Last reviewed 24 August 2026
Service status.
Core delivery implemented
- Website
- Public pages, security documentation, legal pages, and the learning center are implemented.
- Secret delivery
- Operational in the application: the browser encrypts text and files, the server stores ciphertext, and a generated link can retrieve the record once.
- Encryption
- AES-256-GCM browser encryption is implemented. Optional passphrases use PBKDF2-SHA-256 with 250,000 iterations.
- Expiry and deletion
- Records expire after the selected lifetime, up to seven days. A successful retrieval atomically claims and removes the stored ciphertext.
- Accounts and email
- No accounts, recipient tracking, or email delivery are offered. Share links and optional passphrases through channels you control.
- API
- The browser uses internal JSON endpoints, but there is no supported public API, SDK, authentication contract, or integration SLA.
- Cost and advertising
- SecretShare is currently a free, ad-free tool. Advertising scripts and placements are disabled across the application.