Share a secret. Not with the server.

Send a password, API key, private key, or TOTP seed straight to one person's browser — end-to-end encrypted, no account, and gone the moment it's used.

Free to use · Link works once · Nothing kept on our servers


What people send with CipherSend

Drag or use your mouse wheel to scroll.

See all use cases


Four steps, no account

1

Create a link

One click generates a random, single-use session.

2

Share it

Send the link or QR code to your recipient over whatever channel you already trust.

3

Verify the phrase

Both sides see a short word phrase; read it aloud or compare it to confirm you're talking to the right person, not an imposter.

4

Approve and send

Once both sides approve, the secret is encrypted in your browser, sent, and decrypted only in the recipient's browser.

Read the full walkthrough


Built to know as little as possible

No account, ever. Most link- and chat-based sharing requires a login or leaves the secret sitting in a message history. CipherSend has zero accounts and collects no personal information.

Nothing durable to steal. The server never stores your secret, your encryption keys, or your verification phrase — not even briefly. There's no database of past shares to breach.

The server can't read it either. CipherSend's relay only forwards encrypted, structurally-valid data between the two browsers — it never inspects or interprets what's inside.

One link, one use. Each session supports exactly two participants and expires on its own; there's nothing left to revisit or leak later.

See the full comparison


Encrypted where it matters — your browser

End-to-end encryption using ECDH key exchange and AES-256-GCM, computed entirely in your browser. Keys never leave your device.

You verify who you're talking to. A short, human-readable phrase lets both people confirm the connection hasn't been intercepted, before anything is sent.

Nobody sends until both agree. Each side independently controls when their own secret can be sent or displayed — this decision is never made by the server.

Sessions don't linger. Idle sessions time out, and every session has a hard expiry regardless of activity.


Quick answers

No. CipherSend has no accounts, logins, or personal information collected.

No. The secret, the encryption keys, and the verification phrase are never stored on the server — only your two browsers ever handle them.

It's a one-time confirmation that a real person — not an automated link preview — is opening the session, so your link can't be silently occupied before your intended recipient arrives.

Don't approve. A mismatched phrase means the connection may not be with who you expect — treat it as a failed handshake and start a new session.

View full FAQ