Private by design.
Transparent by choice.
Your secret should only be read by the person you share it with. Here’s how GhostKey makes that happen—and where its protection ends.
The key stays in your hands.
Your browser generates a random 256-bit key and encrypts your secret using AES-256-GCM through the Web Crypto API. Each secret gets a fresh key and a random initialization vector. GhostKey sends only the encrypted payload, its initialization vector, and your access settings to the server.
The key is placed after the # in the link. Browsers don’t include this URL fragment in HTTP requests. Decryption happens on the recipient’s device. Share the complete link only with someone you trust: anyone who has it has the key.
Temporary means temporary.
A secret expires after your chosen duration, from 1 minute to 30 days. Choose one view, multiple views, or unlimited views until expiration. The server enforces these rules atomically, so simultaneous requests cannot both take the final view.
Opening a link checks its availability without consuming it. Only confirming “Reveal secret” requests the encrypted payload and spends a view. The final retrieval deletes it from the active database. Expired secrets are inaccessible immediately and are removed by scheduled cleanup within five minutes.
A view is counted when the server releases the encrypted payload. A lost connection or an incorrect key can still spend that view. The server cannot verify local decryption without receiving information it intentionally doesn’t have.
Less to keep. Less to expose.
The active database stores ciphertext, an initialization vector, hashed link and deletion tokens, expiration, view counts, and creation time. It never stores your plaintext or encryption key. Short-lived hash-only records retain “expired” or “consumed” status for up to 24 hours after deletion.
No account, analytics, third-party scripts, or browser storage is used. Abuse protection uses short-lived, one-way identifiers derived from trusted network information; raw IP addresses are not stored by this application. Hosting providers can process standard connection metadata under their own retention policies.
Deletion removes the active encrypted record. Infrastructure backups may retain earlier ciphertext until the provider’s backup retention period ends. The encryption key is never included in those backups by GhostKey.
Private isn’t copy-proof.
Revealed text lives only in this page’s memory. It clears when you leave, when the secret expires, or after five minutes—whichever comes first. You can clear it sooner. Copying a secret puts it in your system clipboard, which GhostKey cannot automatically erase.
Recipients can save, copy, or screenshot what they see. Browser extensions, compromised devices, browser history synchronization, and software with screen access are outside GhostKey’s control. The shared link itself is sensitive, so use a trusted channel to send it.
A clear promise, with clear limits.
Client-side encryption protects stored secrets from being read by the database. You still trust the site to deliver honest JavaScript and your browser to execute it safely. A compromised application host could change that code. This is not a claim of anonymity or a substitute for a dedicated password manager.
HTTPS, a restrictive Content Security Policy, isolated server credentials, and database access controls protect the intended flow. Use GhostKey for temporary sharing, and keep long-term credentials in a system designed for it.