Support
Need help with Valise? Send feedback, open a public issue, or email us — then the answers to the questions people ask most.
Send Feedback
Found a bug, or want Valise to do something it doesn't? The feedback form is the quickest route — no account, and nothing is posted publicly. An email address is optional; leave it blank and the report is anonymous.
Opening it from inside Valise fills in your Valise version, OS version, device model and language. You can see all four on the page before you send, edit them, or clear them entirely — the app itself never transmits anything to us.
Report an Issue Publicly
Prefer to track it in the open? The link below opens a new GitHub issue pre-filled with a template. Leave share links and passwords out of it.
Contact Us
Prefer email? Write to support@mgcrea.io.
Common Questions
What does Valise create in my Cloudflare account?
An R2 bucket, named valise by default, with three lifecycle rules — one each for transfers kept 1, 7, 30 days — and a Worker, also named valise, bound to that bucket with an upload secret and served at its workers.dev address. Valise shows the plan before it creates anything. If your account already has a Worker called valise that is not Valise's, it proposes another name rather than overwrite it.
Which permissions does Valise need?
Sign in with Cloudflare asks for Account Settings: Read, and read and write access to Workers R2 Storage and Workers Scripts. To paste a token instead, create an account API token (Manage account › Account API tokens, not R2’s own API tokens page, which issues S3 credentials) with Workers Scripts: Edit, Workers R2 Storage: Edit and Account Settings: Read.
What does it cost to run?
Valise’s own price is not set yet. On Cloudflare’s side, R2 charges no egress fees, so downloads cost nothing however many times a link is opened. Storage and operations are billed by Cloudflare to your account: R2’s free tier covers 10 GB-month of storage, 1 million Class A and 10 million Class B operations a month, across all your buckets. Each uploaded part is one Class A operation.
What does my recipient see?
A page served by your Worker listing the files, their sizes and when the link expires, with a download for each file. Downloads can resume where they stopped. No account, no app and no JavaScript are needed. A link shared from iPhone while the upload is still running shows “Still arriving” and refreshes itself until the files are there.
What happens when a link expires?
Your Worker refuses it straight away. Cloudflare’s lifecycle rules delete the files from your bucket; they run on Cloudflare’s schedule, so files can linger briefly, but they can no longer be downloaded. To end a transfer early, delete it from Valise’s list of sent transfers, which removes its files from the bucket.
How do passwords work?
Password protection is part of Valise Pro. When you set one, your Worker keeps a salted hash of it, never the password itself, and asks for it before the page or any file opens. Valise does not keep the password either, so send it to your recipient yourself, ideally by another channel than the link. A recipient who enters it gets one cookie, valid for that transfer only, until it expires. The iPhone share sheet cannot set a password yet.
Are my files end-to-end encrypted?
No. They are stored in your own R2 bucket and anyone holding the link can download them, unless the transfer has a password. Links cannot be guessed — each carries 128 random bits — but treat one like the files it opens, and pick a short expiry for anything sensitive.
How large can a transfer be?
Valise sets no limit of its own. Files go up in equal parts of 64 MiB, growing to at most 90 MiB for very large files, and R2 allows up to 10,000 parts per file — just under 900 GiB per file.
Can I see transfers sent from my other devices?
Yes. The list of sent transfers is read from your bucket, so a transfer sent from another Mac appears too, along with how much storage Valise’s transfers use and your account’s R2 total.
What are the requirements?
macOS 26 or later on the Mac, iOS 26 or later on iPhone, and a Cloudflare account.