once
← create a secret

privacy

Privacy, in plain language.

The secret is encrypted before it leaves your browser. This page explains the smaller amount of technical data the service still needs to work.

Last updated · 11 August 2026

the short version

once has no accounts, analytics, advertising, payment system, or secret history. It does not receive your plaintext, password, or the link secret after the # in the URL.

The encrypted note record

When you create a note, the browser sends a random note identifier, ciphertext, nonce, salt, key-derivation parameters, an HMAC-protected unlock proof, protocol version, and expiration time. The database also records when the row was created.

The server stores these fields only to deliver the encrypted note once. A successful unlock atomically deletes the live row before returning its ciphertext. Unopened notes expire after the period selected by the sender—between five minutes and seven days—and expired rows are removed on service activity and by a background cleanup process.

Deletion is permanent in the live service. once does not provide recovery or a secret archive. No dedicated backup process for the notes database is configured on this host.

Short-lived abuse prevention

The server receives your IP address as part of an ordinary internet connection. It uses that address in process memory to enforce short request limits and reduce automated abuse. These timestamp records are not written to the notes database. During normal operation, stale entries are cleared within roughly ten minutes at the latest, or sooner when the app restarts.

Wrong unlock proofs are counted against the random note identifier for about one minute. The counter does not contain the password or plaintext and disappears from memory after its window or an app restart.

Logs and diagnostics

Routine nginx access logging is disabled for this service, avoiding a normal server log of IP addresses and private note paths. Warning-level operational error diagnostics may still contain network or request details when something goes wrong. On this host, nginx logs rotate daily and are normally retained for up to about fourteen days.

Application errors returned to the browser are sanitized. The app is designed not to log request bodies, proofs, passwords, plaintext, or URL fragments.

Your browser

  • The chosen light or dark theme is stored in your browser's local storage when that feature is available.
  • The app does not set account, advertising, or analytics cookies.
  • Your browser, device, clipboard manager, password manager, extensions, screenshots, and recipient may retain information outside once's control.

Service providers and purpose

Hosting and network infrastructure necessarily process connection data to deliver the site and encrypted records. once does not send runtime data to analytics, advertising, social-media, font, or content-delivery services.

Technical data is used only to provide the requested service, enforce one-time delivery, prevent abuse, diagnose failures, and keep the service secure and available.

Questions and requests

Contact me@asabbagh.com for a privacy question or request. Because once has no accounts and holds random encrypted records, it may be impossible to identify a particular note as yours without the note identifier. Never email a plaintext secret or password.

Material changes to these practices will be reflected here with a new update date. See the legal notice for operator information.