Your message disappears after it is read. No trace.

Zero-Knowledge Encryption: Your message is encrypted locally before it is sent.

mBox.pl Security Stack

Private communication without compromise

Every message is encrypted on the client side and ready to share securely with a single link.

Go to mBox

Security

Zero-Knowledge Encryption

Content and key stay exclusively on your side. The server stores only an encrypted payload.

Technology

AES-GCM Algorithm

A modern cryptographic standard combines confidentiality and integrity to detect tampering attempts.

Privacy

100% Privacy

No profiling, no data sales, and no activity tracking. You decide what to share and with whom.

Your data, your keys. Discover real Zero-Knowledge security.

Secure transfer of sensitive data without compromise

mBox.pl is a modern tool created for secure sharing of sensitive information in a digital world. Whether you are sending a banking password, an API token, or a confidential company document, mBox.pl guarantees that no one - including us - can read your message.

The key to our system is client-side encryption. This means your data is secured directly in your browser before it even reaches the network. It is the simplest, fastest, and safest way to transfer data, without creating an account or installing software.

Illustration and technology

Below is a visual summary of the Zero-Knowledge model and the encryption process before data is sent.

Illustration of the Zero-Knowledge security model in mBox.pl

How do we work?

mBox.pl bases its security on the Zero-Knowledge model. In practice, this means the mBox.pl server is only a "blind courier". It receives an encrypted data package but never has the key required to open it. This key is generated locally by the sender and becomes part of a unique link (the fragment after #), which is never sent to our systems.

Encryption itself uses the banking-grade AES-256-GCM standard. This modern cryptographic algorithm guarantees confidentiality (no one can view the content) and integrity (no one can modify the message in transit). If anyone attempts to alter the encrypted payload, the recipient will not be able to decrypt it.

An additional layer of protection is the self-destruct rule. You can set the message to be permanently removed from the server according to selected rules.

This ensures that confidential information does not stay online a second longer than necessary, eliminating the risk of a later leak.

  • After first read (Burn after reading) Perfect for one-time password or token sharing. The recipient opens the link once and the message disappears.
  • After a specified time (e.g. 1h, 24h, 7 days) Useful for documents or access codes that should expire after a defined period.

Key benefits

Full privacy

With client-side encryption, your secret never reaches the server in readable form.

Speed and simplicity

Generate a secure link with one click. No registration and no email required.

Self-destruct policy

Full control over data lifetime. Data disappears permanently.

AES-256-GCM

Banking-grade encryption standards protect your message from tampering.

No ads, no tracking

mBox.pl is a security tool. We do not profile users and we do not track activity.

Frequently Asked Questions

Why is Zero-Knowledge encryption safer than traditional methods?

Zero-Knowledge encryption means the decryption key never leaves your browser. The server stores only encrypted data and has no physical ability to read it. Unlike classic solutions where an admin may access content, here even the server owner cannot learn the message content.

Can I safely send passwords via WhatsApp?

WhatsApp offers end-to-end encryption, but messages remain in chat history on both devices. Anyone with phone access can read them later. mBox.pl allows expiration after one read or time limit, eliminating future leak risk.

Why not send passwords via email?

Most email servers do not encrypt messages end-to-end. Email can be stored on intermediate servers, in sender and recipient mailboxes, and in backups. Mail admins, hosting providers, or people with account access can read contents. mBox.pl encrypts data locally before sending and deletes it after reading.

Can the mBox.pl administrator read my message?

No. The decryption key is only in the link (URL fragment after #), which is never sent to the server. The server stores only an encrypted data package that cannot be decrypted without the key.

How does mBox.pl differ from sending files via Google Drive or Dropbox?

Google Drive and Dropbox do not encrypt data in Zero-Knowledge mode by default - the provider has key access. Files remain in the cloud long-term and require an account. mBox.pl encrypts data locally, requires no registration, and messages expire automatically after reading or time limit.

What does "burn after reading" mean?

The "1 view" option causes the message to be permanently deleted from the server immediately after first read. The recipient cannot open it again and the link stops working. It's ideal for sending passwords or one-time tokens.

How can I trust that the server really has no key access?

The decryption key is placed in the URL hash fragment (after #). Browsers never send this part of the address to the server. You can verify this in browser dev tools (Network tab) - no HTTP request contains the key.

Why not share passwords via Slack, Microsoft Teams, or other corporate messengers?

Corporate messengers store message history on servers accessed by organization admins and the platform provider. Messages can be archived, indexed, and retained for compliance. mBox.pl stores no metadata about content and deletes data after the selected time.

How does the AES-GCM algorithm used by mBox.pl work?

AES-GCM (Galois/Counter Mode) is a modern cryptographic standard combining encryption (AES) with authentication (GCM). It not only hides content but also detects any tampering attempts. If someone tries to modify the encrypted message, decryption fails with an error.

Is mBox.pl better than password generators with sharing features?

Password managers have varying encryption quality and don't always offer burn-after-reading or short expiration times. mBox.pl is an independent tool you can use to share any data (not just passwords), without installing apps or creating accounts.

Does mBox.pl store logs with my data?

We store only minimal technical logs necessary to prevent attacks (e.g., IP, request time). However, we do not log the contents of your messages or decryption keys, because we cannot see them. Technical logs are regularly purged.

What happens if I lose the message link?

Due to Zero-Knowledge architecture, we have no way to recover your message or key. If the link is lost, the content will remain encrypted on the server until expiration time, after which it will be permanently deleted.

Are files sent through mBox.pl also encrypted?

Yes. Every attachment is encrypted in your browser before sending with the same key as the text message. The recipient downloads the encrypted file, which is decoded locally on their device.

Is mBox.pl GDPR compliant?

Yes. The mBox.pl project implements 'Privacy by Design' and 'Privacy by Default' principles. We minimize data collection, and thanks to end-to-end encryption, we are not the administrator of your message content because we have no access to it.

Is the service free?

Basic mBox.pl features are and always will be free. In the future, we plan to introduce Premium accounts for businesses, offering larger file limits, SMS notifications, and dedicated team panels.