// guide

How to send sensitive documents securely

You need to send a photo of your driver's license to a new landlord. Or a bank statement to a lender. A signed form to HR. The default is to attach it to an email, or text it, because that's how everything else moves.

That's not necessarily a disaster. The real risk isn't usually someone intercepting the file in transit. It's that the file ends up sitting in two inboxes indefinitely, in accounts that might not be especially well-secured, accessible to whoever can get into those accounts at some later point. Something worth protecting deserves a bit more thought than a regular attachment.

Here are the actual options, and what each one does and doesn't cover.

Password-protect the file, send the password separately

PDF files can be password-protected natively. On Mac, open the PDF in Preview, go to File, Export as PDF, and check the Encrypt box. On Windows, Adobe Acrobat and a number of third-party PDF tools do the same. Zip archives can be encrypted too. You send the file one way, the password another.

"Another channel" matters here. If you email a PDF to someone and then email the password to the same address, you've added a step without changing anything. The password should travel by text, phone call, or a different service entirely. The same logic applies whenever a credential needs to travel separately from what it protects; see how to share a password without texting it for the general version of this problem.

This works well for forms, signed documents, and tax records. The recipient doesn't need anything beyond what opens a PDF. They just need the password.

The limit: once they've typed the password and opened the file, the document is on their machine. You can't take it back from there.

An expiring shared link

Google Drive, Dropbox, and similar services let you share a file through a link you can revoke, or set to expire after a certain date. The document lives in one place rather than two inboxes. You can confirm the link was accessed before you close it. You can set it to view-only so they can see it but not download their own copy.

This is the better choice for anything large, or anything where you want to know whether it was actually opened. Set the expiry at the point you share it. A drive link that never gets revoked stays open indefinitely, which is the same problem you were trying to get ahead of.

The limit here is the same one as everywhere: if they screenshot or download a local copy before you revoke access, that copy exists outside your control.

In person, for the highest-stakes items

A Social Security card, a passport, original legal documents: sometimes the honest answer is not to send them at all. Walk it over, let whoever needs it make a copy, and take the original home.

If in-person isn't possible, physical mail has a better track record than most people expect for originals. Difficult to intercept at scale, and there's a paper trail. It costs a stamp and a day.

This option gets dismissed because it takes effort. But the overhead is a one-time cost, and some documents are worth it.

For short sensitive text, a hidden message

Most of the time, "sending a sensitive document" is not really about a large file. It's about the piece of information the file contains: a bank account number, a PIN, a password, a confirmation code. Something short enough to be a message.

For those, there's a different option. GhostCode hides a short message inside an ordinary photo. You write the message, set a key, and send the photo through any normal channel. It looks unremarkable in a chat or email. The recipient opens it in the app with the key you've already shared separately, and the message is there. To anyone else, it's just a picture.

This doesn't replace a document when you actually need a document. If your lender wants a PDF of your bank statement, they need the PDF. But if what they really need is your account number, or if you're passing a PIN alongside a form, hiding it in a photo is cleaner than plain text. The key travels separately by whatever means you both have; for why that matters, see what "out of band" actually means in messaging.

GhostCode also lets you set a timer on the message, so it can only be opened within a window you control. Useful when you want the information to be readable once and not sitting around afterward.

The limit that applies everywhere

Whatever method you use, the protection ends the moment the other person can read it. A screenshot, a photo of the screen, a note written down: the information is now somewhere you didn't put it, and you have no say in what happens next.

Some apps and services imply otherwise. Disappearing messages and self-destruct timers stop an app from re-opening something after a set point. They don't erase copies that were already made. There's no secure-sharing method that solves the other person's screen.

What these tools do is reduce exposure during transit, and reduce how long a copy sits somewhere you don't control. That's the honest version of what's on offer. Reduce, not eliminate.

Questions people ask

Is it safe to email a photo of my ID?

Safer than most people assume, but not ideal. A photo sent as a plain attachment can sit in both inboxes for years. For something like a driver's license, password-protecting the image first and sharing the password by text is a reasonable step up. For a passport or Social Security card, in-person or mail is worth the extra effort.

What's the safest way to send an account number or PIN?

A phone call is often the simplest answer. If it needs to be in writing, putting it in a hidden message in GhostCode is more deliberate than plain text or SMS that lives in both chat histories indefinitely.

Can I just password-protect a Word document?

Yes, and it works. In Word or Excel, go to File, Info, Protect Document, then Encrypt with Password. The same rule applies: send the password through a different channel than the file itself.

What should I never send by regular text message?

SMS is plain text. A Social Security number, a full bank account number, a password, or any combination of identifying details is worth more care. If someone gains access to either phone's message history, everything sent that way is readable. Use a phone call for one-time information, or a tool that keeps the information out of the message thread entirely.

// try it

Send the message, not just the document

GhostCode hides your message inside a photo or a QR code, so only the person you choose can read it. See how it works.

Back to the blog