Secret: share a password properly

A link that opens once, encrypted in your browser. Free, no account.

Open Secret

A password you send does not go away

A password sent by email sits in two mailboxes, in two backups and in the search index of both mail clients, for years. A password pasted into a team channel stays readable by everyone who joins that channel later, including after the person who wrote it has left.

The problem is not the handover: it is what remains afterwards. A one-time link replaces a permanent message with one that removes itself, read or not.

How it works

  1. You paste the secret

    The text is encrypted in your browser before anything is sent. The encryption key stays on your computer alone.

  2. You get a link

    The decryption key lives in the fragment of the address, the one part no browser sends to any server. We store ciphertext and nothing else.

  3. The other person opens it once

    The content is served, then destroyed. Nobody can read it again, ourselves included. Left unread, it expires on its own.

We cannot read your secrets

Not a policy but a consequence: the key never reaches our servers. Anyone who obtained our database would obtain ciphertext.

The link is the secret

Whoever holds the link holds the content, until the first read. Send it over a different channel from the one carrying the rest, and there is nothing left to intercept in one place.

A lost link is a lost secret

We have no way of recovering it, and that is the price of the rest. We would rather say so upfront than discover it with you.

Why Deepy offers this tool

Handling sensitive data rules out sharing secrets over email or instant messaging. To guarantee the integrity of the transfer, viewing cannot rest on a page load alone: it requires a deliberate action by the user in the browser, validated by a cryptographic proof that only the key carried in the link can produce. That is the strict minimum for a secret to be readable at the intended moment and at no other.

For complete isolation, no third-party script and no audience measurement is loaded on the page, because the decryption key resides in the recipient’s own browser. This deliberately spare design removes indirect data leaks while consuming very little server resource, which is what makes the tool available free of charge, with no commercial transaction and no concession on protection standards.

A project in this area?

Talk it through with one of our engineers. Thirty minutes is usually enough to tell whether we are the right people for it.