t. tempmsg

A private message. A passing moment.

Encrypted on your device. Retrieved once. Automatically expires.

01 / SHARE PRIVATELYNo account needed
Text, or one encrypted attachment.0 / 65,536 bytes
Add a file PNG, JPG or PDF · up to 10 MiB
PNG, JPG or PDF · up to 10 MiB

Cleaned images become PNGs, with no additional JPEG compression. Colors or file size may change. Up to 16 megapixels; animations are not supported. Visible names, faces and watermarks remain. PDFs are not cleaned.

A passphrase adds protection. Share it through a separate secure channel.

The key stays in your browser. Only encrypted content reaches our server.

01

On your device

Encrypted before the message leaves your browser.

02

One retrieval

No message history. No second retrieval from the server.

03

No permanent storage

Encrypted data stays in memory until retrieval or expiry.

02 / KEEP IT GOING

Support a little more privacy.

If tempmsg is useful to you, consider a small donation. Your support helps cover hosting, maintenance and continued development.

Bitcoin BTC

Bitcoin donation address

bc1qan4tete88nkzwujm72a3e9mq6gmj69p7m362hg

Monero XMR

Monero donation address

434zmubZYhLF66Ho3kRaiuQy1BkezktYRTBc4D9V9BNqZgqcN9SaknWHXkNqLuMTzS3jggXCRk5az6s1H5w8XY3PL3KH3zM

Support is entirely optional. Thank you for helping keep tempmsg going.

What is protected. And where the limits are.

This first version uses AES-256-GCM in your browser. Plaintext and encryption keys are never sent to the server. The full share link is a secret: your clipboard, browser extensions and messenger may access it.

Our application uses no cookies, trackers, external resources or persistent browser storage. The server processes connection data; short-lived IP counters hashed with a rotating key limit abuse. Hosting and network providers may process additional metadata.

We keep daily totals of created, retrieved and expired messages for 90 UTC days, plus a current storage-usage snapshot. These statistics contain no message IDs, content, keys, IP addresses or visitor identifiers. They are accessible only locally to the operator; there is no public statistics endpoint.

A server restart removes unread messages. Recipient screenshots and copies cannot be prevented. Modified web code or a compromised device can read content. Clearing a session does not guarantee forensic erasure from device memory.

Version 1.0. Not independently audited. Operator and hosting disclosures must be completed before public operation.

03 / UNDER THE SURFACE

A secret from browser to browser.

Follow your message from local image cleaning to encryption and one-time retrieval.

  1. 01YOUR DEVICE

    Clean, then lock.

    By default, JPG/PNG metadata is removed locally. Your browser then encrypts the message and attachment before upload.

    Local image cleaning · AES-256-GCM
  2. 02TEMPMSG SERVER

    Keep only the sealed copy.

    Encrypted content waits in temporary memory. The secret stays in the share link.

    No plaintext or key
  3. 03RECIPIENT’S DEVICE

    Unlock it there.

    Retrieval removes the server copy. The recipient’s browser then decrypts the message.

    One retrieval

The secret is after the #. Your browser does not send that part of the link when loading the page. Keep the full link private: your messenger, clipboard or browser extensions may still see it.

Explore the encryption flow Step by step
Show full sequence diagram
How your message stays private Sequence of optional local JPG/PNG metadata removal before encryption, temporary encrypted storage, one-time retrieval and local decryption. The numbered explanations below describe the same flow. Clean JPG/PNG locally (default) Prepared content + passphrase AES-GCM ciphertext + secret Encrypted payload + expiry Message ID + access tokens Share the secret link through your chosen channel Click Retrieve: ID + read token Consume valid message once Ciphertext + secret (+ passphrase) Authenticated plaintext Clean, encrypt & store Share privately Retrieve & decrypt Web Crypto · Inside your browser · Sequence participant Web Crypto Inside your browser Your browser · Encrypt locally · Sequence participant Your browser Encrypt locally tempmsg server · Temporary memory · Sequence participant tempmsg server Temporary memory Recipient browser · Decrypt locally · Sequence participant Recipient browser Decrypt locally Web Crypto · Inside recipient browser · Sequence participant Web Crypto Inside recipient browser Legend main request return security message
The first loop stays inside your browser: JPG/PNG cleaning is enabled by default; PDFs are not cleaned. Web Crypto also runs locally. Arrows show the order of operations; they do not represent a separate encryption service.
  1. Clean images before encryption

    With image cleaning enabled (the default), your browser rebuilds JPG and PNG attachments from their pixels as a still PNG, respecting image orientation. Original EXIF, GPS, comments and embedded thumbnails are not copied; extra PNG metadata is removed. A neutral filename is enabled by default and can be switched off independently. The original file stays unchanged. Cleaning errors stop the upload.

    PDFs are not cleaned. Turning image cleaning off preserves the original image metadata. Visible names, faces and watermarks remain; colors and file size may change.

  2. Create the secret and encrypt

    The browser generates a random 256-bit link secret. Without a passphrase, this is the AES key. Text and any prepared attachment, including its filename and type, are packed locally, padded to 1 KiB blocks and encrypted with AES-256-GCM, a fresh 96-bit nonce and a 128-bit authentication tag.

  3. Add a passphrase, if you choose

    PBKDF2-SHA-256 uses 600,000 iterations, the passphrase, a random salt and the link secret to derive the AES key. Both the link and the passphrase are then needed. Share the passphrase through a separate secure channel.

  4. Store the encrypted envelope

    Only ciphertext, encryption parameters and the chosen lifetime are uploaded. The server keeps them in process memory alongside the expiry and hashes of separate read and deletion tokens.

  5. Share the link, then retrieve once

    The browser builds the link with the message ID, secret and read token after the #. Opening it does not retrieve the message. Clicking “Retrieve message once” sends only the ID and read token to the server, which checks access and expiry, removes the record, and returns the encrypted envelope.

  6. Verify and decrypt locally

    The recipient’s browser uses the link secret and any required passphrase to verify and decrypt the content. A wrong passphrase can be retried in the same tab using the retrieved ciphertext. Reloading or losing the response may make the message unrecoverable.

Encryption protects content, not every trace. HTTPS protects transport in production; hosting providers still process connection metadata. Compromised devices or modified web code can expose secrets, and recipients can keep copies.