Skip to content
Alexandru JungeanOne Time SecretOther tools

One Time Secret - Tool - by Alexandru Jungean

Terms of Use

Română

The contract for using this free, browser-encrypted, at-most-once secret-link service.

Version 1.1.0 · Effective 22 August 2026

These Terms of Use (“Terms”) are a legally binding agreement between you and Alexandru Jungean, a natural person established in Romania, European Union (the “Operator”, “we”, “us”). They govern access to and use of One Time Secret - Tool - by Alexandru Jungean at https://secret.alexjungean.com (the “Service”).

By accessing the Service, creating a secret link, opening a reveal page, or sending a create or reveal request, you accept these Terms and the documents they incorporate: the Privacy Policy, Cookies and Local Storage, Acceptable Use Policy, Legal Notice, and Illegal Content Notices. If you do not agree, do not use the Service.

The Romanian text at Termeni de utilizare has the same date and version. For a consumer habitually resident in Romania, the Romanian text prevails if the two texts conflict on a mandatory consumer-information point. Otherwise the English text prevails.

1. Definitions

Plaintext
The secret text you type or paste. It is generated and, after a successful create, cleared in the browser. It is never sent to the Operator’s application server.
AES key
A 256-bit AES-GCM key created in your browser. It exists only in the URL fragment of a capability link and is never sent to the server.
Public identifier
A non-secret 16-byte identifier that may appear in the path of a reveal page. It does not, by itself, authorize disclosure.
Lookup proof
A 32-byte capability value that stays in the URL fragment. After you choose Reveal, the browser sends the public identifier and the proof in a same-origin JSON body. The server never stores the raw proof.
Ciphertext envelope
The versioned AES-256-GCM blob (nonce, ciphertext, authenticated associated data) stored by the server. The Operator cannot decrypt it.
Capability link
The shareable URL that combines the reveal path with fragment values for the lookup proof and the AES key. Anyone who has the complete link can attempt a single Reveal.
At-most-once release
A successful Reveal performs one atomic delete-and-return of the stored envelope. A later request receives the same generic unavailable outcome as expiry, a wrong proof, or a replay. If the HTTP response is lost after the delete commits, the envelope is gone and cannot be recovered. This is not exactly-once delivery to the recipient.

2. The Service

The Service is a free, anonymous, text-only tool. Encryption and decryption run in your browser with AES-256-GCM. The server stores only the documented allowlist fields (public identifier, HMAC verifier and key version, envelope version, ciphertext, nonce, authenticated associated data, created time, expiry time) and, separately, hashed rate-limit counters. It releases a stored envelope at most once.

The Service is not a backup, archive, messaging product, identity service, compliance certification, or guaranteed delivery network. It does not create accounts, take payments, send email, attach files, identify recipients, or protect a compromised device or a leaked capability link.

Default expiry is 24 hours or when revealed, whichever happens first. The other options are 1 hour, 3 days, and 7 days. Maximum plaintext size is 8192 UTF-8 bytes. Empty, whitespace-only, and invisible-only input cannot be created. Expired rows lose authorization immediately and are physically purged within 6 hours.

3. Eligibility and capacity

You must be at least 16 years old. If you are 16 or 17, you may use the Service only if you have the legal capacity to accept these Terms under the law of your habitual residence. You must not use the Service if applicable law forbids you from doing so.

If you use the Service for an organization, you represent that you have authority to bind that organization. Professional customers who submit ciphertext that contains personal data of others also accept the Data Processing Addendum.

The Service is not directed at children. We do not knowingly store an account or a profile for anyone under 16 because the Service has no accounts.

4. No account, no fee, no withdrawal of a paid contract

The Service does not offer registration, login, passwords, or customer dashboards. There is no fee and no in-Service payment. Because you pay nothing, there is no distance-selling refund to administer. Create and Reveal are performed immediately at your request.

EU consumer information required of an information-society service is in the Legal Notice. Mandatory consumer rights that cannot be waived remain available to the extent they apply to a free digital service.

5. Your responsibilities

  • You decide what plaintext to encrypt. You must have the right to submit it and to share the capability link.
  • You are responsible for who receives the capability link. The complete link is a bearer credential. Anyone who has it can attempt Reveal.
  • You must not put the lookup proof or AES key in a query string, a referrer, a ticket, a chat preview, or any channel that logs full URLs. The Service redirects query-string capability values off the reveal path and treats that page as unavailable.
  • You must not rely on the Service as the only copy of important material. A lost create or reveal response, a consumed link, expiry, or a second Reveal can destroy the only server copy.
  • You must comply with the Acceptable Use Policy and with criminal, privacy, export, and sanctions law that applies to you.
  • You must keep your device, browser, clipboard, and screenshots under your control. The Operator cannot protect a compromised endpoint.

6. What the Operator can and cannot do

The Operator cannot read plaintext, cannot reconstruct the AES key, and cannot reconstruct a raw lookup proof from the stored HMAC verifier. The Operator cannot identify you from the secret row. The Operator cannot restore a consumed or expired envelope.

The Operator can refuse or rate-limit requests, delete a row when a valid notice or lawful order identifies it, rotate HMAC keys under the documented retention window, and discontinue the Service. Application logs may contain only a request identifier, a route template, a status, a duration, and a generic error class. They must not contain plaintext, proofs, keys, public identifiers, fragments, full capability links, or ciphertext payloads.

7. Acceptable use

You must not use the Service to store or share illegal content, to attack the Service, or to circumvent rate limits or technical controls. The full rules are in the Acceptable Use Policy. A breach of that policy is a breach of these Terms.

Because the Operator cannot decrypt envelopes, the Operator does not generally monitor content and is not required to. Notices of alleged illegal content follow the Illegal Content Notices process.

8. Availability, rate limits, and changes

The Service is provided as available. There is no uptime commitment. Create is limited to 5 requests per hour per network identity and Reveal to 20 requests per hour per network identity. Identities are hashed; raw addresses are not stored on the secret table. When the hashed-bucket table is full, new identities fail closed.

We may change limits, expiry options, size caps, or features, or we may suspend or shut down the Service, including for security, abuse, legal, or operational reasons. Material changes to these Terms will carry a new version and effective date on this page. Continued use after the new date is acceptance. If you do not agree, stop using the Service.

9. Intellectual property

The Service’s software, design, marks, and documentation are owned by Alexandru Jungean or licensors. These Terms give you a limited, revocable, non-exclusive, non-transferable right to use the Service for its intended purpose. They do not sell the software.

You retain whatever rights you have in plaintext you submit. You grant the Operator a limited authorization to host the ciphertext envelope and to disclose it at most once to a caller who presents a valid proof, solely to operate the Service.

The repository name and category description do not copy another product’s brand, user interface, copy, or code. “One Time Secret” is used as a descriptive product mark for this Operator’s tool.

10. Infrastructure and third parties

The application is hosted on Netlify. Durable rows are stored in PostgreSQL in the EEA (Ireland) via Supabase. Search Console verification is DNS-only and does not load Google scripts on the Service. Details are in Infrastructure and Subprocessors and the Privacy Policy.

Create and reveal routes load no analytics, tag manager, captcha widget, font CDN, or other third-party script. Self-hosted fonts are first-party. Links to alexjungean.com and to public authorities open those sites under their own terms.

11. Disclaimers

To the maximum extent permitted by mandatory law, the Service is provided “as is” and “as available”, without warranties of merchantability, fitness for a particular purpose, uninterrupted availability, or error-free operation.

  • We do not warrant that a capability link will be delivered to an intended recipient, that a recipient’s browser will decrypt, or that a lost HTTP response can be retried.
  • We do not warrant that ciphertext is unreadable by a future attacker who obtains the envelope and the AES key, or that a leaked fragment cannot be used.
  • We do not warrant anonymity against your network operator, a compromised device, or a person who sees your screen or clipboard.
  • We do not warrant that the Service meets a particular regulatory standard, certification, or sectoral duty that applies to you.
  • Public statements are limited to browser-encrypted operation and at-most-once server release, as implemented and tested. They are not a promise of perfect secrecy.

Nothing in these Terms excludes a warranty or liability that applicable law does not allow to be excluded, including liability for fraud or for death or personal injury caused by negligence where that prohibition applies.

12. Limitation of liability

You understand and accept the at-most-once design: a consumed, expired, or response-lost secret cannot be restored by the Operator. You accept that the Operator cannot inspect or recover plaintext.

To the maximum extent permitted by mandatory law, the Operator is not liable for indirect, incidental, special, consequential, or punitive damages; for lost profits, data, or goodwill; for unauthorized Reveal by a person who obtained the capability link; or for unlawful content submitted by a user.

If, despite the Service being free, a court finds the Operator liable to you, the Operator’s aggregate liability for all claims arising out of the Service is limited to EUR 0 (the amount you paid to the Operator for the Service) except where mandatory law requires a higher floor or forbids a limitation.

If you are a consumer in the European Union, nothing in this section reduces rights that cannot be waived, including rights under product-safety or unfair-contract-terms rules that a court finds applicable to a free digital service.

13. Indemnity

To the extent permitted by law, you will indemnify the Operator against claims, losses, and reasonable legal fees arising from your plaintext, your capability links, your breach of these Terms or of the Acceptable Use Policy, or your violation of law. This does not require a consumer to indemnify the Operator where such a clause is unenforceable.

14. Refusal, deletion, and termination

We may refuse a request, apply a rate limit, or delete a stored row when we have a valid notice that identifies it, a lawful order, a security need, or a reasonable belief that these Terms or the Acceptable Use Policy have been breached. Because rows are anonymous, we usually cannot notify an author. Your right to stop using the Service is immediate: close the site and do not create or reveal further secrets.

On discontinuation, remaining envelopes expire under their existing timestamps and the purge job. We do not offer export of ciphertext to you.

15. Governing law and disputes

These Terms are governed by Romanian law, without prejudice to mandatory provisions of the law of your habitual residence if you are an EU consumer.

Courts of Romania have jurisdiction, except that an EU consumer may also bring proceedings in the courts of that consumer’s habitual residence, and proceedings against that consumer may be brought only in those courts, as required by the Brussels I bis Regulation. You may also use the EU Online Dispute Resolution information at https://ec.europa.eu/consumers/odr. The Operator is not obliged to use a specific ADR entity unless required by law. Digital Services Act supervision for hosting is described in the Legal Notice; the Romanian Digital Services Coordinator is Autoritatea Națională pentru Administrare și Reglementare în Comunicații (ANCOM).

16. General

  • These Terms, with the documents they incorporate, are the entire agreement for use of the Service.
  • If a court strikes a clause, the remainder stays in force.
  • A failure to enforce a right is not a waiver.
  • You may not assign these Terms. The Operator may assign them to a successor that continues the Service.
  • Headings are for reading convenience only.
  • Version 1.1.0, effective 22 August 2026.

17. Contact

All legal documents