Skip to content

📝 Compose a secret message

Your text is encrypted client-side and can only be decrypted once.

How does it work?

The message is encrypted in the browser with a one-time key. This key is never sent to the server.

  • When submitting, only the encrypted text is sent to the server.
  • The generated link contains the key inside the #fragment (after the hash symbol) – the server never sees that fragment.
  • On opening, the browser decrypts using the key from the link. Afterwards the entry is deleted once.
Note: The #fragment is evaluated only in the browser. Test the link in a private window before sharing.

Security notes

  • Share the link only with people you trust—the link contains the decryption key.
  • The link works exactly once or expires after 60 minutes at the latest.
  • We store no keys and no plain text.

Echo Vault does not store keys and deletes the text after the first retrieval or after 60 minutes at the latest.

Technology at a glance

Client-side encryption (e.g. AES-GCM in the browser): the random key is derived into key material and the message is encrypted locally. The server only receives the ciphertext package.

The key is passed in the link as a #fragment (e.g. #k=…). Browsers never send fragments to the server; decryption happens locally for the recipient.

Single use: after successful decryption the stored ciphertext is deleted on the server or removed automatically after expiry.

Transparency: this page is a convenience interface—you can review the plain text locally before sending. No advertising or marketing trackers of your plain texts.