# Secret sharing privacy ratings

Services for sending passwords and secrets that expire.

| Name | Grade | Jurisdiction | Description |
| --- | --- | --- | --- |
| [PrivateBin](https://privacyratings.com/secret-sharing/privatebin/) | A (90/100) | Unknown | Open source, self-hosted pastebin that encrypts text and files in the browser with AES-256-GCM, so the server never sees the content. Supports expiry, burn after reading, passwords and discussions. |
| [Onetime Secret](https://privacyratings.com/secret-sharing/onetime-secret/) | B (75/100) | Canada (Five Eyes) | Secret sharing service that stores a message behind a one-time link and deletes it after it is viewed or expires, with optional passphrases. Offers regional data centers, paid plans with custom domains, and can be self-hosted. |
| [crypt.fyi](https://privacyratings.com/secret-sharing/crypt-fyi/) | C (69/100) | Unknown | Ephemeral secret sharing service that encrypts text and files in the browser before upload, with burn-after-reading, expiry, password and IP restrictions. Offers web, CLI and browser extension clients and can be self-hosted. |
| [1time.io](https://privacyratings.com/secret-sharing/1time-io/) | D (59/100) | Unknown | One-time secret sharing service that encrypts text and files in the browser with AES-256-GCM before upload and deletes them after the first view or expiry. Also offers a CLI, a browser extension and self-hosting. |
| [Hemmelig.app](https://privacyratings.com/secret-sharing/hemmelig-app/) | D (59/100) | Unknown | Secret sharing service that encrypts text and files in the browser and deletes them after a set number of views or an expiry time. Supports passwords, IP restrictions, webhooks and self-hosting. |
| [Password Pusher](https://privacyratings.com/secret-sharing/password-pusher/) | D (59/100) | United States (Five Eyes) | Service for sharing passwords, text and files through links that expire after a set number of views or days, with audit logs. Hosted in EU and US regions with paid team plans, and the open source edition can be self-hosted. |
| [Yopass](https://privacyratings.com/secret-sharing/yopass/) | D (50/100) | Sweden (Fourteen Eyes) | Open source secret sharing tool that encrypts messages and files in the browser with OpenPGP and deletes them after one view or an expiry time. Can be self-hosted, and a public instance runs at share.yopass.se. |

## Criteria

- **Open source** (weight 3): Is all the source code needed to run the product public?
- **No trackers or telemetry** (weight 3): Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
- **No ads or data sales** (weight 2): Is the product funded without advertising, ad targeting or selling user data?
- **Independent audit** (weight 2): Has an independent security or privacy audit been published within the last three years?
- **Transparency report** (weight 2): Does the provider regularly publish how many government and legal requests it receives and how it responds?
- **Tells users about requests** (weight 1): Does the provider promise to tell users about requests for their data, unless a court forbids it?
- **TLS configuration** (weight 2, automated): Does the website pass the Qualys SSL Labs test with a grade of A or better?
- **Security headers** (weight 1, automated): Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?
- **Modern web standards** (weight 1, automated): Does the website score 90% or higher on the Internet.nl website test?

Source: https://privacyratings.com/secret-sharing/
