One Time Secret

Encrypted in your browser with AES-256-GCM, decrypted once, then permanently destroyed. Open-source crypto, no logs, no tracking — even we cannot read your message.

Message content:
0 / 5000
Expiration time:

How to send a one-time secret message

Send a self-destructing encrypted note in 4 simple steps

  1. Write your secret message

    Type your confidential one-time secret in the secure text box above.

  2. Choose encryption settings

    Pick an auto-generated password or set your own; choose an expiry time between 1 and 24 hours.

  3. Click Encrypt

    Click the Encrypt button — AES-256 encryption happens entirely in your browser.

  4. Share the one-time secret link

    Copy the one-time link and send it to your recipient through any channel you trust.

What to share with a one-time secret message

  1. Passwords and API keys

    Use a one-time link to hand over a password, API key, or access token. The secret is deleted after a single read, so it never sits in your email or chat history.

  2. Recovery phrases and private credentials

    Wallet recovery phrases, MFA backup codes, and private credentials are exactly what a self-destructing link is for: read once, then permanently destroyed.

  3. Anything you would not put in email

    If you would hesitate to type it into an email or a chat, send it as a one-time secret link instead — encrypted in your browser, zero logs, no signup.

For one-off secrets — a password, a key, a recovery phrase — a one-time link is the safest way to hand it over.

Frequently Asked Questions

How does scyscan encrypt my message?+

We use AES-256-GCM with PBKDF2 key derivation. Encryption happens client-side in your browser, so your plaintext never touches our servers.

Are messages really deleted after reading?+

Yes. The encrypted ciphertext is wiped from our database the moment the recipient decrypts it once. Even we cannot recover it afterwards.

Can scyscan see my messages?+

No. The decryption password never leaves your browser, and we never store plaintext. We operate under a strict zero-logs policy and require no account.

Is scyscan a good Privnote alternative?+

Yes — same one-time-link UX, but with stronger client-side encryption, zero logs, and no signup required.

What can I share safely?+

Passwords, API keys, recovery phrases, private credentials, or any text you would not put in email or chat.

Is it really free?+

Yes — unlimited messages, no signup, no credit card. scyscan is supported by our other security tools, not by selling your data.