One Time Secret
Encrypted in your browser with AES-256-GCM, decrypted once, then permanently destroyed. Open-source crypto, no logs, no tracking — even we cannot read your message.
How to send a one-time secret message
Send a self-destructing encrypted note in 4 simple steps
Write your secret message
Type your confidential one-time secret in the secure text box above.
Choose encryption settings
Pick an auto-generated password or set your own; choose an expiry time between 1 and 24 hours.
Click Encrypt
Click the Encrypt button — AES-256 encryption happens entirely in your browser.
Share the one-time secret link
Copy the one-time link and send it to your recipient through any channel you trust.
Frequently Asked Questions
We use AES-256-GCM with PBKDF2 key derivation. Encryption happens client-side in your browser, so your plaintext never touches our servers.
Yes. The encrypted ciphertext is wiped from our database the moment the recipient decrypts it once. Even we cannot recover it afterwards.
No. The decryption password never leaves your browser, and we never store plaintext. We operate under a strict zero-logs policy and require no account.
Yes — same one-time-link UX, but with stronger client-side encryption, zero logs, and no signup required.
Passwords, API keys, recovery phrases, private credentials, or any text you would not put in email or chat.
Yes — unlimited messages, no signup, no credit card. scyscan is supported by our other security tools, not by selling your data.