One Time Secret

Encrypted in your browser with AES-256-GCM, decrypted once, then permanently destroyed. Open-source crypto, no logs, no tracking — even we cannot read your message.

Message content:
0 / 5000
Expiration time:

How to send a one-time secret message

Send a self-destructing encrypted note in 4 simple steps

  1. Write your secret message

    Type your confidential one-time secret in the secure text box above.

  2. Choose encryption settings

    Pick an auto-generated password or set your own; choose an expiry time between 1 and 24 hours.

  3. Click Encrypt

    Click the Encrypt button — AES-256 encryption happens entirely in your browser.

  4. Share the one-time secret link

    Copy the one-time link and send it to your recipient through any channel you trust.

Frequently Asked Questions

How does scyscan encrypt my message?

We use AES-256-GCM with PBKDF2 key derivation. Encryption happens client-side in your browser, so your plaintext never touches our servers.

Are messages really deleted after reading?

Yes. The encrypted ciphertext is wiped from our database the moment the recipient decrypts it once. Even we cannot recover it afterwards.

Can scyscan see my messages?

No. The decryption password never leaves your browser, and we never store plaintext. We operate under a strict zero-logs policy and require no account.

Is scyscan a good Privnote alternative?

Yes — same one-time-link UX, but with stronger client-side encryption, zero logs, and no signup required.

What can I share safely?

Passwords, API keys, recovery phrases, private credentials, or any text you would not put in email or chat.

Is it really free?

Yes — unlimited messages, no signup, no credit card. scyscan is supported by our other security tools, not by selling your data.