Frequently asked questions
Frequently asked questions
Can you read my secrets?
No. The secret is encrypted in your browser before it is sent, with a key that stays in the link, after the # sign. Browsers never send that part of the address to servers. We only receive an unreadable encrypted block.
Is it really free?
Yes, with no account, no ads and no time limit. A paid enterprise plan (white label, teams, SSO) will come later, without removing any free feature.
What happens after it is read?
The secret is deleted from our database in the same operation as the read. If someone opens the link again, they see the same message as for an unknown link.
What if Slack or Outlook opens the link before my recipient?
No risk. The link page does not contain the secret. It is only sent after a click on “Reveal”, which link previewers do not do.
Can the recipient keep a copy of the secret?
Yes, and no service can prevent it: once displayed, a secret can be copied, written down or photographed. Sésame Éclair guarantees that the link opens only once and that nothing remains on our side; it does not control what the recipient does afterwards. Only send secrets to people you trust.
Does the recipient need an account?
No. A recent browser is enough, on a computer or a phone. Nothing to install or sign up for, for you or for them.
Why not a disappearing message on Signal or WhatsApp?
Disappearing messages require you both to use the same messaging app, and their lifetime depends on the conversation's settings. A Sésame Éclair link opens in any browser, without an account; you choose the number of reads, the expiry and an optional code, and you know when it was read.
Why does the link say “not found”?
The secret has already been read, has expired, was destroyed by its sender, or the link was copied incorrectly. We deliberately show the same message in every case, so as to reveal nothing to a third party. Ask the sender for a new link; their tracking link will tell them whether someone else read it.
Can you recover a secret that was read or has expired?
No. A read secret is deleted in the same operation as the read; an expired secret becomes unreadable at once, then is purged. And we never had the key: even a technical copy of the database would only hold an encrypted block.
Can I ask someone to send me a secret?
Yes, for free: create a drop link from the “Request a secret” page and send it to your client or colleague. Whatever they drop is encrypted in their browser for you alone.
How can I tell a genuine Sésame Éclair link?
The official service is at eclair.kayzen-lyon.com. Some organisations use their own domain, for example secrets.their-company.com. If the address surprises you or the message pressures you to act, check with the sender through another channel before opening the link.
What would you hand over if an authority asked?
Only what we hold: an encrypted block, unreadable without the link's key, and a few dates. We have neither the key, nor the content, nor your IP address in our database. A secret that was read or expired is deleted from our database.
What is the PIN for?
It protects the secret if the link falls into the wrong hands. Send it through another channel (phone, text). After 5 wrong attempts, the secret is destroyed.
Is a 4-digit PIN enough?
Against someone who only has the link, yes: only 5 attempts. Against an attacker holding both the link and a copy of our database, a short code can be cracked. For a critical secret, choose a passphrase.
How do I know my secret was read?
After creating it, keep the tracking link. It shows the status (waiting, read, expired, destroyed) and the date of each event.
Can I destroy a secret before it is read?
Yes, from the tracking link, with the “Destroy now” button.
How long does a secret stay available?
From 5 minutes to 30 days, as you choose. It disappears as soon as it has been read the planned number of times, or at expiry.
Can I send a secret to several people?
Yes: add recipients and each gets their own link, with a separate read receipt and revocation. You can also allow up to 10 reads for one link.
Where is the data hosted?
In the European Union: the application runs in Paris, the database is in Frankfurt. Our hosting providers are listed in the legal notice. End-to-end encryption limits what they can see to an encrypted block and a few dates.
Do you keep my IP address?
Our database does not contain it. To limit abuse, we use a non-reversible fingerprint that changes daily and disappears within 24 hours. The hosting provider's technical logs are described in the privacy policy.
Do you use cookies or trackers?
No trackers, no analytics, no third-party scripts. Hence no cookie banner.
How can I check that encryption happens in my browser?
The “What the server sees” page runs our real code and shows the request that is sent. You can also watch that request in your browser's developer tools (F12, Network tab).
Which algorithms do you use?
AES-256-GCM for content, HKDF-SHA-256 to derive keys, Argon2id (64 MiB) for the PIN, all through native browser implementations or proven libraries. The full format is published on the Security page.
Has the service been audited?
Not yet. An external security audit is planned before version 1.0, and its report will be published. Meanwhile, the cryptographic format and its test vectors are public.
What if I lost the link?
Nobody can recover it, not even us: the key only exists in the link. Create a new secret and, if needed, destroy the old one from the tracking link.
Can I share files?
Yes: up to 10 files and 100 MB per send, stream-encrypted on your device before upload, kept 7 days at most and deleted after download.
How does it relate to Sésame?
Sésame Éclair is the sister product of Sésame, KAYZEN's free password manager. Sésame keeps what must last; Éclair sends what must disappear.
How do I report an abusive link?
From the “Report abuse” page. A clearly abusive link is destroyed; we cannot read its content.
Is there an API?
Yes: API v1 is publicly documented (OpenAPI 3.1 specification), as are the command line and the MCP server. Encryption always stays on your side.