Secret sharing privacy ratings
Services for sending passwords and secrets that expire.
7 secret sharing are rated against 9 public criteria, and 7 have enough evidence for a letter grade. Of the 3 with a known jurisdiction, 2 are based in a Five Eyes country, and 3 in the wider Fourteen Eyes.
Open-source secret sharing only · Criteria for this category · Suggest an addition · Markdown
| Name | Grade | Score | Data | Jurisdiction | Open source | No trackers or telemetry | No ads or data sales | Independent audit | Transparency report | Tells users about requests | TLS configuration | Security headers | Modern web standards |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Open source, self-hosted pastebin that encrypts text and files in the browser with AES-256-GCM, so the server never sees the content. Supports expiry, burn after reading, passwords and discussions. |
Grade A | 90 | 100% | – | Yes | Yes | Yes | Partial | Not applicable | Not applicable | Not applicable | Not applicable | Not applicable |
Secret sharing service that stores a message behind a one-time link and deletes it after it is viewed or expires, with optional passphrases. Offers regional data centers, paid plans with custom domains, and can be self-hosted. |
Grade B | 75 | 100% | Canada Five Eyes | Yes | Yes | Yes | No | Partial | Yes | Yes | No | Not tested yet |
Ephemeral secret sharing service that encrypts text and files in the browser before upload, with burn-after-reading, expiry, password and IP restrictions. Offers web, CLI and browser extension clients and can be self-hosted. |
Grade C | 69 | 100% | – | Yes | Yes | Yes | No | No | No | Yes | Yes | Not tested yet |
One-time secret sharing service that encrypts text and files in the browser with AES-256-GCM before upload and deletes them after the first view or expiry. Also offers a CLI, a browser extension and self-hosting. |
Grade D | 59 | 100% | – | Yes | Yes | Yes | No | No | No | Partial | Partial | Not tested yet |
Secret sharing service that encrypts text and files in the browser and deletes them after a set number of views or an expiry time. Supports passwords, IP restrictions, webhooks and self-hosting. |
Grade D | 59 | 100% | – | Yes | Partial | Yes | No | No | No | Yes | Yes | Not tested yet |
Service for sharing passwords, text and files through links that expire after a set number of views or days, with audit logs. Hosted in EU and US regions with paid team plans, and the open source edition can be self-hosted. |
Grade D | 59 | 100% | United States Five Eyes | Partial | Yes | Yes | No | No | No | Yes | Yes | Not tested yet |
Open source secret sharing tool that encrypts messages and files in the browser with OpenPGP and deletes them after one view or an expiry time. Can be self-hosted, and a public instance runs at share.yopass.se. |
Grade D | 50 | 100% | Sweden Fourteen Eyes | Yes | No | Yes | No | No | No | Yes | Yes | Not tested yet |
Questions
What is the most private option among secret sharing?
No pick has been made yet. The table above is sorted by score, based on public evidence.
How are secret sharing rated?
Each entry answers 9 questions: open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests, TLS configuration, security headers and modern web standards. Answers need links to evidence. See the full criteria.
Does jurisdiction matter?
Jurisdiction decides which laws can compel a provider to hand over data. Each entry shows its country and whether it is in the Five, Nine or Fourteen Eyes. The data a provider can hand over depends mostly on what it stores and who holds the keys. Read about jurisdictions and the CLOUD Act.