Skip to content
Security

Stop emailing passwords: how to share sensitive info safely

Written by Sam Serrien ·

lokr secure links for passwords and files

Firing off a password by email. Dropping a spreadsheet full of client data on WeTransfer. It happens every day, in every office. And every single time that sensitive information ends up somewhere it doesn't belong.


Why email isn't a vault

Email feels personal, but it isn't. A password you send today still sits in at least two mailboxes five years from now: yours and the recipient's. Probably also on a phone, a backup server, or an old laptop that has long since been resold.

What happens if someone breaks into one of those mailboxes?

  • Every historical password is suddenly exposed, including ones for systems the recipient no longer has access to
  • Client data forwarded years ago is still sitting there, ready to read
  • Attachments with personnel data, invoices or contracts are downloadable by whoever gets in
  • You have zero visibility on who the recipient has forwarded it to since

Heads up

Mail servers keep messages indefinitely by default. Even if you delete the email, the copy in the recipient's inbox stays. Once sent, you lose control.


WeTransfer and GDPR

"Let's just pop it on WeTransfer." Sounds harmless, but for personal data it's a poor choice. WeTransfer processes data on servers outside the EU, and as a sender you have limited control over how long a file stays available or who can download it.

For a holiday photo, fine. For an employee roster, a membership list or a customer database, it's a liability you shouldn't accept.

What does GDPR actually require?

Personal data must be shared with appropriate security. "Appropriate" means: encryption in transit and at rest, access limited to who needs it, and control over retention. A publicly reachable download link that stays live for a week does not clear that bar.


The real problem, laid out

What you'd want

  • One-time use: after the recipient opens it, the link is dead
  • Encryption from sender to recipient
  • Only the right person can open it
  • No trace left in mailboxes for years

What actually happens

  • Passwords by email, readable in the inbox forever
  • Spreadsheets with client data on WeTransfer, publicly downloadable
  • Login details in Slack or Teams, visible to everyone in the channel
  • Files that hang around until someone happens to clean them up

Why we built lokr

At GeNx we kept seeing the same pattern: well-meaning people sharing sensitive information the wrong way, simply because there wasn't a practical alternative. So we built one: lokr.be.

lokr is a tool for sharing passwords, text and files through secure links. The recipient opens the link, sees the content, and the link disappears. No trail in mailboxes, no copies drifting around.

  • Burn links: one-time use. Once opened, the content is gone
  • Password-protected links: only someone with the password can open it
  • Email verification: only the specified address gets access
  • Share text, passwords or files through the same secure flow
  • Encrypted and hosted in Belgium, no detours through non-EU servers

A concrete example

You're giving a new bookkeeper access to an online platform. Instead of emailing the password, you create a lokr link with email verification and burn-on-open. Only her address can see it, she opens it once, and after that it no longer exists. No password sitting in an archive email five years from now.


When to use it

  • Handing over passwords or API keys to a colleague, supplier or client
  • Sharing a spreadsheet with personnel data with your accountant
  • Delivering a contract or quote without leaving a public download link around
  • Passing CMS, server or tool credentials to an external freelancer
  • Sharing sensitive text or notes that can disappear after reading

And the passwords your team uses every day?

lokr is ideal for sharing something once. For passwords that several colleagues need every day, a password manager with shared vaults is the better choice. Read why we recommend Proton Pass for businesses or see our password management offering.


Frequently asked questions

Share it the smart way

Stop emailing passwords. Create your first secure link on lokr.be and share sensitive info without second-guessing.

Try lokr