Hidetext.sh
encrypted pastebin where the server never sees the key
Details
- External ID
- 48871436
- Source
- HN
- Company
- —
- Product
- Hidetext.sh
- Website domain
- hidetext.sh
- Launched
- July 11, 2026
- Cohort
- —
- Upvotes
- 7
- Upvotes percentile
- 0.3972520908004779
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
Hi HN! I built hidetext.sh — a way to share text, code, and files through links the server can't read.How it works: your browser generates a random key and encrypts everything locally (NaCl secretbox, XSalsa20-Poly1305). Only ciphertext is uploaded. The key goes into the URL fragment — the part after # — which browsers never send to servers. The link carries the key, my server stores the locked box, and the two only meet in a browser.A design detail I'm fairly happy with: burn-after-read doesn't destroy the paste on the first HTTP request. The naive version means a Slack or iMessage link preview "reads" your paste before the recipient ever opens it. Instead, the reader's tab sends a heartbeat, and the paste is deleted only once nobody is watching it anymore.Being upfront about the limits (full page at hidetext.sh/how-it-works): you're trusting the JavaScript I serve — inherent to any browser-based E2E tool; filenames are stored in plaintext (contents aren't); and anyone holding the link can read the content, because the link is the key. No accounts, no cookies, no analytics, IPs aren't stored.Stack: Next.js static on Cloudflare Pages, Pages Functions, D1 for metadata, R2 for encrypted blobs.It's free. I'd love feedback — especially on the threat model and anything you'd expect from a tool like this that's missing.
Enrichment
- Theme
- file transfer and sharing tools
- Vertical
- Security
- Function
- Vertical SaaS
- Audience
- B2C
- AI stance
- Not AI
- Project type
- Commercial product
- Normalized one-liner
- encrypted pastebin with client-side encryption
- Manually corrected
- False
Could you build this?
Yes The client-side encryption flow using TweetNaCl / libsodium (XSalsa20-Poly1305) in the browser with fragment-based keys and an encrypted blob storage backend is a well-established pattern achievable in days.
Discussion
1 comment analyzed.
Competitors mentioned: PrivateBin
Competitors
Other products that read as similar to this one — 281 launches clear the similarity bar, closest 8 shown.
Attention rank: #140 of 282 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 255 days after the earliest competitor.
- Online Clipboard · ph · 2026-09-13 · 1 upvotes · similarity 0.53
- Classified · ph · 2026-09-10 · 1 upvotes · similarity 0.52
- Nullsec · hn · 2026-09-17 · 6 upvotes · similarity 0.52
- SendKey · ph · 2026-09-08 · 2 upvotes · similarity 0.51
- just f***ing send it · ph · 2026-06-19 · 155 upvotes · similarity 0.49
- Encoder · ph · 2026-09-29 · 2 upvotes · similarity 0.47
- Wormhole.page · hn · 2026-03-22 · 6 upvotes · similarity 0.46
- Portable Secret · hn · 2026-02-26 · 5 upvotes · similarity 0.46
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a vertical saas tool for Insurance yet.