At some point, almost everyone needs to hand a password to someone else — a new hire needs access to a shared account, a family member needs the Wi-Fi key, a client needs a login for a staging site. The instinct is to use whatever's closest: email, a text message, a Slack DM. All three are worse choices than most people realize.
Email is designed to be permanent and searchable. Once you send a password by email, it typically lives in at least four places: your sent folder, the recipient's inbox, and both providers' backup systems. If either account is ever compromised — even years later — that password is sitting there in plain text, easily found by searching for words like "password" or "login."
Many email providers also scan message content for spam filtering, ad targeting, or "smart" features, meaning the password may pass through systems never intended to handle sensitive credentials.
SMS messages are typically unencrypted in transit and are frequently backed up automatically to cloud services tied to your phone. A password sent by text can end up duplicated across a phone, a cloud backup, and a carrier's systems — all without anyone intending for that to happen.
Workplace chat tools retain message history by default, often indefinitely, and are searchable by anyone with the right permissions — including future employees who join a channel later and can scroll back through years of history. A password dropped into a channel "just for now" frequently outlives the reason it was shared.
Say you need to give a contractor temporary access to a CMS login. Instead of typing the password into a Slack message, you'd paste it into a one-time secret tool, set it to expire after a single view or a few hours, and send the resulting link. The contractor opens it, copies the password, and the link is immediately useless to anyone else — including if the Slack channel itself is later searched or exported.
Need to share a password right now? Create a one-time encrypted link — no account required.