private by design
Share something once.
Password-protected secrets that disappear after they’re revealed.
or press ⌘ ↵
- 01Your browser encrypts the secret — plaintext never leaves this tab.
- 02The server receives only ciphertext it cannot read.
- 03Opening requires both the private link and the password.
- 04A successful reveal atomically deletes the stored copy.
- 05No accounts, no analytics, no secret history.
Honest footnote: no tool can erase what recipient devices, screenshots, or clipboard managers do afterward. What we control — our server — never sees plaintext, and forgets the ciphertext the moment it is read.
one-time secret sharing
Private sharing, without a permanent copy.
once is a free, browser-encrypted way to send passwords, API keys, recovery codes, access instructions, and private notes. No account, inbox, or searchable history.
the complete trip
How once works
- 01
Seal in your browser
Argon2id derives strong keys from your password, then AES-256-GCM encrypts your text locally. Plaintext never leaves this tab.
- 02
Share two pieces
Send the private link and password separately when you can. Opening the secret requires both.
- 03
Reveal and destroy
The first valid reveal atomically removes the encrypted copy from the server before your browser decrypts it.
privacy boundary
What the server sees
Ciphertext, KDF parameters, an expiry time, and an HMAC-protected proof. It never receives your plaintext, password, or the link secret stored after the # in the URL.
Good for
Passwords, API keys, recovery codes, credentials, access details, and private text.
Not a vault
Text only, up to 64 KB, with a fixed expiry. Keep anything permanent somewhere built for storage.
The honest limit: no website can erase screenshots, clipboard history, copied text, or records a recipient keeps after opening it.
the fine print
Questions, answered.
- Is once free and accountless?
- Yes. There is no account, sign-in, payment, analytics profile, or secret history. Create a link and share it.
- Does the server ever receive plaintext?
- No. Encryption and decryption happen in the browser. The server receives ciphertext, expiry data, KDF parameters, and an HMAC-protected unlock proof.
- What happens after a wrong password?
- The encrypted secret survives. Repeated failed attempts trigger a temporary cooldown, but a wrong password never consumes the note.
- Can a revealed or expired secret be recovered?
- No. A successful reveal permanently deletes the stored encrypted copy, and expired copies are purged. There is no recovery path or archive.