Privacy Policy
Effective date: 2026-06-18
This Privacy Policy explains how this 1TimeSekret instance processes information when you create or view one-time secret links.
1. What This Service Does
This service allows users to share sensitive text through links that are designed to be read once, then deleted.
2. Data We Process
- Encrypted secret payloads stored temporarily in Redis until viewed or expired.
- Secret metadata such as expiration choice and whether a passphrase was used.
- Operational counters (for example, secrets created/viewed) used for service statistics.
- Technical request metadata needed for security and abuse prevention (for example, rate limiting).
3. Data We Do Not Intend to Store
- Plaintext secrets in persistent storage.
- Passphrases in persistent storage.
- Secret content in analytics events.
4. Security Model
- Secrets are encrypted server-side using AES-256-GCM before storage.
- Encrypted secret records are stored in Redis under temporary keys and are not designed for long-term archival.
- A passphrase may be required to decrypt protected secrets.
- Non-passphrase links are consumed atomically when revealed.
- Passphrase-protected links are deleted after successful decryption or after max failed attempts.
- Rate limiting is used to reduce abuse.
4A. Where Secrets Are Stored (Public Transparency)
- Storage backend for secrets: Redis (ephemeral key-value store).
- Stored value: encrypted payload envelope, plus minimal metadata needed for reveal flow.
- Default expiration choices: 1 hour, 24 hours, or 7 days.
- Deletion triggers: first successful reveal, TTL expiry, or security destruction after max failed passphrase attempts.
5. Retention
Secrets are retained only until one of the following occurs: successful reveal, expiration (TTL), or security-triggered destruction. Aggregated counters may be retained longer for operational reporting.
6. Analytics and Cookies
Google Analytics may be used only after user consent. If enabled, analytics is intended for product usage insights and not for secret content. Users can decline analytics tracking via the consent banner.
7. International Transfers
If this instance is hosted in a different jurisdiction from the user, data may be processed in the hosting region.
8. Legal Bases (GDPR)
Where GDPR applies, processing is based on one or more of the following legal bases: legitimate interests (service security and reliability), performance of a contract (providing the requested secret-sharing service), and consent (analytics tracking).
9. Data Subject Rights
Depending on your jurisdiction, you may have rights to request access, correction, deletion, restriction, objection, and portability.
To exercise rights, contact the deployment operator through the published support channel. You may be asked to verify your identity.
10. California Privacy Rights (CCPA/CPRA)
If applicable, California residents may request disclosure of personal information categories processed, deletion of personal information, and correction of inaccurate personal information, subject to legal exceptions.
11. Children
This service is not intended for children under 13 (or the minimum age required in your region). If you believe a child has provided data, contact the operator to request deletion.
12. Your Choices
- Do not submit information you are not authorized to share.
- Use passphrases for extra protection.
- Decline analytics consent if desired.
- Review our Cookie Policy for storage controls.
13. Security Reporting
Security researchers can report vulnerabilities using the contact channel published in security.txt.
14. Contact
For privacy requests or questions, contact the operator of this specific deployment through the support channel published by the host.
15. Updates
This policy may be updated over time. Continued use after updates means you accept the revised policy.