Encrypted
URLs and uploaded files are sealed with a key stretched from your password by scrypt. The disk holds a salt and ciphertext. Nothing else.
Paste a URL or drop a file, set a password, share the short link. Nobody sees what is behind it until they type the password. Not even this server.
// aes-256-gcm · key derived from your password
Send the link and the password separately. Anyone with both gets what is behind it.
Most "protected" shorteners store your URL in plain text and check a password in front of it. Latch never stores the URL at all.
URLs and uploaded files are sealed with a key stretched from your password by scrypt. The disk holds a salt and ciphertext. Nothing else.
Five wrong passwords and that address waits ten minutes. Guessing gets slow fast.
Set a link to die in an hour, a day, a week or a month. Expired links are deleted, not hidden.
The short link opens a lock screen, never the site. The real URL is only shown after the password decrypts it, so link previews and crawlers learn nothing.