The launch release
1.0 is the first OpenDrop release we recommend for everyone. It's the version that ships in the App Store, Google Play, Microsoft Store, GitHub Releases for Linux, and to existing macOS preview testers. The desktop server, mobile apps, control plane, and encrypted relay are all on the same protocol baseline.
Headline End-to-end encryption on every transfer path
File contents are encrypted on the sending device with ChaCha20-Poly1305 IETF AEAD (RFC 8439). The 32-byte content key is derived with HKDF-SHA256 from your account's shared secret — computed identically on each of your devices, so the key is never sent over the network — with a fresh random 12-byte nonce prefix per transfer. The encryption applies to:
- Chunked uploads, true-streaming uploads, and downloads (including range-sliced byte ranges)
- Thumbnails fetched from remote devices
- Direct desktop↔desktop relays via
/send-to - LAN/Wi-Fi HTTP and HTTPS transfers
- Phone-to-phone nearby Wi-Fi transfers
- Bluetooth Low Energy fallback transfers
The mobile build runs the encryption through Apple CryptoKit on iOS and BoringSSL on Android API 28+, with a pure-Dart fallback for older devices. The desktop build uses Python's cryptography wheel (with the OpenSSL backend). The wire format is byte-identical across every implementation and is covered by a shared test-vector file.
Headline No plaintext fallback, protocol v2 is mandatory
The desktop server and mobile clients advertise and require X-OpenDrop-Protocol: 2 on every request. Servers respond with HTTP 426 Upgrade Required to any client below protocol v2, and v1.0 clients refuse to connect to a server that reports a lower protocol version. Account-deletion, receipts, app-version, and subscription endpoints are deliberately exempt from the gate so that pre-1.0 users can still clean up.
Headline Auto-fallback transport: Wi-Fi LAN → peer-to-peer → encrypted relay
The mobile and desktop apps now choose the fastest available transport automatically. mDNS discovery (Bonjour service type _opendrop._tcp.local.) finds devices on the same Wi-Fi for direct LAN streaming. Across different networks, OpenDrop tries a direct peer-to-peer connection over WebRTC, using our own self-hosted STUN servers for NAT traversal (no third-party STUN, and no TURN). When a direct connection isn't possible, traffic falls back to OpenDrop's own end-to-end-encrypted WebSocket relay: the free tier uses our Oracle Cloud relay, and Pro subscribers get the high-throughput Fly.io relay with automatic failover to Oracle if Fly is ever down. Bluetooth LE carries small payloads when Wi-Fi isn't available. The free tier prefers P2P and treats the relay as a backstop; Pro prefers its fast dedicated relay and uses P2P as the fallback. Pairing and signaling run through our control-plane Cloudflare Worker, which never sees your files — and there is no third-party tunnel to download.
Headline Cross-platform parity
iOS
App Store · Apple CryptoKit · Cupertino UI · iOS 26 Liquid Glass adaptation · Sign in with Apple · Background NSURLSession uploads
Android
Google Play · BoringSSL-accelerated AEAD on API 28+ · Foreground-service uploads with sticky notification · Multi-window drag-and-drop
Windows
Microsoft Store and direct .exe installer · Inno Setup · Bundled ffmpeg · CLI mode included
Linux
x86_64 and aarch64 .AppImage · AppStream metadata for software centers · CLI mode included
macOS
In active development, preview builds available to existing testers; not yet shipped to the Mac App Store at 1.0.
Headline OpenDrop Pro
- Multi-device mesh: pair multiple phones and multiple desktops to a single account; same-account auto-connect via mDNS account hash.
- High-throughput Fly.io WebSocket relay for large cross-network transfers, with automatic failover to a backup Oracle Cloud relay and no per-transfer size cap. (Free transfers use the Oracle Cloud relay.)
- Cross-device file conversion: image (HEIC/PNG/JPG/WebP/BMP/TIFF), video (MP4/MOV/AVI/MKV/WebM), and RAW (CR2/NEF/ARW/RAF). Phone files queue against the desktop's
ffmpeg; one-click undo restores from per-conversion backups. - Pricing: $2.99/month or $24.99/year (≈30% annual discount). Cross-platform entitlement via RevenueCat, one subscription unlocks Pro on every device linked to your account.
New Drag-and-drop and rich browsing
- Thumbnails for images, videos, PDFs, and SVGs across local and remote devices.
- In-app preview for images (with
InteractiveViewerzoom), code and text files, and PDFs. - Multi-select bottom action bar; breadcrumb folder navigation.
- Recently Deleted with 30-day retention on the desktop server.
- Drag-and-drop between tabs on desktop and across the mobile file/folder views.
- Chrome-style device tab bar on desktop with per-device favicons.
New Theming & accessibility
Nine built-in color palettes: OpenDrop Brand (cerulean blue + aqua cyan, the default), Ocean Breeze, Tide Pool, Sea Glass, Lilac Night, Cloud Blue, Peach Cream, Rose Petal, and Lavender Mist. Light, dark, and follow-system modes. iOS Cupertino dialogs honor system text-size and Dynamic Type.
New Accounts & auth
- Sign in with Google, Apple, Microsoft, or email/password through Firebase Authentication.
- Email verification flow for email/password sign-ups.
- Hosted account-deletion page (
delete-account-page), your account record, device records, relay addresses, HMAC secret, and analytics counters linked to your account are removed within 30 days. Local files on your devices are never touched. - Sentinel records that force sign-out across any device still holding old credentials.
New Privacy controls
- Analytics opt-out in Settings on both mobile and desktop. When disabled, the app sends an
X-OpenDrop-Analytics-OptOut: 1header and our infrastructure discards the heartbeat without recording it. - Site-wide cookie banner with Google Consent Mode v2; default-deny posture; honors browser Global Privacy Control (GPC).
- New Vulnerability Disclosure Policy with coordinated-disclosure timelines and a safe-harbor clause.
- New EU/UK 14-day withdrawal form reproducing Directive 2011/83/EU Annex I(B).
New Headless / CLI mode
The desktop server can run without a GUI. A CLI client talks to a running GUI through a shared connection file; single-instance detection on a dynamically chosen port keeps multiple invocations from colliding. The CLI is included in every desktop build.
Heads-up Pre-1.0 builds are no longer accepted
Any client running protocol v0 or v1 (pre-1.0 builds, including all internal previews) is rejected by the 1.0 server with HTTP 426 Upgrade Required. There is no compatibility mode and no plan to add one, the security goal is to eliminate the downgrade-attack surface where an attacker could strip the encryption header and force an unencrypted body. Please install the latest 1.0+ build before continuing to use OpenDrop.
Heads-up What’s still in flight
- macOS desktop is still in active development at 1.0. The macOS build is the same PySide6 desktop server that ships on Windows and Linux, just not yet released to the Mac App Store. iOS and Android cover the mobile side.
- Discovery is local-network-aware, not location-aware. Devices find each other through mDNS on Wi-Fi, Bluetooth Low Energy proximity, or cloud pairing. There is no GPS in the loop, and the apps don’t read your coordinates.
Reference Version markers
| Component | Version |
|---|---|
| Flutter mobile app | 1.0.0+18 |
| Desktop server (Python/PySide6) | 1.0.0 |
| OpenDrop wire protocol | 2 (transport & HMAC layer) |
| E2EE wire format | chacha20poly1305-v1 |
| Cloudflare Worker control plane | WORKER_PROTOCOL_VERSION = 2 |
| OpenDrop WebSocket relay | 0.7.16 |
| KV schema | _schema_version: 2 (per-device records) |