End-to-end encrypted · zero-knowledge

Share a secret that
disappears after one read.

Paste a message. readonce encrypts it in your browser, hands you a one-time link, and erases it the instant it’s opened — for everyone.

No account to send Free forever tier Open security model
readonce.app
You write a secret

How it works

Three steps. Then it’s gone.

No accounts required to send. No trace left behind once it’s read.

01
STEP 01

Write it, lock it

Paste a message. It’s encrypted in your browser before it ever reaches us — we never see the contents.

02
STEP 02

Share the link

You get a one-time link and a separate passphrase. Send them through different channels so no single intercept can open it.

03
STEP 03

It burns on read

The moment your recipient opens it, the secret is shown once and permanently destroyed — for them and for you.

Features

Built so the secret can’t outlive its moment.

Zero-knowledge by design

Encryption happens in your browser. The key lives in the link fragment — which never reaches our servers.

Truly one-time

Read-once isn’t a setting you can forget. It’s the only way a secret works here.

Self-destruct timers

Set a deadline from five minutes to seven days. Unopened secrets expire on their own.

Strong passphrases

Generate words, characters, or a PIN. Weak and common passwords are caught by a strength check before you share.

The reveal

Watch a secret cease to exist.

When your recipient reveals a drop, it’s decrypted, shown a single time, then disintegrated — the ciphertext is wiped and the link goes dead. No archive, no backup, no undo.

Decrypted locally, never on our servers
Displayed exactly once
Erased the instant it’s seen
readonce.app/s/7Kq2-mP9x
One secret, waiting.

Opening it reads once, then destroys it for everyone.


Security

The math does the trusting, not us.

We designed readonce so that even we can’t read your secrets. Here’s how.

Client-side encryption

AES-GCM 256 runs in your browser. The decryption key lives only in the URL fragment, which browsers never send to a server.

Zero-knowledge storage

We hold ciphertext we cannot read. Even compelled, the secret itself is not ours to give up.

Guaranteed destruction

On first read the record is overwritten and deleted. Expiry sweeps catch anything left unopened.

Weak passwords blocked

Common and easily-guessed passphrases are caught by a strength check before you can share a link.

Lose the passphrase and the secret is unrecoverable — by anyone, including us. That’s the point.

Share a secret that
keeps itself.

Free to send. No account needed to create your first one-time link.