Secure Files
Encrypt files in your browser and organize them with folders.
Secure Files encrypts file contents, filenames and folder names in your browser before they are saved. It uses the encryption identity from Password Vault. Set up Password Vault first. An active same-tab Password Vault session also unlocks Secure Files; otherwise, enter the same Password Vault password when Secure Files asks.
Upload and download files
Choose Upload and select one or more files, each up to 2 GB. Secure Files encrypts and uploads them one at a time, in chunks, into the folder that is open. If a file cannot be uploaded, Secure Files names it and continues with the others. Magpie stores the encrypted file, encrypted name and a wrapped copy of its random file key. Magpie does not receive the plaintext file or unwrapped file key.
Choose a file's name or Download to retrieve and decrypt it in your browser. Browsers that support the file save picker can write decrypted chunks directly to the selected file. Other browsers assemble the decrypted file in memory before saving it; large downloads can use substantial memory.
PNG, JPEG, GIF, WebP and AVIF images up to 10 MB show a preview in the file list. The preview is downloaded and decrypted in your browser when the list opens, and is discarded when Secure Files locks.
Folders and file names
Folders are listed above files. Choose a folder to open it; the heading above the list shows where you are, and each part of it opens that folder. The browser's Back button returns to the previous folder. Choose New folder to create a folder in the folder that is open. Folder names are encrypted in your browser, so Magpie cannot check for duplicates; Secure Files checks the names in your browser and does not create a second folder with the same name in the same place.
To delete a folder, choose More beside it, then Delete folder. The folder and the folders inside it are deleted, and their files move to Trash. A file restored from Trash returns to its folder, or to Files when that folder has been deleted.
Upload adds the file to the folder that is open. To move a file, choose More beside it, then the destination folder. Choose More and then Rename to change a file's encrypted name; renaming does not change the encrypted file contents.
Search covers file and folder names in every folder. It runs against names decrypted in your browser. Search text is not sent to Magpie.
Storage
Secure Files counts toward your plan's storage, along with images, podcast episodes, recordings and other stored files. The bottom of the file list shows how much Secure Files uses and how much of your plan's storage is used in total. Files in Trash and unfinished uploads still use storage; Delete forever frees it. An upload that would exceed your plan's storage is not started.
Trash
Choose Move to Trash from More to remove a file from Files. Open Trash and choose Restore to return it. Choose Delete forever to remove the encrypted file and its key wrapper from active storage. Infrastructure backups may retain ciphertext temporarily; Trash does not expire automatically.
Share a file with a secure link
Choose More beside a file, then Share securely. Choose when the link expires and whether it allows unlimited downloads or one download. Links expire after 7 days by default. You can also require a passphrase. Give that passphrase to the recipient separately; it is not included in the link.
After you create a link, copy it before closing the drawer. Magpie shows the complete
link only once because it cannot recover the decryption secret. The secret is after
the # in the address. The recipient's browser reads it there; browsers do not send
that part of the address to Magpie. The link's separate ID lets Magpie find the
encrypted file and enforce its expiry, download limit and revocation.
The browser encrypts the file key for the link. Magpie stores the encrypted file and wrapped key, not the link secret, passphrase, file key or plaintext file. If you set a passphrase, the browser uses Argon2id to wrap the key protected by the link secret. The recipient needs both the complete link and passphrase. Use at least 12 characters and send the passphrase through a separate channel.
The recipient page locks after 15 minutes without activity and clears the decryption key. Reopen the original complete link to access the file again.
A one-download link stops accepting new downloads when a recipient starts one. That transfer can finish for up to two hours. The link counts the server's download authorization; it cannot prove the recipient opened or saved the decrypted file. An interrupted transfer still uses that authorization. Choose Revoke beside a link to stop access immediately, including an active transfer. Moving the file to Trash also revokes its links. Neither action removes a copy someone already downloaded.
External links can expire after 1 hour, 1 day, 7 days or 30 days. Revoking or expiring a link stops new downloads; the encrypted file stays in your Secure Files storage. Sharing with other Magpie users and team storage are not available.
In the Magpie app
Secure Files in the Magpie app opens the same encrypted files and folders. Files uploaded in the app open in a browser, and files uploaded in a browser open in the app.
Open Secure Files and enter your Password Vault password. If Password Vault is already unlocked in the app, Secure Files opens without asking again. The keys stay in the app's memory until you choose Lock Secure Files or Lock vault, sign out, or close the app. Locking either one locks both.
Choose Upload, then Take a photo or video, Choose from Photos or Choose from Files. Each file is encrypted on your phone in chunks and uploaded, one file at a time, into the folder that is open. The Uploads list shows each file's progress. If a file is not uploaded, it stays in the list with the reason; choose Retry to upload it again, or swipe it to remove it. Locking Secure Files stops the upload in progress; after you unlock, choose Retry. Leaving Secure Files stops any unfinished uploads and clears the list.
Tap a file to download and decrypt it on your phone. The share sheet then opens, where you can preview the file, save it or send it to another app. The decrypted copy is deleted from the app's storage when the share sheet closes, and again when Secure Files locks or closes. Anything you save or send from the share sheet is a decrypted copy outside Secure Files.
Touch and hold a file for Share securely, Rename and Move to folder, or swipe it to Move to Trash. Swipe a folder to delete it. Choose New folder, Trash and Lock Secure Files from the actions menu. In Trash, choose Restore, or swipe a file to Delete forever. The search field searches file and folder names in every folder on your phone.
Share securely creates the same secure links, with the same expiry, download limit and passphrase choices. The app shows the complete link once, with Share link and Copy link, and lists the file's links so you can revoke one by swiping it. A passphrase is processed with Argon2id on your phone, which can take a few seconds.
Encryption in the app runs on your phone's processor, so large files take longer to upload and open than in a browser. Image previews in the file list and opening a PDF in PDF Workspace are not available in the app.
Magpie can see file sizes, folder relationships, timestamps, sharing relationships, download authorizations and access patterns. It cannot scan encrypted contents for malware. Encrypted data may remain in infrastructure backups temporarily after deletion.
For help with Secure Files, Contact support.