Last reviewed 24 August 2026
Service status.
Core delivery implemented
- Website
- Public pages, security documentation, legal pages, and the learning center are implemented.
- Secret delivery
- Operational in the application: the browser encrypts text and files, the server stores ciphertext, and a generated link can retrieve the record once.
- Encryption
- AES-256-GCM browser encryption is implemented. Optional passphrases use PBKDF2-SHA-256 with 250,000 iterations.
- Expiry and deletion
- Records expire after the selected lifetime, up to seven days. A successful retrieval atomically claims and removes the stored ciphertext.
- Accounts and email
- No accounts, recipient tracking, or email delivery are offered. Share links and optional passphrases through channels you control.
- API
- The browser uses internal JSON endpoints, but there is no supported public API, SDK, authentication contract, or integration SLA.
- Advertising
- No advertising is currently served. Any future ads will be limited to reviewed editorial guide pages, not the composer, recipient view, legal pages, or status screens.