A password sent through a messenger stays there for ever — in the history, in the backup, in the recipient’s cloud. Write it here instead: the text is encrypted right in your browser, you get a link, and after the first read the note is gone. The key lives in the link itself and never reaches our server.
Send the link to the recipient. It can be opened once.
The link can be opened once. We know neither the text nor the key — a lost link cannot be restored.
It opens once and disappears immediately. Make sure you are ready to read it now.
A string we cannot read, and its name. The text is encrypted in your browser with AES-GCM, and the key is placed in the part of the link after the hash — by the design of the protocol that part is never sent to a server at all, only the browser sees it. The note’s name is a hash of the same secret, so nothing can be recovered from it either.
What it protects against: the secret does not stay in the correspondence for ever, does not end up in backups and does not resurface a year later in the chat history. What it does not protect against: someone who intercepted the link before the recipient. Even that you will notice, though — the recipient gets an already burned note.
Nearby: encrypt a file with a password, if the secret is not text, and a password generator.
404 VPN keeps no visit logs, no DNS queries and no traffic contents. Not because we promise, but because there is nothing to hand over on request.
How it works →Was this useful?
One tap, no sign-up