A few things to know.
Practical answers before you send something sensitive.
Do I need an account?
No. The MVP has no accounts, sign-in, teams, payments or email delivery. Create a link and share it yourself.
What can I send?
Text up to 10 KiB measured as UTF-8 bytes: passwords, API keys, tokens, recovery codes or sensitive notes. There are no files or uploads, and HTML is displayed as text.
Can OneTimeRead read my message?
The normal flow encrypts it in your browser and does not send the key or plaintext to the server. You still trust the JavaScript delivered by this service and the browser running it. See the security model for the limits.
Does opening the link use the secret?
No. A page load displays the reveal button. Clicking that button performs the one-time claim. This separation protects against ordinary previews and crawlers.
How long can a secret last?
Choose 1 hour, 24 hours or 7 days. The default is 24 hours. Revealing the secret makes it unavailable immediately, even if time remains.
Why is my secret unavailable?
It may have expired, been claimed already or never existed at that identifier. We show the same message for all three situations: “This secret is no longer available.”
Can a lost link or key be recovered?
No. We cannot recover the key, decrypt a stored message or restore a consumed secret. Ask the sender to create a new one.
What if two people click Reveal at the same time?
Only one claim can receive the ciphertext. The other gets the generic unavailable response. Whoever has the full link may be that first person.
What happens if the connection drops during reveal?
The server may already have removed the message. Claims are not retried automatically. Ask the sender for a new secret if the first delivery is uncertain.
Do secret pages contain ads or trackers?
No. Creation and reveal pages use only first-party resources. Public information pages may load advertising, analytics and Clarity. Those integrations never belong on secret pages.