1. Get a photo from your phone
Click the button, then point your phone's normal camera app at the QR code. Demo images only. No CUI/ITAR data.
Ready.
Match code: tap this number on the phone
---
Expires in 10:00 or after one photo.
Can't scan? Show the link
How this works / what the server can see
When you click Request photo, this browser makes a brand-new lock-and-key pair. The lock (public key) goes into the QR code. The key (private key) stays inside this browser tab and the browser is told it may never be exported. The phone takes the picture, locks it with that lock, and sends only the locked box through our relay server. Only this tab can open it.
The relay server sees
- An encrypted blob (scrambled bytes) and its size
- A random session ID
- Timing (when the session started and the photo was sent)
- IP addresses of the phone and desktop (and Cloudflare, which carries the HTTPS connection, sees the same)
The relay server never sees
- The photo. It is encrypted on the phone before upload (AES-256-GCM).
- The key. The lock travels after the
#in the QR link, and browsers never send that part to a server. - Anything on disk. The relay keeps the blob in memory only and wipes it the moment this tab downloads it.
On the phone
- The camera is used live in the web page. The photo is not saved to the gallery or camera roll, so it is not backed up to iCloud/Google Photos.
- After sending, the page clears the picture from memory and the screen and turns the camera off.
- No app to install.
Single use
- Each QR code works for one photo or 10 minutes, whichever comes first. Then it is dead.
- The phone asks you to tap the 3-digit match code shown here (out of 6 choices) before it opens the camera. That confirms the phone got this computer's lock. One wrong tap ends the session.
Limits (honest list)
- A browser can't block screenshots, on the phone or here.
- Needs HTTPS (phones won't open the camera otherwise).
- Anyone who scans the QR before you could send a photo into this session; the match code and "one photo only" limit this.
- Once you click Save to computer, the file is a normal file on this PC.
- This is a demo. The crypto is the browser's built-in WebCrypto (ECDH P-256 + HKDF-SHA-256 + AES-256-GCM), but nothing here is FIPS-validated or approved for CUI/ITAR.