FAQ

Questions, answered

64 answers on how Clex handles your files, your privacy and your transfers

Transfers

How do I send a file

Open clex.in, drop the file into the workspace and press share. Clex gives you a six character code, a link and a QR. Send any of them to the other person. When they open it, their browser connects to yours and the file streams across.

How do I receive a file

Open clex.in/receive and type the code, open the link you were sent, or scan the QR with your phone camera. The file arrives in your browser, checked chunk by chunk, and you save it from there.

Does the other person need an account or an app

No. Both sides only need a modern browser. There is nothing to install and nothing to sign up for.

How does peer to peer transfer work

Clex uses WebRTC to connect your browser directly to the other one. A small signaling server helps the two browsers find each other by passing along connection details. Once they are connected, the file streams straight from your browser to theirs. No server stores or relays the file.

What is the local route

When both devices are on the same network, the local route offers only local addresses, so the transfer never leaves your network. If the connection would go out over the internet, Clex stops and tells you instead. It is ideal for big files between your own devices.

Do both browsers need to stay open

Yes. Both tabs need to stay open until the transfer finishes, and both devices need to be online at the same time. Clex has no server holding the file in between.

How long does a share code work

A code works while your tab is open and waiting. Close the tab and the code stops working, because there is nothing stored anywhere for it to point at.

Can I send several files at once

Yes. Drop as many as you like and send them together in one transfer. You can also bundle them into a single ZIP first with the ZIP tool.

What if the two browsers can't connect

Some strict networks block direct connections. Clex has no relay server, so it tells you plainly rather than quietly uploading your file somewhere. Trying another network, or the local route when you share one, usually works.

Why is my transfer slower than expected

A direct transfer runs at the speed of the slower of the two connections, and busy Wi-Fi or a phone on mobile data will set the pace. If both devices are nearby, the local route keeps the transfer on your network and is usually much faster.

Can I send from my phone

Yes. The workspace works in mobile browsers, and on Android the Clex Link app finds nearby devices on your network without any code.

Direct+

What is Clex Direct+

Direct+ is the reliability layer on direct transfers: a manifest of every chunk, an acknowledgement for each one, retries for anything lost, pause and resume, and a verified receipt at the end.

Can I pause a transfer

Yes. While a transfer is running there is a pause button. The connection stays open and the receiver keeps what has arrived. Resume picks up from the next pending chunk, not from the start.

What happens if the connection drops

Within the same session, each side knows which chunks are verified, so only the missing ones are sent again. If both tabs close before the end, the session is over and you start a new one. Chunk state lives in the browser, not on a server.

How do I know the file arrived intact

The receiver checks every chunk's size against the manifest and, within the hashing budget, its SHA-256. When everything lines up, both sides build a verified receipt: file count, size, chunks, retries, health and an optional root hash. The receipt holds no file content.

What is in the receipt, and how do I keep it

The route, the number of files, the total size, the chunk count and size, the duration, retries, failed chunks, the health score and a proof root. No file names and no contents. When a transfer finishes you can share the receipt, save it as an image or copy it as text.

What does the health score mean

It is a live 0 to 100 reading of the transfer: connection stability, retries, failed chunks and backpressure. Above 90 is clean. The middle range usually means a few retries, which is the safety net working. Low scores mean the network is genuinely struggling.

What if the other person has an older version

The two sides compare what they support before anything is sent. If either one lacks Direct+, they agree on the classic transfer instead, automatically.

Why 64 KB chunks

Small chunks are cheap to check and cheap to resend. With up to 8 MB in flight at once, the transfer still moves at full speed while every piece stays accounted for.

Privacy and security

Are my files stored on Clex servers

Not for workspace transfers. Direct and local transfers exist only in the two browsers. The signaling server only passes connection details and never sees file data. Files you upload through the developer API are the one exception: they are stored until the expiry you choose, so they can be downloaded by link.

Can Clex see what I send

No. A workspace transfer is encrypted from one browser to the other, and no Clex server is in the path of the file. We never see its name, its size on the wire or its contents.

Is the transfer encrypted

Yes. WebRTC data channels are always encrypted with DTLS, from one browser to the other. There is no server in the path that could decrypt them.

What does the signaling server see

Only what two browsers need to find each other: session offers, answers and connection candidates, which include network addresses. It passes them along and steps aside. It never sees file names, file bytes or Vault data.

Do I need an account

No. Transfers, tools, Vault and API keys all work without one. Signing in with Google is optional and only adds Vault recovery and higher API limits.

Do you use cookies, analytics or trackers

No. There are no HTTP cookies, no analytics or telemetry, no advertising pixels and no device fingerprinting. The storage page lists every item Clex keeps in your browser and why.

What does Clex keep in my browser

Your theme choice and whether you have seen the storage notice. If you use Vault, its encrypted notes and your keys, in IndexedDB. If you create an API key, the key for that tab only, in session storage. Clearing site data removes all of it.

Does the public chain record anything about me

Each transfer adds an anonymous record: a random ID your browser made for itself, the route, file categories, types and sizes, SHA-256 hashes and the status times. Never file names, never contents, never IP addresses, and nothing that names a person.

Who can use my share code or link

Treat it like a key. Anyone who has it can connect while your tab is waiting. Send it only to the person you mean, and close the tab when you are done.

Are API uploads encrypted

They travel over HTTPS and are stored with Cloudflare until they expire. They are not end to end encrypted: anyone with the share link can download the file until it expires or you revoke it. For something sensitive, encrypt it before uploading, or use a direct transfer.

What happens to an API upload when it expires

The link stops working at once and answers that the share has expired. The stored bytes are removed by a cleanup that runs every hour. Revoking an upload yourself works the same way, immediately.

Do you sell or share data

No. There is nothing to sell: Clex does not collect personal data for advertising, and it is not shared with anyone for that purpose.

Which third parties are involved

Cloudflare serves the site and runs the API. Google Fonts serves the typefaces. Firebase Authentication handles Google sign-in, only if you choose to sign in. None of them see the files you transfer.

Is Clex open source

Yes. The code for the site, the workers and the apps is on GitHub, so anyone can check what it does.

How do I report a security problem

Email abhnv@abhnv.in with the details and how to reproduce it. Please give us a chance to fix it before sharing it publicly. Every report gets a reply.

Vault

Where are Vault notes stored

In your browser, encrypted before they are written to its local database. Your device holds the primary copy. Vault can sync between devices you pair, and notes never appear on the public chain.

Does Vault back up my notes to a server

Yes, as ciphertext only. Vault keeps an encrypted snapshot on the Clex API so a paired or signed-in device can restore your notes. It is encrypted in your browser with your vault key before it leaves, and the key is never sent. The server can see how many notes and folders there are and when the backup changed, not what they say.

What happens if I clear my browser data

The notes and the keys on that device are deleted together. You can get them back from a paired device, or from the encrypted backup if you signed in with Google or kept an export of your key. Without any of those, the notes cannot be recovered, by design.

How do I use Vault on another device

Open Devices and keys in Vault and pair the new device with a short code. Your notes sync between the two, peer to peer. Signing in with Google on both also brings them into the same vault.

What does the key fingerprint mean

It is the first eight characters of a hash of your vault key, shown in the Vault bar. Two devices that show the same fingerprint share the same vault.

Can I export my notes or my key

Yes. Devices and keys has an export of your key and of your data, so you can keep a copy somewhere safe.

Are secret links always one time

Only if you switch on view once. Otherwise the recipient can open the link again until it expires.

Does a secret link's key reach the server

No. The key sits after the # in the link, and browsers never send that part to any server. The server only ever holds the encrypted secret.

What do the secret link protections do

You choose per link: view once, a 60 second viewing window, no select, a tab switch lock and a DevTools guard. Only the ones you switch on apply. Keeping the secret in memory only is always on.

Do Vault notes appear on the chain

No. The public chain records workspace transfer metadata only. Notes and secret links stay out of it entirely.

Transfer chain

What is the transfer chain

A public, append only ledger of anonymous transfer records. It lets anyone check that a delivery happened without revealing what was delivered or who delivered it. You can browse it on the Chain page.

Why link records by hash

Every record carries the hash of the one before it. Change any record and every hash after it stops matching, so tampering is easy to spot.

Can someone find my transfers on the chain

Only by the random ID your own browser made, which is kept on your device and is not tied to you. Records hold no names, no contents and no IP addresses.

Developers

Is the API live

Yes, at clex.in/vault/api. You can mint a key and upload a file from the Developers page right now, or with one curl command.

Can I use Clex from a script or terminal

Yes. Mint a key on the Developers page, then upload with one HTTP call from any language, or with the Clex CLI. You get a share link back that anyone can open.

How is an API upload different from a workspace transfer

A workspace transfer is live and browser to browser, with nothing stored. An API upload is stored until its expiry, 24 hours by default and at most 7 days, so the recipient can download it whenever they like. You can revoke it at any time.

What are the API limits

A key made without an account allows 100 MB per file and 60 requests a minute, with up to three keys per device. Signing in on the account page raises those limits.

I lost my API key

Clex stores only a hash of each key, so it cannot show it to you again. Mint a new one and revoke the old one if you still have it.

How do I revoke a key or an upload

Rotate the key on the Developers page, or send DELETE /vault/api/keys/self with it. To revoke an upload, send DELETE /vault/api/uploads/:id. Both stop working immediately.

Can I choose how long a link lasts

Yes. Send X-Expires-In in seconds, from 5 minutes to 7 days. Without it, links last 24 hours.

Files and browsers

Is there a file size limit

For browser to browser transfers the limit is the memory your browser can use, usually several gigabytes. For very large files, the local route between nearby devices works best.

What can the tools process

Images (compress and convert between JPEG, PNG, WebP), PDFs (merge, split, export pages as images), Word documents to PDF, and ZIP bundles of anything. You can send any file type, even without a tool for it.

Does Clex change my files

Only if you run a tool on them, and then you choose which version to send. A transfer delivers exactly the bytes you sent, and Direct+ checks that they match.

Can I use the tools without sharing

Of course. Drop files, prepare them and download the results. Clex works perfectly well as a private file toolbox.

Which browsers work

Any modern browser with WebRTC: Chrome, Safari, Firefox and Edge, on desktop and mobile. The workspace adapts to small screens with everything still there.

Does it work offline

The preparation tools do, after the first visit. Sending needs a connection, since it has to reach the other device, so prepare offline and share when you are back.

Is there an app

On Android, Clex Link is available as an APK from GitHub, with Play Store and App Store releases on the way. On any other device, the browser is the app.

About Clex

Who makes Clex

Clex is built by Abhinav Raj. You can see more of his work at abhnv.in.

Is Clex free

Yes. Transfers, tools, Vault and API keys cost nothing, with no account needed.

How do I get in touch

Email abhnv@abhnv.in. A real person reads every message, whether it is a question, a bug or an idea.

Still wondering

Write to the developer and a real person will answer. Questions, bugs, security reports and ideas are all welcome.