ENCRYPTED DROP // NO ACCOUNT REQUIRED

Leave no
loose ends.

Create a one-time secret link for a password, recovery code, API key, or private note. It can destroy its encrypted copy after the first read.

● AES-256-GCM encrypted● key stays out of storage● free, no account
NEW DROPSESSION 08F-A9
0 / 4000
Burn protocol

Encrypted in this browser. The server stores ciphertext, never the decryption key.

ADVERTISEMENT
Your ad could be
the last thing they see.
Quiet placements. High intent.
NO ACCOUNTSCLIENT-SIDE ENCRYPTIONNO RECOVERYTEXT UP TO 4,000 CHARACTERS

HOW IT WORKS

Three steps.
One private handoff.

01

Write the secret

It’s encrypted on your device. We never get the key, and we don’t want it.

02

Pass the link

Send it through whatever channel you trust. Or whichever one you distrust least.

03

Let it expire

First-read links delete their stored ciphertext when revealed. Timed links remain readable until their one-hour or 24-hour deadline.

4,000

characters per encrypted drop

“The internet has a long memory.
We don’t.
ADVERTISEMENTClearly marked ad space

Advertisements are kept separate from the secret-link controls.

WHEN TO USE IT

Share sensitive text without leaving the text in chat.

Send a password once

Hand off a temporary login or initial password without pasting the password itself into email or chat history.

Pass an API key or code

Share a short token, recovery code, Wi-Fi password, or configuration value with one recipient.

Send a private note

Give someone up to 4,000 characters they can decrypt in their browser without creating an account.

Know the limits

This is a secure handoff tool, not a password manager. Anyone with the complete link can reveal the secret. A recipient can copy or screenshot it, and automated link scanners may trigger a first-read link. For highly sensitive credentials, share the link through a trusted channel and rotate the credential after use.

PLAUSIBLE DENIABILITY

Questions? Briefly.

Is it really free?+

Yes. A small number of clearly marked ads pay the tab. Your secret is never used for targeting.

Can you read my secret?+

No. Encryption happens before the secret leaves your browser. Only the person holding the complete link can decrypt it.

Where is the decryption key stored?+

The key is placed after the # in the link. Browsers do not send that fragment to the server, so the database receives only the encrypted text and initialization vector.

What is the difference between first-read and timed links?+

A first-read link deletes its ciphertext when it is revealed and expires unread after seven days. One-hour and 24-hour links can be opened more than once until their deadline.

Can a burned secret be recovered?+

No. Once the stored ciphertext is deleted or expires, this service has no recovery feature. A recipient may still have copied the plaintext while it was visible.

Can a link preview burn my secret?+

The recipient must press Reveal & burn, which prevents ordinary previews from fetching the secret. Some automated security tools can behave like a user, so avoid first-read links when the delivery channel aggressively scans links.