Effective: 24 August 2026
Overview
This policy applies to the SecretShare website and one-time secret-delivery service. SecretShare encrypts content in the sender’s browser, receives and temporarily stores ciphertext, and returns that ciphertext once to a recipient who possesses the complete link.
The service does not require an account. This policy will be updated before accounts, payments, analytics, or materially different processing are introduced.
Data we process
We do not ask you to create an account on this website. When you visit, infrastructure providers may automatically process technical information required to deliver and secure the page, such as your IP address, browser type, requested URL, timestamp, and basic request logs.
If you contact us, we process the information in your message so we can respond.
Secret text and files
Text and files are encrypted in your browser before upload. The server receives ciphertext, the encryption nonce, a passphrase-derivation salt, an expiry time, and a Boolean value indicating whether a separate passphrase is required. The server does not receive the browser-generated master key stored after the URL #.
Encrypted records are deleted after the first confirmed retrieval or rejected after expiry. Recipients can still copy or retain decrypted content, and a compromised browser or delivered script could expose it; one-time delivery cannot control the recipient’s device.
Advertising status
SecretShare uses Google AdSense publisher ID ca-pub-2654122264996557. Google’s advertising script is present for site verification and future ad serving. Google’s use of advertising data is governed by its own policies and the consent choices presented to visitors.
Traffic from the EEA, UK, and Switzerland must use a Google-certified consent management platform where required. Auto ads must exclude the secret composer, recipient view, legal pages, and other non-editorial screens before serving is enabled.
Retention and security
The cookie preference stays on your device until you clear browser data or reset it. Encrypted secrets remain available until first retrieval or the selected expiry, up to seven days. Infrastructure logs follow the hosting provider’s operational and security retention. Contact messages are kept only as long as needed to respond and meet legitimate legal or security requirements.
No internet service can guarantee absolute security, but we aim to minimise collection and limit access to information that is genuinely needed.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of your personal information, and to object to or withdraw consent for certain processing. You may also complain to your local data-protection authority.
Because this site does not have user accounts, we may need enough information to verify and locate a relevant contact message or record before fulfilling a request.
Contact and policy updates
For privacy questions or requests, email privacy@secretshare.dev. If this policy changes materially, the effective date above will be updated and a prominent notice will be posted when appropriate.