← All guides
Sharing links and passwords more safely
Most leaked secrets don't leak through clever attacks. They leak because they were pasted into a chat and left there. This guide is about the boring part — the channel you choose — and a routine that takes ten extra seconds.
Last updated: September 2026 · 5 min read
Chat is a permanent record you don't control
When you send a password to someone in a messenger or a work chat, at least three copies exist before they've even read it: your device, the service's servers, and their device. Then multiply by backups, exported histories, and device restores. Deleting the message later removes your copy — not the others.
Work chats add another wrinkle: company platforms are admins of their own space. Depending on the setup and jurisdiction, they may retain or review messages. A WiFi password in family chat is one thing; a production credential in a team channel is another.
Link previews: read before you paste
Most messengers and many mail services fetch every link you send to build a preview card — title, description, sometimes an image. That happens automatically, before the recipient decides anything, and the fetch often comes from a datacenter, not from their phone.
For public pages this is harmless. But it means:
- A secret-bearing link is opened by a robot seconds after you send it. One-time links, file downloads, and view-limited notes do not care who "reads" them — a preview bot can consume a one-time link before your recipient clicks. If a link must be consumed exactly once, don't paste it anywhere with previews. Send the link itself only after the recipient confirms they're ready for it, or use a password-protected note where the robot stops at the lock screen.
- Preview fetches show up as visits. Your click statistics will include the messenger's crawler alongside real people — one reason the numbers are a rough signal, not gospel.
The account-takeover scenario worth knowing: an attacker with access to someone's email or chat can request "password reset" on services and simply read the reset link as it arrives. Any secret that travels through a compromised channel is compromised, no matter how carefully it's phrased. For high-value accounts, split the delivery: even modest separation (code in one channel, password in another, or a time-limited note) beats a single message.
A routine that takes ten extra seconds
- Open a burn-after-reading note (we run one at priv.sh0rt.biz). Paste the password or text, pick 1 read for a single recipient, and add a password if the material is sensitive.
- Send the note link in the chat — that's fine. It's a link to a locked door, not the key.
- Send the note's password separately — a different channel, or at least a different message after the first one has been acknowledged. If either half leaks, it's useless alone.
- For files, prefer a note with an upload over a permanent cloud folder. Files in shared drives outlive their purpose, get synced everywhere, and sit in "Shared with me" forever.
The note burns once it's read (or once your read limit runs out). No copy sits in an inbox, and nothing depends on someone remembering to delete the message later.
Honest limits of the approach
None of this is magic, and overselling it would be worse than not writing this guide:
- A read limit isn't a leash. Your recipient can screenshot, photograph, or copy the content before it burns. Read limits reduce the window of exposure; they don't manage people. If you don't trust the recipient, no tool will fix that.
- The weakest channel sets the ceiling. If you send half the secret over the same compromised account you're worried about, you've achieved nothing. Separation only works when it's real separation.
- Passwords inside notes are still passwords. Prefer unique ones, and rotate anything that was ever shared in plain text before you started being careful. Old exposure doesn't vanish because new habits exist.
Used with those limits in mind, the routine handles the most common real-world case — the everyday secret sent to a colleague, friend, or family member — far better than a permanent chat message, at a cost of almost nothing.