Skip to main content
LeonAI
PRODUCT 05 · ONE-TIME

LeonAI Secrets

Secure one-time secret sharing

Encrypted in the browser with AES-256-GCM, burned before it is delivered — and gone forever.

AES-256-GCM encryption before data leaves your browserSecrets automatically delete after viewingSet expiration from 5 minutes to 30 daysFree for personal use
ISO/IEC 27001HOSTED ON CLOUDFLARE · GLOBAL EDGE
CAPABILITIES

Everything your business runs

01

End-to-End Encryption

AES-256-GCM encryption before data leaves your browser.

02

Burn After Reading

Secrets automatically delete after viewing.

03

Password Protection

Optional additional security layer.

04

Manual burn and notification

If something went wrong you can burn the secret before it is read, and get an email notification the moment it is opened.

05

Flexible TTL

Set expiration from 5 minutes to 30 days.

06

Limits

Up to 10KB of text, a file up to 10MB, and up to ten recipients per secret.

07

Passwordless sign-in

You sign in with a one-time link sent to your email address.

HOW IT CONNECTS

What passes between the sender and the recipient

The sender encrypts the secret in the browser before it reaches Secrets; the recipient opens a one-time link, and then the secret is deleted.

Sender
Encrypts in the browser
LEONAI SECRETS
Recipient
Opens a one-time link
PRICING

Pricing that is simple and clear

Free for personal use
/month · ex-VAT
SECURITY & HOSTING · VERIFIABLE

Built to pass security reviews

The questions your IT and compliance teams will ask — answered up front.

  • The server never stores the encryption key.
  • Encryption happens in the browser with AES-256-GCM via Web Crypto.
  • The secret is deleted from storage before the response is sent to the recipient.
  • Three wrong password attempts destroy the secret.
  • Expiration — between five minutes and thirty days — is enforced at the storage layer.
  • IP addresses are anonymized after 30 days, and audit logs are deleted after 90 days.
  • A CSP policy with a nonce regenerated for every request.

ISO/IEC 27001

ISO 27001 certified.

HOSTED ON CLOUDFLARE · GLOBAL EDGE

Data is stored on Cloudflare's global edge network using D1 (SQLite), R2 (object storage), and KV (key-value storage). All data is encrypted at rest.

Full security page
FAQ

Questions that keep coming up

What happens after the secret is read?

It is deleted from storage before the response even reaches the recipient. A link opened once will not open again, and we cannot recover it either.

I sent it to the wrong address — what now?

As long as the secret has not been read you can burn it manually, and it is gone. If you enabled the email notification, you will know immediately whether someone already opened it.

How long is the secret kept?

As long as you choose — from five minutes to thirty days. Expiration is enforced at the storage layer, and once it passes the secret is no longer available even if nobody opened it.

Smart moves — it’s in our nature

Want to see Secrets at your company?