Understand what protects your secret.
A clear security boundary matters more than a sweeping promise. Here is what OneTimeRead does, and what you still need to protect.
Encryption happens in the browser
OneTimeRead uses the browser’s Web Crypto API with AES-GCM, a fresh 256-bit key, a random 12-byte IV and a 128-bit authentication tag for each secret. The server receives ciphertext, the IV, a format version and an allowed expiration. It never needs your plaintext or decryption key.
The key lives in the fragment
The complete link contains the key after #. Browsers exclude this fragment from the HTTP request. Keep the full link private: the identifier and key together grant access to anyone who has them.
Private pages have no third-party resources
Creation, reveal and secret API routes are separated from the public site. They use first-party resources only, a restrictive Content Security Policy, no-referrer and no-store headers. Analytics, advertising and session recordings are restricted to public information pages.
A claim is atomic
Reading requires a deliberate POST request. The server uses a database transaction and a row lock so that two competing claims cannot both receive the message. The record is deleted before the successful response is completed. Page loads, previews and ordinary crawlers do not consume it.
What this does not protect against
- A compromised browser, device, browser extension or service delivering altered JavaScript.
- A person or messaging provider who receives or inspects the complete link.
- A recipient copying, photographing or saving the plaintext after reveal.
- Backups or storage remnants retaining old ciphertext; database deletion is not a guarantee of physical erasure.
Use HTTPS and a trusted device. Do not treat one-time sharing as a substitute for rotating credentials, limiting access or revoking an exposed key.
Anonymous does not mean no request metadata
Network connections reveal an IP address to infrastructure. A short-lived keyed identifier derived from the connection’s origin supports creation rate limits; it is kept separate from the secret record. See our privacy notice for the handling of public pages and abuse controls.
Report a problem
Contact hi@valle.dev with the affected route and a safe reproduction. Do not include a live secret, full secret link or private credential.