Privacy Ratings

Open-source secret sharing

5 secret sharing whose code is public under an OSI-approved license, rated for privacy with evidence. Picks first, then by score.

  1. PrivateBin Grade A

    Open source, self-hosted pastebin that encrypts text and files in the browser with AES-256-GCM, so the server never sees the content. Supports expiry, burn after reading, passwords and discussions.

    Zlib license, with bundled libraries under other OSI licenses. Source code

  2. Onetime Secret Grade B

    Secret sharing service that stores a message behind a one-time link and deletes it after it is viewed or expires, with optional passphrases. Offers regional data centers, paid plans with custom domains, and can be self-hosted.

    MIT. Source code

  3. crypt.fyi Grade C

    Ephemeral secret sharing service that encrypts text and files in the browser before upload, with burn-after-reading, expiry, password and IP restrictions. Offers web, CLI and browser extension clients and can be self-hosted.

    Apache-2.0. Source code

  4. 1time.io Grade D

    One-time secret sharing service that encrypts text and files in the browser with AES-256-GCM before upload and deletes them after the first view or expiry. Also offers a CLI, a browser extension and self-hosting.

    MIT. Source code

  5. Yopass Grade D

    Open source secret sharing tool that encrypts messages and files in the browser with OpenPGP and deletes them after one view or an expiry time. Can be self-hosted, and a public instance runs at share.yopass.se.

    Apache-2.0. Some business features in the same code base require a paid license key. Source code

Compare all 7 secret sharing, open source or not.