So you find us again

Share information safely and simply on the internet

Encrypted in your browser. Deleted automatically once it has been opened.

Your browser cannot encrypt safely here

This page needs your browser’s Web Crypto interface. It is only available over a secure HTTPS connection and in current browsers. We deliberately disable the form rather than transmit your message unprotected.

Open the page over https:// and use a current version of Firefox, Chrome, Edge or Safari.

Secret message
0 / 1.000
Self-destruct
Extra password

Every message is deleted automatically after 7 days.

Your secure link is ready

  • Deleted the first time it is opened.
  • The key sits behind the # sign and exists only in this link. We cannot recover it – copy the link in full.
The problem

The problem is not the passwords. It is how they travel.

Credentials have to be handed over constantly – to colleagues, to contractors, to a neighbour for the wifi. Almost always through channels that were never built for it.

  • Nothing is ever deleted

    An email sits in several mailboxes, in backups and in the archive. A chat history sits on every device and in the cloud backup. Still there in five years.

  • It spreads on its own

    Forwarded, quoted, pasted into a group. Before long nobody knows how many people have seen that one password.

  • The damage surfaces late

    An old mailbox is taken over, a laptop is sold, an account is breached. Those old credentials often still work.

The only thing that really helps: the secret must never be left lying anywhere in the first place.

How it works

Three steps – and it is gone again.

  1. Step 1

    You write

    Your message is encrypted in your browser – before anything reaches us.

  2. Step 2

    We only ever store gibberish

    We only hold encrypted text. The key sits behind the # sign in the link – browsers never send that part to a server.

  3. Step 3

    Read once, then gone

    Opening it removes it from the database at once. A second attempt finds nothing – for us either.

Trust

Why we cannot read along

Not because we promise not to, but because we simply do not have the key. Encryption uses AES-256-GCM; add a password and a second key is derived from it with 600,000 PBKDF2 rounds. Both happen in your browser.

  • If somebody copies our database, all they hold is unreadable gibberish. The key was never in it.
  • We could not open your message even if we wanted to – or if somebody demanded it of us.
  • With the extra password an attacker needs both: the complete link and the password.
Encryption
AES-256-GCM
Password derivation
600,000 PBKDF2 rounds
Key stored by us
no — only in the link
Use cases

What people use EasySafeShare for

Access within a team

Pass server passwords, API keys or database credentials to colleagues without them living in a chat forever.

Clients and contractors

The new freelancer needs access once. Afterwards it should not still be sitting in their inbox.

Personal

The wifi password for guests, credentials for the family, a number nobody else should read.

Honestly

What technology cannot do

So you know what you are relying on – and what you are not:

  • The recipient can copy everything

    Whoever opens the message can photograph it or write it down. No encryption in the world prevents that.

  • One intercepted link is enough

    Whoever opens the complete link before the recipient reads the message. That is what the password option is for – and why link and password should travel separately.

  • Your device stays your responsibility

    We protect the path in between. A compromised computer or a malicious browser extension is outside what we can secure.

Questions

Frequently asked questions

How do I send a password securely?

Paste the password above and create a link. The content is encrypted in your browser, and the resulting link can be opened exactly once – after that the message is gone. Send the link through a channel only the recipient reads, and add a password for particularly sensitive credentials.

Why should I not send passwords over chat or email?

Because they stay there. An email ends up in several mailboxes, in backups and often in archives; a chat history stays on every device and in the cloud backup. Anyone who gains access to one of those accounts months later still finds the password. A one-time link only exists until it is first opened.

What does end-to-end encryption mean here?

Encryption happens in your browser before the data reaches our server. The key sits behind the # sign in the link, and browsers never transmit that part of an address to a server. What we hold is therefore unreadable ciphertext.

Can you read the messages?

No – not because we promise not to, but because we do not have the key. Even if somebody copied our entire database, all they would hold is encrypted data. We could not hand over content on an official request either.

What happens if I lose the link?

The message is lost. The key exists only in that link, we never stored it and cannot recover it. Always copy the link in full, including the part behind the # sign.

How long does a link stay valid?

Every message is deleted automatically after 7 days at the latest – even if it was never opened. With self-destruct enabled it disappears the moment it is first retrieved.

What if somebody intercepts the link?

Whoever opens the complete link before the recipient can read the message – no encryption prevents that. That is what the password option is for: an attacker then needs the link AND the password. Send the two through different channels, for example the link by chat and the password by phone.