Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Hidetext.sh

encrypted pastebin where the server never sees the key

Details

External ID
48871436
Source
HN
Company
—
Product
Hidetext.sh
Website domain
hidetext.sh
Launched
July 11, 2026
Cohort
—
Upvotes
7
Upvotes percentile
0.3972520908004779
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

Hi HN! I built hidetext.sh — a way to share text, code, and files through links the server can't read.How it works: your browser generates a random key and encrypts everything locally (NaCl secretbox, XSalsa20-Poly1305). Only ciphertext is uploaded. The key goes into the URL fragment — the part after # — which browsers never send to servers. The link carries the key, my server stores the locked box, and the two only meet in a browser.A design detail I'm fairly happy with: burn-after-read doesn't destroy the paste on the first HTTP request. The naive version means a Slack or iMessage link preview "reads" your paste before the recipient ever opens it. Instead, the reader's tab sends a heartbeat, and the paste is deleted only once nobody is watching it anymore.Being upfront about the limits (full page at hidetext.sh/how-it-works): you're trusting the JavaScript I serve — inherent to any browser-based E2E tool; filenames are stored in plaintext (contents aren't); and anyone holding the link can read the content, because the link is the key. No accounts, no cookies, no analytics, IPs aren't stored.Stack: Next.js static on Cloudflare Pages, Pages Functions, D1 for metadata, R2 for encrypted blobs.It's free. I'd love feedback — especially on the threat model and anything you'd expect from a tool like this that's missing.

Enrichment

Theme
file transfer and sharing tools
Vertical
Security
Function
Vertical SaaS
Audience
B2C
AI stance
Not AI
Project type
Commercial product
Normalized one-liner
encrypted pastebin with client-side encryption
Manually corrected
False

Could you build this?

Yes The client-side encryption flow using TweetNaCl / libsodium (XSalsa20-Poly1305) in the browser with fragment-based keys and an encrypted blob storage backend is a well-established pattern achievable in days.

Discussion

1 comment analyzed.

Competitors mentioned: PrivateBin

Competitors

Other products that read as similar to this one — 281 launches clear the similarity bar, closest 8 shown.

Attention rank: #140 of 282 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 255 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a vertical saas tool for Insurance yet.