They may be encrypting the file with a parameter passed in the URL. In this case, assuming no logs are kept, it would be a reasonable encryption setup.
The encryption key is passed after the hash (#) in the URL.
Therefore the keys are never sent to the server over the HTTP request (more info about this can be found here: https://nofile.io/security/).