Using Aeterna
Encryption & decryption
Your files are encrypted in your browser using AES-256-GCM before they ever leave it. We only store the encrypted ciphertext and a ZK commitment. Only you have the key to decrypt them.
How it works
When you turn on encryption, your browser creates a brand-new random key for that file — a 256-bit key that exists nowhere else. It uses it to lock the file with AES-256-GCM, the same standard used to protect bank and government data, and only then uploads it.
| What | Where it lives |
|---|---|
| The file’s contents | Encrypted. Stored on Arweave and IPFS as unreadable ciphertext. |
| Its name and type | Encrypted too, inside the file. Publicly it is just “an encrypted file”. |
| A ZK commitment | Public. A fingerprint of the contents that reveals nothing without the key, used to check the file later. |
| The key | Only with you. Shown once, at upload. Never sent to us. |
Save your key — it cannot be recovered
We never have your key, so we cannot help you get it back. If you lose it, the file stays stored forever but can never be opened. Copy it or download it the moment you see it.Encrypting a file
Turn on encryption
On the Upload page, tick Enable client-side encryption. Encryption works for files up to 1 GB.Upload as usual
Click Store permanently.Save the key
Each encrypted file shows a yellow Decryption key box. Use Copy key, Copy decrypt link or Download key (a small text file with both). Keep it somewhere safe, such as a password manager.
Your browser also keeps a copy of each key, so your vault can show the real file names and open files in one click. That copy is a convenience only: clearing your browser data, or using another device, loses it. The key you saved is the one that counts.
Opening an encrypted file
With a decrypt link
A decrypt link looks like https://…/decrypt/<transaction-id>#<key>. Open it and the file is fetched from Arweave and decrypted right there in your browser. The part after # — the key — is never sent to any server; browsers keep it on your device.
With just the key
Go to /decrypt/<transaction-id>, or click the unlock icon next to the file in your vault, and paste the key.
Once decrypted you can preview it (images, video, audio, PDF and text) and download it with its original name.
It works without us
Decryption happens entirely in your browser and reads the file straight from Arweave. Even if Aeterna's servers were down, a decrypt link would still open your file.“Matches the ZK commitment”
After decrypting, the page recomputes the file's commitment and compares it with the one recorded publicly at upload. A match proves these are exactly the bytes that were stored. If it ever says the file does not match, treat that file with suspicion.
Sharing an encrypted file
- Send the decrypt link to someone and they can open the file. Anyone who has it can.
- There is no way to take access back: once someone has the key they can keep a copy. Share it only with people you trust with the file.
- Sharing the file's verification link instead proves the file exists without giving anyone the ability to read it.
If decryption fails
| Message | What to do |
|---|---|
| Wrong key, or the file has been altered | Check you have the key for this exact file — every file has its own. Copy it again, without spaces. |
| That is not a valid file key | The key is 43 characters of letters, numbers, - and _. Something was cut off or added. |
| Could not fetch the file | A very recent upload may still be propagating. Wait a few minutes and try again. |
Files encrypted with an older version of Aeterna used a passphrase instead of a key. The decrypt page recognises them and asks for the passphrase.