Privacy Notice

Effective October 3, 2026

SendThePass.com is a free project sponsored by HUFF DATA SYSTEMS, developed by contributors including HUFF DATA SYSTEMS team members, and built with open-source software. It is designed so that the information you share cannot be read by anyone running the Service. This notice explains what we collect, how it is protected, how long it is kept and when it is deleted.

1. How your information is protected

Encryption happens on your device. Passwords, messages, Wi-Fi details and QR codes are encrypted in your web browser before anything is sent to us, using AES-256-GCM, an industry-standard authenticated encryption algorithm. Each link uses its own randomly generated 256-bit key. Content is padded to a fixed block size before encryption, so the stored data does not reveal how long a password is.

The key is in the link, never on our servers. The key is contained in the part of the link after the “#” symbol. Web browsers never send that part to a website, so the key never reaches us. Without it, the stored data cannot be read, including by us.

Optional passphrase. If you add a passphrase, it is strengthened in your browser with PBKDF2-SHA256 (600,000 iterations) and combined with the link key using HKDF-SHA256. The passphrase is never sent to us or stored.

What we never receive or store: your passwords or messages in readable form, encryption keys or passphrases. Our servers hold only encrypted data and one-way SHA-256 hashes of the security tokens used to manage each link, which cannot be reversed.

2. Information we store

3. IP addresses

What we record. Each link has an activity log, visible only to the person who created it through the link’s private status page. The visitor’s IP address, approximate country and browser type are recorded when:

How long we keep it. Activity logs, including IP addresses, are kept for 30 days after the link expires so that you can review access afterwards, and are then permanently deleted by our automated hourly clean-up. To prevent abuse, repeated failed or blocked attempts are limited to 100 log entries per link; creation, views and deletions are always recorded.

Abuse prevention. To protect the Service from automated abuse, our hosting provider counts requests from each network over a 60-second window. These counts are not stored by us.

4. Automatic deletion

An automated clean-up runs every hour and:

Content is also deleted immediately, without waiting for the hourly clean-up, when a link reaches its last view, when the sender or recipient deletes it, or after too many incorrect passphrase attempts. Expired links stop working the moment their time limit is reached, even before the clean-up runs.

5. Limiting a link to a single network

By default, each link is locked to the first viewer’s IP address (you can turn this off when creating a link):

Please note that a recipient who changes networks (for example, from office Wi-Fi to mobile data) will also be blocked.

6. Information stored in your browser

My pushes. To let you check on links you have created, your browser keeps a list of them in its local storage, including each link, its private status token and any reference note you add. This list is never sent to us. A link’s full address, which contains its key, is removed from the list the next time you open My pushes after the link has expired. You can remove entries at any time, or clear this site’s data in your browser settings.

When a link is opened. The recipient page removes the key from the browser’s address bar as soon as it loads, and a revealed secret is hidden again when the recipient leaves the page, so it does not reappear with the Back button. Please note that your browser may still record the link in its history when it is opened.

7. Clipboard and copied passwords

When you choose Copy, the password or link is placed on your device’s clipboard. Many devices keep a clipboard history or synchronise it between devices (for example, Windows Clipboard History and cloud clipboard, Apple Universal Clipboard, and keyboard apps on Android), so copied passwords may remain there after the link has expired. This is controlled by your device, not by SendThePass.com. We only write to your clipboard when you click Copy, and we never read from it. For sensitive information, we recommend clearing your clipboard history after use.

8. What we do not do

9. Hosting

SendThePass.com is hosted on Cloudflare, which processes requests on our behalf and may retain standard request logs under the Cloudflare Privacy Policy. All connections use HTTPS, and browsers are instructed to always use a secure connection.

10. Contact

For questions about this notice, or about data relating to a link you created, contact the SendThePass.com team through our sponsor’s website, www.huffdata.com. See also our Terms of Service.