ToolboxKit

How to Share Sensitive Documents Safely Online

Sooner or later, everyone has to send something private over the internet: a passport scan for a rental application, a signed contract, a tax form, medical paperwork. Most of us attach the file to an email and hit send. It works, but it also leaves copies of sensitive data sitting in several inboxes, backups, and servers long after the task is done.

You don't need to be a security expert to do better. A few habits cover most of the risk.

Why a plain email attachment isn't private

Email was designed in an era when privacy wasn't a priority. Even when your connection to the mail server is encrypted, the message itself is typically stored in readable form on the providers' servers, on the recipient's devices, and in any backups. A few consequences follow:

  • The attachment lives in your "Sent" folder, the recipient's inbox, and possibly a shared mailbox, for years.
  • If any one of those accounts is compromised, the document is exposed.
  • Forwarding spreads the file further, without your knowledge.

None of this means email is unusable. It means the file itself should be protected, not just the channel.

Share only what's necessary

The safest document is the one you never send. Before attaching anything, ask:

  1. Do they really need the whole document? If a landlord only needs proof of income, you can often send one page rather than a full year of statements.
  2. Can sensitive fields be hidden? Account numbers, ID numbers, and addresses can often be masked if the recipient doesn't need them. Make sure the redaction is real: drawing a black box over text in some editors leaves the original text underneath. Flatten the page or export it as a fresh image or PDF afterwards.
  3. Is there a deadline? Decide when the file should stop being available.

Protect the file itself

Adding a password to a document means that even if the email is intercepted or forwarded, the contents stay unreadable without the key. For PDFs, most readers and editors let you set an "open" password.

Some rules that make this actually work:

  • Use a strong, unique password, ideally a long passphrase rather than something guessable like a birthdate.
  • Send the password through a different channel. If you emailed the file, share the password by phone call, text message, or a messaging app. A password sent in the same email as the file protects nothing.
  • Don't reuse the password you use for any account.

Encryption quality matters too. Older password schemes in some document formats are weak; modern PDF encryption (AES-256) is considerably stronger than legacy options.

Consider a link instead of an attachment

Cloud storage services let you share a link rather than a copy. Used carefully, this gives you more control:

  • Restrict access to specific people rather than "anyone with the link".
  • Set an expiry date so access ends automatically.
  • Turn off downloading or resharing where the option exists.
  • Revoke the link once the other party confirms receipt.

Be aware that "anyone with the link" really means anyone: links can be forwarded, pasted into chats, or end up in browser history on a shared computer.

Clean the hidden data first

Files carry more information than what is visible on screen. Photos can include the location and device that took them, and documents can record author names and edit history. Before sending a photo of a document, or a file you created, check what metadata it contains and strip it if it isn't needed. Our guide on hidden data in your photos explains what to look for.

Verify who you're sending it to

A large share of document leaks happen because the file went to the wrong person, not because of a clever attack. Scammers also impersonate landlords, employers, and banks to request IDs.

  • Confirm the request through a contact method you already trust, not the one in the message that asked.
  • Double-check the email address character by character; look-alike domains are common.
  • Be suspicious of urgency. "Send it in the next hour or lose the offer" is a classic pressure tactic.

Clean up afterwards

Once the exchange is finished:

  • Delete the shared link or file from cloud storage.
  • Remove downloaded copies from shared or public computers, and empty the trash or downloads folder.
  • If you sent the file by email and your provider allows it, delete it from Sent and Trash.

A quick checklist

  1. Send the minimum necessary.
  2. Redact properly, then flatten.
  3. Remove hidden metadata.
  4. Password-protect the file, or use an expiring, restricted link.
  5. Share the password separately.
  6. Confirm the recipient is who they claim to be.
  7. Delete copies when you're done.

If you need to lock a PDF before sending it, you can use the Password Protect PDF tool, which adds a password to your document so you can share it more safely.