Secretus — Share a Secret by Secretus
Share one-time, end-to-end encrypted secrets from Firefox. Encryption happens on your device, and decryption keys are never sent to Secretus secret endpoints.
Some features may require paymentSome features may require payment
Available on Firefox for Android™Available on Firefox for Android™
1 User1 User
Scan the QR code to open this extension in Firefox for Android
Extension Metadata
Screenshots
About this extension
Share passwords, API keys, recovery codes, private notes, and files through one-time, end-to-end encrypted links that become unavailable after their first successful retrieval.
Secretus encrypts your secret on your device before upload. During normal operation, Secretus secret endpoints receive ciphertext rather than plaintext. The decryption key stays in the URL fragment of the link you share and is not included in HTTP requests to Secretus secret endpoints.
ABOUT THE DATA PERMISSIONS FIREFOX SHOWS YOU
Firefox lists “personal communications” because encrypted secrets pass through and are temporarily stored by Secretus so the recipient can retrieve them. Secret content arrives as ciphertext, and the decryption key is not sent to Secretus secret endpoints.
Optional labels are not encrypted and are readable by the service. “Authentication information” covers your account email, authentication tokens, and the information required to sign in.
WHAT YOU CAN DO
- Share a password, API key, recovery code, or private note in seconds
- Select text and choose “Share selection securely with Secretus”
- Attach files encrypted on your device before upload with the Business plan
- Set an expiry between 15 minutes and 30 days
- Label secrets and track them in “My secrets”
- See when a link was opened and revoke unopened links instantly
- Open Secretus using Ctrl+Shift+S or ⌘⇧S on macOS
SECURITY DETAILS
- AES-256-GCM encryption using Firefox’s native WebCrypto implementation
- Decryption keys remain in URL fragments and are not sent to or stored by Secretus secret endpoints
- Each link can be retrieved successfully only once
- After retrieval, the link is invalidated immediately and the encrypted payload is queued for deletion, with expiry cleanup as a backup
- Password sign-in uses SRP, so your password is not transmitted by the add-on
- No analytics, advertising trackers, or browsing-history permission
- Page content is accessed only when you explicitly choose to share selected text
- Disabled in private browsing by design
A Secretus account is required. New accounts receive a 14-day free trial with no credit card required. After the trial ends, choose a paid plan to continue creating secrets. See secretus.app/offer.
Recipients can open generated links in a compatible browser without installing the extension or an app.
Secretus encrypts your secret on your device before upload. During normal operation, Secretus secret endpoints receive ciphertext rather than plaintext. The decryption key stays in the URL fragment of the link you share and is not included in HTTP requests to Secretus secret endpoints.
ABOUT THE DATA PERMISSIONS FIREFOX SHOWS YOU
Firefox lists “personal communications” because encrypted secrets pass through and are temporarily stored by Secretus so the recipient can retrieve them. Secret content arrives as ciphertext, and the decryption key is not sent to Secretus secret endpoints.
Optional labels are not encrypted and are readable by the service. “Authentication information” covers your account email, authentication tokens, and the information required to sign in.
WHAT YOU CAN DO
- Share a password, API key, recovery code, or private note in seconds
- Select text and choose “Share selection securely with Secretus”
- Attach files encrypted on your device before upload with the Business plan
- Set an expiry between 15 minutes and 30 days
- Label secrets and track them in “My secrets”
- See when a link was opened and revoke unopened links instantly
- Open Secretus using Ctrl+Shift+S or ⌘⇧S on macOS
SECURITY DETAILS
- AES-256-GCM encryption using Firefox’s native WebCrypto implementation
- Decryption keys remain in URL fragments and are not sent to or stored by Secretus secret endpoints
- Each link can be retrieved successfully only once
- After retrieval, the link is invalidated immediately and the encrypted payload is queued for deletion, with expiry cleanup as a backup
- Password sign-in uses SRP, so your password is not transmitted by the add-on
- No analytics, advertising trackers, or browsing-history permission
- Page content is accessed only when you explicitly choose to share selected text
- Disabled in private browsing by design
A Secretus account is required. New accounts receive a 14-day free trial with no credit card required. After the trial ends, choose a paid plan to continue creating secrets. See secretus.app/offer.
Recipients can open generated links in a compatible browser without installing the extension or an app.
Rated 0 by 0 reviewers
Permissions and data
Optional permissions:
- Access your data for api.eu.secretus.app
- Access your data for secretus-eu-1765116481.auth.eu-central-1.amazoncognito.com
- Access your data for cognito-idp.eu-central-1.amazonaws.com
Required data collection, according to the developer:
- Authentication information
- Personal communications
More information
- Add-on Links
- Version
- 1.0.5
- Size
- 147.42 KB
- Last updated
- 2 days ago (Aug 31, 2026)
- Related Categories
- License
- All Rights Reserved
- Privacy Policy
- Read the privacy policy for this add-on
- Version History
- Add to collection