about once
A quieter way to share something sensitive.
once is a small, accountless tool for sending private text without leaving a permanent readable copy on the server.
the starting point
Privacy is the starting point, not an add-on.
Your browser seals the secret before upload. The password and the private fragment of the link stay outside the stored record, so a database copy alone is not enough to read what you shared.
Why one-time?
Passwords, recovery codes, API keys, and private instructions often need to cross from one person to another. They rarely need a searchable inbox or a permanent paste. once keeps that trip deliberately short: create, share, reveal, delete.
A successful reveal removes the encrypted database row before the recipient's browser decrypts it. Expired rows are also removed. There is no account history or recovery archive to browse later.
What the design values
- Plaintext encryption and decryption stay in the browser.
- No account, analytics profile, advertising pixel, or third-party runtime script.
- Short, explicit expiration choices instead of permanent storage.
- One atomic server operation decides the first successful reader.
- Honest limits are documented instead of hidden behind a security slogan.
Use it for the right job
A good fit
Passwords, tokens, recovery codes, credentials, private notes, and access instructions that need one controlled handoff.
Not a good fit
Permanent records, emergency communications, large files, regulated archives, or anything that must remain recoverable.
Who made it
once is operated by Arsam Sabbagh as an independent public utility. Operator and contact details are in the legal notice. The exact data boundary is documented in privacy, and the technical model is described in security.