Privacy policy
Effective August 31, 2026
The short version: we built this service so that the most sensitive thing about it, your secrets, never reaches us in readable form. Around that, we collect as little as possible, keep it as briefly as possible, and sell none of it.
What we never receive
Secrets are encrypted on your device, and the keys travel in the part of your links that browsers never send to servers. So the following never reach us at all:
- The plaintext of anything you share or request.
- Encryption keys and passphrases.
- 2FA seeds, and the codes computed from them.
- The prompt text of a secret request (it travels inside the link).
This is structural: a full copy of our database would contain sealed boxes we cannot open, and neither could anyone who stole it.
What we store, and for how long
- Encrypted shares and request responses. Sealed ciphertext plus its settings (view limit, expiry). The ciphertext is erased the moment a secret burns, is revoked, or expires. The remaining record, which lets the link honestly say "this was burned", is deleted entirely seven days after expiry.
- Open history. For each share or request we record events (created, viewed, revoked) with a timestamp and the country the action came from. We deliberately store no IP address and no browser details with these events. They are deleted with the share's record.
- Account data. If you sign in: your email address and sign-in timestamps. Sign-in links expire after 15 minutes and work once; sessions last 30 days. All tokens are stored only as one-way hashes.
- Notification addresses. If you ask for an alert when something is opened or filled, the email address for that alert is stored with the share or request and deleted with it.
- Operational logs. Like nearly every website, our infrastructure keeps short-lived technical logs (request paths, status codes, timing) for debugging and abuse prevention. Keys cannot appear in them because key material never leaves your browser.
Cookies and tracking
One cookie, and only if you sign in: a session cookie that keeps you signed in. No analytics scripts, no advertising, no tracking pixels, no fingerprinting. We do not sell or share personal information with anyone for marketing, and there are no third-party ad networks here to opt out of.
Emails we send
Only the ones you ask for: sign-in links, email confirmations, and the open or filled alerts you turn on. No newsletters, no marketing.
Service providers
- Cloudflare hosts the service, stores the database, delivers our email, and provides the bot check on forms. Like any host, Cloudflare processes IP addresses and request metadata to serve and protect the site. Data is stored on Cloudflare's network, primarily in the United States.
- Google Fonts serves the site's two typefaces, so your browser requests font files from Google's servers when a page loads.
Those are the only third parties involved. There are no others.
Security
Encryption happens in your browser with AES-256 before anything is sent. Everything travels over HTTPS. Tokens are stored only as one-way hashes, and secrets are erased rather than flagged when they burn. No system is perfectly secure, but ours is built so a breach would expose sealed boxes, not secrets. If a breach affects your personal information, we will notify you as the law requires.
Your rights and choices
- Burn any share yourself, at any time, with its management link. No account needed.
- Everything else deletes itself on the schedules above, with no action from you.
- To access or delete your account data, email us. We will verify the request from the account's address and act on it promptly.
- Depending on where you live, you may have legal rights to access, correct, delete, or port your personal data. Email us and we will honor them.
Children
The service is not directed to children under 13, and they may not use it. If you are under the age where you live for consenting to data processing, do not use the service.
Where we operate
The service is operated from the United States. If you use it from elsewhere, your data is processed in the United States under this policy.
Changes
If this policy changes materially, the updated version will be posted here with a new effective date. We will not weaken what "we never receive" means: that part is architecture, and changing it would be a different product.
Contact
Privacy questions or requests: support@onetimeauth.app