

Encrypted in your browser with AES-256-GCM before anything is sent. The server only ever stores ciphertext it can't read
Zero-knowledge server
Decryption keys live in the URL fragment, they're never sent to any server
Burns after reading
Destroyed atomically after the last view, race-safe and no leftovers
Expires automatically
Native TTL removes it even if the link is never opened