Paste a message. readonce encrypts it in your browser, hands you a one-time link, and erases it the instant it’s opened — for everyone.
No accounts required to send. No trace left behind once it’s read.
Paste a message. It’s encrypted in your browser before it ever reaches us — we never see the contents.
You get a one-time link and a separate passphrase. Send them through different channels so no single intercept can open it.
The moment your recipient opens it, the secret is shown once and permanently destroyed — for them and for you.
Encryption happens in your browser. The key lives in the link fragment — which never reaches our servers.
Read-once isn’t a setting you can forget. It’s the only way a secret works here.
Set a deadline from five minutes to seven days. Unopened secrets expire on their own.
Generate words, characters, or a PIN. Weak and common passwords are caught by a strength check before you share.
When your recipient reveals a drop, it’s decrypted, shown a single time, then disintegrated — the ciphertext is wiped and the link goes dead. No archive, no backup, no undo.
Opening it reads once, then destroys it for everyone.
We designed readonce so that even we can’t read your secrets. Here’s how.
AES-GCM 256 runs in your browser. The decryption key lives only in the URL fragment, which browsers never send to a server.
We hold ciphertext we cannot read. Even compelled, the secret itself is not ours to give up.
On first read the record is overwritten and deleted. Expiry sweeps catch anything left unopened.
Common and easily-guessed passphrases are caught by a strength check before you can share a link.
Free to send. No account needed to create your first one-time link.