PrivSend

How Drops work

Create a drop address · Send a secret · Suomeksi

What a Drop is

A normal privsend secret goes outward: you write something, and you send the link to one person. A Drop is the reverse. You publish one stable address, and anyone — with no account — can send an encrypted message to you, files and all. You read it later. Think of it as a private, encrypted “contact me”: a tip line, a whistleblower inbox, an intake box that only you can open.

Your two links do opposite jobs

When you create a drop address you get two links. Keeping them straight is the one thing that matters most.

🔑 Your SECRET console link (…/SECRET#…) is your private way in. With it and your passphrase you read your messages. Never share it. The word SECRET is written into the link on purpose: if you ever glance at a link you are about to paste and see it, stop — that one is not for sharing.
📣 Your public drop address (…/public/…) is what you hand out. Put it on your profile, your site, a business card. Anyone who has it can write to you, and nothing more — it cannot read your inbox or reveal a single message.

Your passphrase is a second lock

Reading a message needs both your console link (something you have) and your passphrase (something you know). If someone finds your console link, they still cannot read anything without the passphrase; if someone learns your passphrase, it is useless without the link. That is deliberate — it is what protects your inbox if one of the two ever leaks.

Because a leaked console link can be attacked offline — at whatever speed the attacker’s computer allows — your passphrase is only as safe as it is hard to guess. So we ask for a real one: four everyday words (like “amber tractor velvet moon”) is easy to remember and extremely hard to crack. And we deliberately do not let your browser remember it — it is the one key that is not already sitting on your device, so a borrowed or stolen device does not hand over your inbox along with everything else.

And if someone does sit at your console guessing passphrases: the next time you unlock we tell you how many failed attempts have been made since you last read — not counting your own. If that number is not you, it is a sign your console link has leaked, and a nudge to retire it (below). We count only the guesses made here, and we keep no record of who made them: no address, no identity, just a number that resets when you get in.

There is no recovery. Your passphrase never reaches us — not even as a hash — so if you forget it, nobody, including us, can ever read your messages again. You can change it from inside your inbox while you still know it, but it cannot be recovered once forgotten. Choose it carefully and store it safely.

The fingerprint lets senders check they reached you

Your drop page serves your public key, and a sender’s browser encrypts to it. The one thing a hostile or compelled server could tamper with is which key it serves. Your fingerprint is the defence: publish it somewhere people already trust to be you, and a careful sender can confirm the address served them the right key before they write.

What we can and cannot see

Every message is encrypted in the sender’s browser to your key. We store only ciphertext, your public key, and your private key encrypted under your passphrase — which we can never open. We do not know who you are, and we do not know who wrote to you. A sender is anonymous unless they sign the message themselves.

Files, as well as words

A message can carry files too — up to 10 files, 25 MB in total. Each is encrypted in the sender’s browser to your key, exactly like the message, and uploaded as opaque ciphertext. We never store a filename or a file type; only you, once you unlock, see what a file is called. And unlike a one-time secret — destroyed the instant it is read — a drop’s files stay: you can download them again, from any of your devices, until you delete the message or it reaches your retention limit. Deleting a message takes its files with it.

Messages don’t wait forever

When you create your address you choose how long each message is kept — 7, 14, or 30 days. After that a message is destroyed automatically, whether or not you have read it. You can also delete any message yourself the moment you have read it.

Is a drop address still watched?

A drop address has no account and no notifications — we hold no email, no phone number, nothing that could tell the owner a message arrived. So a sender cannot know for certain that anyone is still reading, and if you send something time-critical it is worth nudging the recipient another way if you safely can. Two owner-controlled settings help with this, and both are built to say as little as possible:

Last active (off by default). The owner can choose to show senders a rough, coarse hint — “within the last week”, “within the last 3 months” — of roughly when they last opened and read their inbox. Their own console reports it after they unlock and read, so an owner who has lost their passphrase and only loads the page to try guesses does not mark themselves active. It is a best-effort signal from the owner’s console, though — a “probably still watched”, not a cryptographic proof — so a careful sender should treat it as a hint, not a guarantee. It is kept only to weekly accuracy, only while the owner leaves it on, and it never reveals who they are or anything about the messages. If they never turn it on, senders simply see that it cannot be shown.

On hold. The owner can pause an address. A paused address stops accepting new messages and looks, to a sender, exactly like one that was never watched — it does not announce that the pause was deliberate. Everything already received stays safely in the owner’s inbox.

If a link is exposed. Hold pauses an address but can be switched back on by whoever holds the console link. If a SECRET link is ever compromised, the owner can instead delete the address permanently — it and every message in it are destroyed, the link stops working, and senders see the same “does not exist” as for an address that never existed. Delete needs only the console link, not the passphrase, so an owner who is locked out — a leaked link they can no longer read, or a passphrase they have lost — can still retire the address and start fresh.

Create a drop address →