How it works

Secure Exchange sends a password or private note to one person, once. Here's what happens to it, and what we can and can't see.

When you share a secret

Your browser makes a random key, a four-word phrase, and an encrypted copy of your text. The encryption is AES-256-GCM, done on your device with a key built from both the random key and the phrase. The phrase is stretched with Argon2id first, which makes guessing it slow.

Only the encrypted copy is sent to us. The random key goes at the end of the link, after the # sign. Browsers never send that part of an address to a server, so we never see it, and we never see the phrase either.

Why the link and the phrase go separately

Opening a secret takes both. If an email is forwarded or a message is read over someone's shoulder, one on its own is no use. So send them different ways: the link by email and the phrase by text message, or the link in a chat and the phrase over the phone.

When it's opened

The recipient's browser rebuilds the key from the link and the phrase, and proves to us that it has the right phrase. Only then do we hand over the encrypted copy, and we delete it in the same step. Their browser decrypts it. If two people try at the same moment, only one gets it.

Your status link

When you share a secret you also get a private status link. It shows whether the secret has been opened, how many wrong phrases have been tried, and lets you delete it early. It never shows the secret.

What we keep

While a secret is waiting we hold the encrypted copy, the settings needed to rebuild the key, a fingerprint (a hash) that lets us check the phrase without knowing it, a fingerprint of your status link, when it was made, when it expires, and how many wrong phrases have been tried.

Once it's gone we keep a short record of what happened and when (opened, destroyed, deleted, removed or expired) until a week after its expiry date, so your status link can tell you. Then that goes too. We don't store IP addresses, and there are no analytics or tracking cookies.

What that means for you

Keeping it free of abuse

Cloudflare Turnstile runs a quick security check when you share a secret or send a report, and each connection can only share a few secrets a minute. If someone sends you a secret that turns out to be a scam, malware or anything illegal, use Report this link on its page. We can't read secrets, but we can remove them.