Skip to content

📝 Create a private message

Your text is encrypted in your browser. The link is intended for one retrieval and expires after 60 minutes at the latest.

How does it work?

The message is encrypted in the browser with a one-time key. This key is never sent to the server.

  • When submitting, only the encrypted text is sent to the server.
  • The generated link contains the key inside the #fragment (after the hash symbol) – the server never sees that fragment.
  • When retrieved, the server deletes the encrypted message before your browser decrypts it using the key in the link. A decryption failure can therefore use up the link.
The #fragment is read only by the browser. Do not open the real link as a test: retrieving it uses up the message.

Security notes

  • Share the link only with people you trust—the link contains the decryption key.
  • The link works exactly once or expires after 60 minutes at the latest.
  • We store no keys and no plain text.

Echo Vault stores no keys or plaintext. The encrypted message is deleted on first retrieval. The link expires after 60 minutes at the latest; file deletion is scheduled for that time.

Technology at a glance

Client-side encryption (e.g. AES-GCM in the browser): the random key is derived into key material and the message is encrypted locally. The server only receives the ciphertext package.

The key is passed in the link as a #fragment (e.g. #k=…). Browsers never send fragments to the server; decryption happens locally for the recipient.

Single retrieval: the server deletes the stored ciphertext when it is retrieved, before browser decryption. The token is valid for at most 60 minutes; file deletion is scheduled for that time.

Transparency: this page is a convenience interface—you can review the plain text locally before sending. No advertising or marketing trackers of your plain texts.