snippetsafe← Back

How snippetsafe Works

snippetsafe inverts traditional “paste a secret, get a link” workflows. Instead of trusting a sender to handle your sensitive data correctly, you (the recipient) create a cryptographic inbox and invite others to push encrypted messages into it. Only your browser can decrypt them.

High-Level Flow

  1. You generate a keypair locally. Private key stays in browser storage; it never leaves your device.
  2. You share a public link (contains an identifier + your public key or a reference).
  3. Sender loads a minimal page that uses your public key to encrypt their message entirely client-side.
  4. Encrypted payload (ciphertext) is sent to the server; no plaintext ever touches our infrastructure.
  5. Your inbox fetches ciphertext and decrypts locally with your private key when you view messages.

Why This Is Different

  • Recipient-first trust model: You originate the secure channel.
  • No secret-bearing reveal link: There is never a decryption token traveling through email or chat.
  • Fewer exposure points: Plaintext is never staged server-side.
  • Reusable inbound link: Collect multiple secrets securely without creating dozens of expiring URLs.
  • Local key custody: Clearing browser storage automatically renders stored ciphertext undecryptable (privacy by design).

Threat Model Snapshot

VectorImpactMitigation
Server compromiseAccess to ciphertext onlyKeys never stored server-side
Intercepted share linkPublic key + ID onlyNo decryption possible
Lost local storageLose ability to decryptBy design (no escrow)
Malicious senderCan send spam ciphertextFuture: rate limiting / blocklist

FAQ

Do you ever see my messages?

No. We only store opaque ciphertext plus minimal routing metadata.

Can I recover messages if I clear my browser?

No—your private key is gone, and we cannot help decrypt. Consider exporting keys (future feature) if long-term retention matters.

Why not just use a one-time secret service?

Those rely on the sender to correctly handle and destroy a reveal link. snippetsafe removes that responsibility—senders just type and submit.

Next Steps

  • Generate your secure inbox on the homepage.
  • Share the link with someone who needs to send credentials or private notes.
  • Open your inbox to decrypt messages locally.

Future Enhancements

  • Key export / rotation
  • Sender authenticity indicators
  • Optional passphrase layer
  • Message shredding confirmations