Browsers do not let websites add bookmarks, for good reason – otherwise every site would do it uninvited. This shortcut takes a second:
D
Tap your browser’s share icon and choose “Add to Home Screen” or “Add bookmark”.
Last updated: August 31, 2026
This service is built so that we learn as little about you as possible. Messages are encrypted in your browser; the key never reaches our servers. What we do process is listed here in full.
The controller responsible for data processing on this website is:
Maskow Softwares UG (haftungsbeschränkt)
Hans-Sachs-Str. 53a
90542 Eckental
Deutschland
Email:
easysafeshare@maskow.io
When you create a message it is encrypted in your browser with AES-256-GCM. The key is generated in your browser as well and exists only behind the # sign of the resulting link. Browsers never transmit that part of an address to a server.
What sits on our servers is therefore an encrypted record we cannot decrypt. We can neither read the contents of a message nor hand them over on request – including to authorities.
Encrypted message content: we store the encrypted text, a random link identifier, whether a password was set, whether the message is deleted after being opened, and the expiry time. The plaintext and the key never reach us.
IP address: to prevent abuse (bulk creation of messages, guessing links) we limit the number of requests per IP address. For that the IP address is counted briefly in a cache. It is not linked to any particular message.
Server log files: loading the site technically produces access data at our hosting provider (IP address, timestamp, requested address, volume transferred, browser type). These serve the operation and security of the website.
Cookies: we set two strictly necessary cookies – one protecting against cross-site request forgery and one for the session, which also holds your language choice. Both are required for operation, contain no advertising identifier, and therefore need no consent under § 25 (2) no. 2 TDDDG.
We count how many messages are created per calendar day, and how many of those use self-destruct or an additional password. All that is stored is the date and a counter.
No times of day, no IP addresses, no content and no reference to an individual message are stored. These numbers cannot be traced back to you or to any particular message. The legal basis is our legitimate interest in understanding usage under Art. 6 (1) (f) GDPR.
We use no analytics tools, no advertising networks, no social media plugins and no external fonts or content delivery networks. Every resource on the page is served from our own server. There is no profiling and no automated decision-making.
Processing the encrypted message content serves the delivery of the service you requested, under Art. 6 (1) (b) GDPR.
Processing the IP address and log files to prevent abuse and keep the service running is based on our legitimate interest under Art. 6 (1) (f) GDPR.
Messages with self-destruct enabled are deleted the moment they are retrieved. Independently of that, every message is deleted automatically and permanently no later than 7 days after it was created – even if it was never opened.
The rate-limiting counters expire after a few minutes, at most one hour. Retention of server log files follows our hosting provider’s policy.
Your data is not sold and not passed on for advertising. The only party with access is our hosting provider, which operates the servers and with which a data processing agreement under Art. 28 GDPR is in place:
Laravel Cloud, betrieben von Laravel Holdings, Inc. (USA)
Infrastructure: Amazon Web Services (AWS)
Server location: EU Central (Frankfurt am Main, Deutschland)
Our hosting provider is based in the United States, but the servers themselves are located in the region we selected inside the European Union. In normal operation your data is not processed outside the EU.
Where support access from a third country is nevertheless possible, it relies on the European Commission’s Standard Contractual Clauses under Art. 46 (2) (c) GDPR, or on certification under the EU-US Data Privacy Framework.
You have the right to access the data held about you (Art. 15 GDPR), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21 GDPR).
One honest caveat: we store nothing alongside a message that would let us link it to you – no account, no email address, no IP stored with the message. We therefore cannot give you information about a specific message or delete it on request. Every message deletes itself after 7 days regardless.
You also have the right to lodge a complaint with a data protection authority. The competent one here is the Bavarian Data Protection Authority (BayLDA), Promenade 18, 91522 Ansbach, Germany.
The encryption protects the content in transit and in our database. It does not prevent the recipient from photographing, copying or forwarding the message, and it does not prevent someone who intercepts the complete link from reading it before the recipient does. Send the link and the password through two different channels.
For questions about data protection you can reach us at: