{
  "slug": "crypt-fyi",
  "category": "secret-sharing",
  "name": "crypt.fyi",
  "description": "Ephemeral secret sharing service that encrypts text and files in the browser before upload, with burn-after-reading, expiry, password and IP restrictions. Offers web, CLI and browser extension clients and can be self-hosted.",
  "website": "https://www.crypt.fyi",
  "source": "https://github.com/osbytes/crypt.fyi",
  "license": "Apache-2.0",
  "platforms": [],
  "jurisdiction": null,
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "C",
  "score": 69,
  "coverage": 100,
  "summary": "crypt.fyi scores 69 out of 100 (grade C) on the secret sharing criteria. It meets 5 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration and security headers. It does not meet independent audit, transparency report and tells users about requests. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade A+.",
  "url": "https://privacyratings.com/secret-sharing/crypt-fyi/",
  "markdown": "https://privacyratings.com/secret-sharing/crypt-fyi/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/osbytes/crypt.fyi/blob/main/LICENSE",
      "note": "Apache-2.0."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://www.crypt.fyi/privacy",
      "note": "The privacy policy shares data only with hosting providers and user-set webhooks, and the site's Content Security Policy allows no third-party scripts."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.crypt.fyi/privacy",
      "note": "Free open source service without ads. The privacy policy states data is not shared with third parties beyond hosting."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No transparency report or government request policy is published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=crypt.fyi&hideResults=on",
      "note": "Grade A"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=crypt.fyi",
      "note": "Grade A+ (110/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    }
  },
  "tests": {
    "ssllabs": "A",
    "observatory": "A+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:01:19.372Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}