mit 600 000 Iterationen auf allen Geräten fest eingestellt, um inkompatible Entschlüsselungen (Mobil/Desktop) zu vermeiden. Jedes Objekt enthält zufälliges Salt und IV. Passwörter können wir nicht wiederherstellen.

6. “KI”-Hilfen

Dateinamen‑Hinweise und OCR sind Hilfen (möglichst lokal) und keine Garantie für vollständige Compliance‑Prüfungen.

7. Aktuelle Schutzmaßnahmen

Der Workflow umfasst u. a. Metadaten‑Vorschau vor dem Empfang, explizite Bestätigung für Dateien, kurze Sicherheitscode‑Prüfung sowie lokale Datenschutz‑Kontrollen für den Verlauf. Das reduziert Fehler vor dem Transfer – es ist kein Cloud‑Speicher.

8. Transparenz

Allgemeine Erklärung (Stand Januar 2026). Für formelle Anfragen:

Kontakt: E‑Mail [email protected]

Acerca de este sitio y la tecnología

FlashDrop Pro es un espacio de trabajo en el navegador para enviar archivos y texto directamente entre dispositivos. Aquí explicamos la arquitectura, qué servicios gestionan la cuenta y el pago, y cómo funciona el cifrado opcional.

1. Arquitectura híbrida

El tráfico de transferencia está pensado como P2P; la cuenta y la facturación usan servicios separados para poder ofrecer límites Pro sin operar una “bandeja nube” para sus archivos.

  • Plano de datos: carga útil entre navegadores.
  • Plano de control: identidad y estado de conexión, mínimo necesario.

2. WebRTC y señalización

Puede usarse una pequeña cantidad de señalización (metadatos de conexión) para que los pares se encuentren; no sustituye al almacenamiento del contenido. Al cerrar la pestaña se pierde el estado de sesión. Algunas redes bloquean P2P.

3. Cuentas (Supabase)

Supabase cubre autenticación y campos mínimos de perfil; no necesita acceder al flujo WebRTC en el funcionamiento normal.

5. AES-256-GCM opcional — parámetros unificados

El cifrado con contraseña usa AES-256-GCM en el navegador; la clave se deriva con PBKDF2-HMAC-SHA256 con 600.000 iteraciones fijas en todos los dispositivos para evitar que móvil y escritorio generen perfiles incompatibles. Cada objeto incluye sal e IV aleatorios. No podemos recuperar su contraseña.

6. Asistencia tipo IA

Pistas de nombre de archivo u OCR son ayudas locales y no garantías de cumplimiento.

7. Salvaguardas actuales

El flujo actual incluye vista previa de metadatos antes de recibir, confirmación explícita para archivos, comparación breve de códigos de seguridad y controles locales de privacidad del historial. Reducen errores antes de transferir; no convierten el producto en almacenamiento en la nube.

8. Transparencia

Declaración general a enero de 2026. Para solicitudes formales, contacte:

Contacto: Email [email protected]