Encrypted in your browser · zero-knowledge

Share a secret that
disappears after one read.

Send a password or private note without putting a readable copy on our servers. Your recipient reveals it once; then the stored envelope is deleted.

No account required Passphrase by default Automatic expiry
readonce.app
You write a secret

How it works

Three steps. Then it’s gone.

No account required. A successful reveal consumes the stored encrypted envelope.

01
STEP 01

Write it, lock it

Paste a message. It’s encrypted in your browser before it ever reaches us — we never see the contents.

02
STEP 02

Share the link

You get a one-time link and a separate passphrase. Send them through different channels so no single intercept can open it.

03
STEP 03

It burns on read

When your recipient deliberately reveals it, the secret is shown once and permanently destroyed — for them and for you.

Create now

Make a one-time link.

No signup or setup. Your message is encrypted on this device before upload.

Encrypted in your browser before it ever leaves this page.

0 B / 64.0 KiB

Link settingsPassphrase protected · 1 hour

You'll see the link and passphrase once. We can't recover them.

Features

Built so the secret can’t outlive its moment.

Zero-knowledge by design

Encryption happens in your browser. The key lives in the link fragment — which never reaches our servers.

Truly one-time

Read-once isn’t a setting you can forget. It’s the only way a secret works here.

Self-destruct timers

Set a deadline from five minutes to seven days. Unopened secrets expire on their own.

Strong passphrases

Generate words, characters, or a PIN. Weak and common passwords are caught by a strength check before you share.

The reveal

Watch a secret cease to exist.

When your recipient reveals a drop, it’s decrypted, shown a single time, then disintegrated — the ciphertext is wiped and the link goes dead. No archive, no backup, no undo.

Decrypted locally, never on our servers
Displayed exactly once
Erased the instant it’s seen
readonce.app/s/7Kq2-mP9x
One secret, waiting.

Revealing it reads once, then destroys it for everyone.


Security

The math does the trusting, not us.

We designed readonce so that even we can’t read your secrets. Here’s how.

Client-side encryption

AES-GCM 256 runs in your browser. The decryption key lives only in the URL fragment, which browsers never send to a server.

Zero-knowledge storage

We hold ciphertext we cannot read. Even compelled, the secret itself is not ours to give up.

Atomic one-time retrieval

A successful reveal consumes the stored envelope in the same database operation that returns it. A second reveal gets nothing.

Weak passwords blocked

Common and easily-guessed passphrases are caught by a strength check before you can share a link.

Lose the passphrase and the secret is unrecoverable — by anyone, including us. That’s the point.

Send the secret.
Not a permanent copy.

Create an encrypted one-time link. No account, delivery setup, or recovery copy.