Skip to main content
Use Wipe.me when another person needs a password, recovery code, private note, card detail, photograph, or file—but the chat, email, ticket, or shared workspace carrying the handoff should not retain the plaintext.
  1. Create the message at wipe.me.
  2. Choose an expiration appropriate to the task.
  3. Send the private link through the intended conversation. If you selected a custom passphrase, share it through a separate trusted channel.
  4. Ask the recipient to open it only when ready; retrieval is one-time.
  5. Delete an unopened message if the handoff is canceled or sent incorrectly.
The conversation may retain the link, but the original content remains locally encrypted and is claimed on first successful retrieval.

Keep an ongoing conversation private

Wipe.me can also protect a continuing conversation, not just an occasional password or file. You and the other person agree on a shared passphrase once. After that, each of you can use it to create new one-time messages and send only the resulting Wipe.me links through your usual messenger. The messenger history contains generic private-message links rather than the subject and contents of the conversation. The same is true for notification previews, exports, backups, moderation tools, and other systems that process the messenger history: they receive the link, not the protected text or attachments.
A messenger showing generic Wipe.me links instead of the protected conversation
The private conversation opened locally through Wipe.me
Each message is still retrieved only once. The shared passphrase makes repeated exchanges convenient because it can be remembered or stored separately instead of being included in every link.
The messenger can still retain ordinary conversation metadata, such as the participants, timestamps, and the fact that Wipe.me links were exchanged. If the shared passphrase may have been exposed, agree on a new one before continuing.
Confirm the recipient through a separate trusted signal when impersonation is a concern. Wipe.me protects the content in transit and at rest; it does not verify the identity of the person opening a bearer link.