LAST UPDATED // AUGUST 23, 2026
Privacy
Burn After Link is a Magill Digital, LLC utility for passing short pieces of sensitive text. This page explains what the application can and cannot see.
What happens to a secret
Your browser creates a random 256-bit key and encrypts the text with AES-GCM before sending anything to the application server. The server receives and temporarily stores the ciphertext, its initialization vector, the chosen burn mode, and timestamps. It does not receive the decryption key.
Where the key goes
The key is included after the # in the generated URL. That URL fragment is available to the recipient’s browser but is not included in the HTTP request to this server. The recipient’s browser uses it to decrypt the ciphertext locally.
Expiration and deletion
A first-read secret is deleted from the application database when it is successfully retrieved and becomes unavailable after seven days if unread. Timed secrets become unavailable after one hour or 24 hours. Expired database rows are removed during subsequent application cleanup. The product has no account, archive, or recovery feature.
Infrastructure and advertising
The site runs on Cloudflare infrastructure, which necessarily processes network requests and may retain operational or security logs under its own policies. Google AdSense is configured to support the free service and may process device, cookie, or advertising data. The plaintext of your secret is not supplied to either provider by this application.
Important limits
- Anyone who obtains the complete link, including its fragment, can attempt to reveal the secret.
- The recipient can copy, photograph, or screenshot plaintext after decryption.
- Some security scanners or automated browsers may activate a first-read link.
- This tool does not replace a password manager, credential rotation, or a trusted delivery channel.
Publisher
Burn After Link is published by Magill Digital, LLC. No registration or email address is requested to create or open a secret.