CipherDriveâ„¢ can protect an encrypted file while it is stored and delivered through the documented sharing workflow. After a recipient successfully decrypts and obtains the content, that recipient controls what happens to their copy.
The recipient's browser or client reconstructs the plaintext file locally. At that point, the file may be saved to the recipient's downloads folder, opened in another application, copied, or otherwise handled outside CipherDrive's encrypted-storage boundary.
A recipient may be able to:
save the file locally;
make additional copies;
forward it to another person;
upload it to another cloud provider;
place it on removable storage;
screenshot or screen-record content;
extract information from the file;
re-share it through another CipherDrive object.
These actions are outside the core zero-knowledge guarantee because the recipient has already been given legitimate access to the plaintext.
Revocation can stop future requests through CipherDrive's revoked sharing path, but it cannot delete a copy that already exists on the recipient's device or another service.
Where supported, an authenticated recipient may be able to save shared content as a separate encrypted object in their own CipherDrive storage.
An independent saved copy can have its own:
object identifier;
storage lifecycle;
encryption and key material;
account ownership;
sharing state.
Deleting or revoking your original source object does not necessarily delete an independent copy stored in another user's account.
For safety, abuse prevention, legal compliance, or operational integrity, Ackaia may retain limited records showing that one object originated from or was saved from another shared object where the feature requires this information.
Such provenance or sharing records do not necessarily give Ackaia the plaintext file contents or the plaintext encryption keys.
Before sharing sensitive information, consider whether you trust the recipient to retain it appropriately after access.
If disclosure would be unacceptable once a recipient has a readable copy, a public or downloadable sharing mechanism may not be appropriate for that content.
Encryption can control access before decryption; it cannot control a trusted recipient after decryption.