Help & FAQ

Frequently Asked Questions

Everything you need to know about BurnLink — secure encrypted messages, how self-destructing links work, and how to send passwords and sensitive data safely.

Security & Encryption

What encryption does BurnLink use?

BurnLink uses AES-256-GCM — the same encryption standard used by NATO, the NSA for Top Secret classification, and the world's leading banks. It is the highest commercially available encryption standard. All data in transit is additionally protected by TLS 1.3 with forward secrecy.

Is BurnLink end-to-end encrypted?

Yes. BurnLink encrypts your message before it is stored. The plaintext content is never written to disk or logs at any point. Only the encrypted payload is stored, and it is deleted immediately after being accessed.

Can BurnLink read my secrets?

No. BurnLink operates a zero-knowledge architecture. We store only the encrypted payload and are structurally incapable of reading your secrets. Even our own staff cannot read your message.

Can law enforcement access my BurnLink messages?

No. Because BurnLink stores only encrypted payloads and deletes all data upon access, there is nothing to produce in response to a subpoena or court order. Burned messages are irrecoverably gone from all infrastructure, including backups.

Is it safe to send bank details or passwords through BurnLink?

Yes. BurnLink is specifically designed for this use case. The AES-256-GCM encryption and one-time link model mean your credentials are protected in transit and self-destruct after delivery. It is significantly safer than sending passwords via email, SMS, or chat.

Privacy & Data

Does BurnLink keep logs?

BurnLink keeps no logs of secret content. Operational metadata (IP address, user-agent, timestamp) is stored temporarily for abuse prevention and is purged when the secret is deleted. We do not log what you type or who receives your message.

Does BurnLink use cookies or track me?

BurnLink does not use advertising cookies or cross-site tracking. Basic session functionality may use a cookie for UI preferences (e.g., dark mode), but no third-party advertising or analytics trackers are embedded.

Can someone intercept my secret link?

The link itself is useless without the key embedded in the URL fragment. The content is encrypted with AES-256-GCM. Even if someone intercepts the link before you share it, they cannot read the message without both the link and the decryption key. Adding a passphrase gives a further layer of protection.

What data does BurnLink store?

BurnLink stores: (1) the encrypted secret payload, (2) the view limit setting, (3) the expiry timestamp, (4) whether a passphrase is set (not the passphrase itself), (5) the creator's IP address for abuse prevention. All of this is deleted when the secret is burned.

Password & Credential Sharing

What is the safest way to send a password to someone?

The safest way is to use BurnLink. Paste the password, get an encrypted one-time link, send it via any channel. Even if the link is later discovered in an email thread or chat log, it will be expired and contain nothing. Far safer than sending passwords in plain text.

Can I share API keys securely with BurnLink?

Yes. BurnLink is widely used by developers to share API keys, private keys, access tokens, and SSH passwords. The one-time link ensures credentials cannot be re-accessed after delivery.

Can teams use BurnLink for employee onboarding?

Yes. HR and IT teams use BurnLink to deliver initial credentials to new employees. The one-time link model ensures credentials are not left floating in email inboxes permanently.

Can I add a passphrase to my link?

Yes. In Advanced Options, you can add a passphrase. The recipient must enter the correct passphrase before the message is revealed. This is useful if you are sending the link over an insecure channel and want a second authentication factor.

Alternatives & Comparisons

Is BurnLink better than Privnote?

BurnLink offers the same burn-after-reading concept as Privnote but with explicitly documented AES-256-GCM encryption, modern mobile-friendly design, optional passphrase protection, configurable view limits, and a strict zero-logs policy. BurnLink also works with no account or sign-up.

How is BurnLink different from Signal or WhatsApp?

Signal and WhatsApp require both parties to have the app installed and an account. BurnLink works with nothing — no app, no account. You create a link and send it via any channel. The message exists only until it is read, then it is gone entirely. BurnLink is purpose-built for one-time sensitive disclosures, not ongoing conversations.

Is BurnLink a Privnote alternative?

Yes. BurnLink is a strong Privnote alternative. It offers self-destructing encrypted links with stronger explicitly-stated encryption (AES-256-GCM), optional passphrase, configurable view limits, and a modern interface.

Is BurnLink a OneTimeSecret alternative?

Yes. Like OneTimeSecret, BurnLink creates one-time encrypted links for sensitive data. BurnLink offers a more modern interface, passphrase protection, configurable view limits, and is completely free with no account required.

Can I send disappearing messages without an app?

Yes. BurnLink works entirely in the browser — no app, no install, no account. Just open the website, write your message, and get a self-destructing link.

Ready to send a secure message?

Free, no account required. Your secret self-destructs after being read.

Create a secure link