A CLEARER KIND OF PRIVACY

Private sharing.
Plain explanations.

You should know what a tool protects,
and where its protection ends.

What Gliiph does, and what it doesn’t.

Gliiph is built for temporary handoffs. The aim is less sensitive information left sitting in everyday conversations.

Ad-free, on every pageNo account for free sharingEncryption in your browserNo third-party scripts on the composer, recipient, sign-in, or account pages

Encryption happens in your browser.

Your note is encrypted with AES-256-GCM before it is sent. What we store is ciphertext. The key travels in the fragment of the link, the part after the #, which your browser does not send to our server.

A complete link is sensitive.

Anyone who has the full link can open the note. Send it through a channel you trust. Plus can add a separate password, which you should share a different way.

Deletion has a specific meaning.

The hosted copy is deleted after the note is opened, or when its expiration passes. That does not erase copies, screenshots, browser history, or anything the recipient saved.

Two kinds of logs.

Gliiph does not log note contents, keys, or the IP addresses behind a note at the application level. Our hosting provider keeps standard infrastructure logs. The privacy policy spells out the difference.

Two different threats.

A breach of our stored ciphertext exposes nothing readable without the keys. Code delivered to your browser is a separate trust boundary. We keep the composer, the recipient page, sign-in, and your account free of third-party scripts to keep that boundary small. Cookieless analytics run only on the guides, pricing, how-it-works, security, and contact pages.

Security is more than a label.

One-time sharing does not replace individual accounts, permission controls, credential rotation, or your own security policies. It removes one copy from one conversation.

Try it with something harmless.

Create your first note