getpigeon.io

Big files,
homed.

The friendly way to send heavy files, and the only one that lands them straight in your own cloud, never ours.

The file transfer that never touches your files.

Someone drops files on your own branded portal and they fly straight into your Google Drive or SharePoint. Pigeon carries the link, the audit trail and the good news, never a copy of the bytes.

1

They drop

A client or supplier lands on your pigeon.yourwebsite.com page, drags in files or a folder, and confirms their email with a code.

2

It flies home

Files go directly into your own cloud storage. Nothing is parked on a third-party service, and Pigeon keeps no copy once they land.

3

You hear the coo

Everyone named gets an email the moment files arrive, with a link to view or download. When they do, the files stream straight from your own cloud, never from us.

Everything a homing pigeon should carry

Fast, branded, and yours.

🎨

Your brand, not ours

Your wordmark, your colours, your domain. Recipients never see us.

â˜ī¸

Files stay in your cloud

Google Drive or SharePoint. Your data never leaves your own storage.

đŸ”Ĩ

Secure notes

Send a password or key that self-destructs after it is read. Set views and expiry.

🔑

Per-transfer access

Each drop is its own locked folder. People see only what is theirs.

đŸ“Ŧ

Know when it lands

Get told when files are viewed or downloaded, WeTransfer style.

đŸĒļ

Nothing to install

A link is the whole thing. Works for anyone, on any device.

Built to keep your data yours. Everything is encrypted in transit. Files are stored only in your own Google Drive or SharePoint, so there is no shared bucket, no seven-day retention, no third-party cloud holding your work. Pigeon keeps the link and the audit trail, never the bytes.

Security by design

Boring where it counts

The interesting part is the pigeon. The security is deliberately dull.

Sign-in (SSO)

Staff sign in with the workspace account they already have, Google Workspace or Microsoft 365, over OpenID Connect and OAuth 2.0. Pigeon never sees or stores a password. Before a session is issued we verify the account is a real, active member of your domain, using Google’s hosted-domain claim and Microsoft’s directory (tenant) check, so an outside Google or Microsoft account cannot slip in. Sessions are short-lived, encrypted, and http-only.

Your data stays in your cloud

Files are written straight into your own Google Drive or SharePoint and nowhere else. Pigeon keeps the link, the audit trail and the file list, never the bytes. Because the store of record is your own tenant, your files inherit the region, retention and ISO 27001 / SOC 2 posture you already run with your provider.

Encryption

Everything is served over modern TLS (1.2 and 1.3) with certificates issued and renewed automatically. Secure notes are end-to-end: the message is encrypted in the sender’s browser with AES-GCM and the key lives only in the link fragment, so it never reaches our servers. Notes self-destruct after a set number of views or an expiry, whichever comes first.

Access and audit

Every transfer is its own access-scoped folder. External recipients confirm ownership of their email with a one-time code before they can download. Links are revocable, expiry is enforced per transfer, and a nightly purge removes anything past its date. Every send, view and download is written to an audit trail you can see.

Data protection

Built for your privacy obligations

Designed to support GDPR, UK GDPR and global privacy law, not to get in the way of it.

Data minimisation

The most private data is the data we do not hold. Pigeon stores no file content and asks for no more than a name and an email to route a transfer, which keeps your exposure under GDPR and UK GDPR small by construction.

Residency and erasure

Because files live only in your own cloud tenant, they stay in the region you have configured with your provider. Deleting a transfer removes it from your Drive or SharePoint and clears its metadata from Pigeon, giving you a clean path for right-to-erasure requests.

Global privacy law

The same minimise-and-keep-it-in-your-tenant model is designed to support obligations under GDPR and UK GDPR, the California CPRA, and comparable regimes such as Australia’s Privacy Act and Canada’s PIPEDA. A Data Processing Agreement is available on request.

Few sub-processors

Your workspace provider is the store of record, so the list of parties that ever touch your data stays short and is documented. No third-party file-sharing service sits in the middle, and nothing is sold, mined or repurposed.

Request your portal

Tell us a little about your business and we will set up a branded portal that lands files in your own cloud.