Mándamele
Back to guides

Guides

Privacy and security checklist before sending files

A direct path reduces exposure to service-side storage, but it cannot correct a wrong recipient, compromised device or uncontrolled downloaded copy.

Updated 2026-08-07 · approximately 727 words

The review covers before, during and after the transfer.

1. Confirm the recipient and context

Verify who controls the second browser and why they need the file. When you are apart, confirm by voice or an independent channel before sharing the code. The current flow automatically approves a valid join because manual approval is disabled; there is no screen displaying a verified name or fingerprint for the other person.

Avoid public or shared computers for sensitive documents. Check for screen sharing, session recording, remote assistance and onlookers. If the intended recipient changes or an unexpected state appears, close the Pase and create a new one. A short code makes joining convenient, but it cannot replace human verification.

2. Inspect the file before selecting it

Open the correct file and review its name, contents and version. Names can reveal customers, projects or personal data even when content is protected. Photos and documents may contain author, location, comments or editing history. Remove information that should not travel or export a clean copy when necessary.

Mándamele limits each file to 50 MB, but it does not classify malware, secrets or regulated data. It has no data-loss-prevention engine. In a professional environment, apply organisational policy before using a Pase and do not bypass an approved channel.

3. Decide whether additional encryption is needed

The application uses the browser’s WebRTC transport and does not add a file password, application encryption or fingerprint verification. Content is not deliberately uploaded to Mándamele servers, but that property does not answer every threat model. A compromised endpoint can read the file before or after transfer.

For high-impact material, encrypt the file first with an appropriate tool and share its password over a separate channel. Keep a verifiable original until receipt is confirmed. If you require auditing, revocation, identity controls or corporate policy enforcement, use a solution that explicitly implements those capabilities.

4. Protect the code, QR and network

Create the Pase immediately before use. Show the QR directly or send the code through a private conversation; do not publish it or leave it in an exposed screenshot. Check that the link uses mandamele.com. An unconnected Pase expires after ten minutes, but during that window the code remains a valid invitation.

Avoid networks you do not trust when the risk calls for it. The application configures STUN and not TURN, so some restrictive networks will not connect. A VPN may block WebRTC or be part of your protection; do not disable it by habit without considering policy and context. The priority is an authorised known network, not merely making the connection succeed.

5. Watch the transfer

Keep both browsers open and observe progress. Do not treat the appearance of a partial preview as completion. A file travels in chunks and the receiver reconstructs it after the expected size arrives. If interrupted, there is no server copy to resume from; create a new Pase and resend from the original.

At the receiver, check name, size and whether the file opens. For critical information, compare a checksum using an external tool or validate contents through an agreed method. Mándamele validates structure and size during assembly, but it does not provide a user-facing verified hash exchange.

6. Close the session and clean up copies

Close the Pase when finished. The interface revokes local object URLs when items are removed or the session unmounts, and the service ends state on closure or expiry. That cannot erase the sender’s original, a saved download, clipboard history or a preview indexed by the operating system.

Review downloads, trash, automatic synchronisation, backups and shared devices. The recipient should retain only what is needed and protect it according to sensitivity. If the handoff was intended to be temporary, agree when both copies will be removed. Privacy ultimately depends on both endpoints as well as the network path. Record that agreement outside the file if it matters, because Mándamele does not manage retention schedules or send deletion reminders. On managed devices, follow the organisation’s disposal process instead of assuming that trash removes every backup.

Apply the same cleanup to text. If either person copied a message, the operating system or a clipboard manager may retain it after the Pase closes. Clear sensitive clipboard contents, close previews and remove temporary exports when the exchange is complete.

  • Before: person, device, file and the code-sharing channel.
  • During: connection, progress and expected recipient.
  • After: integrity, download, closure and agreed deletion.