Here. For a while.

Identity
MessageGroup chatShort link
Receive

Between open tabs

Create a message

Write a message and share it with a secret link.

Plain text · up to 32 KiB

Use Markdown for bold, quotes, lists, and code.

.md, .markdown or .txt · UTF-8 · up to 32 KiB
Supported Markdown formatting

Preview shows what recipients will see. These formats are supported:

Bold
**bold text**
Italic
*italic text*
Strikethrough
~~crossed out~~
Headings
# Heading
Use one to six # characters.
Quotes
> Quoted text
Lists
- Bullet item
1. Numbered item
Inline code
`code`
Code blocks
```js
console.log("Hello");
```
Links
[label](https://example.com)
Divider
---
On its own line, after a blank line.
Tables
| Item | Value |
| --- | --- |
| A | 1 |

HTML stays as text. Images are shown as their descriptions. Code blocks keep their spacing; syntax highlighting is not applied.

Voice

Disguised changes your voice’s pitch and tone in this browser. It does not guarantee anonymity.

Record up to 5 minutes. Listen before sharing.

0:00

Up to 5 minutes. Attach your recording, then listen before sending.

Up to 5 files · 1 GB each

[↔]

A room held by its people.

Everyone can write. Messages pass directly between peers and stay only in open browsers.

A name is generated for the group. Share its secret link to invite someone. The room ends when its last participant leaves.

Up to 16 participants · Available history travels with peers
How long should it stay?
How long should it stay?

Held stores this address only until the link expires.

No accounts. No click tracking.

Here. Until then.

Your short link is ready.

Expires

Anyone with this link goes straight to your destination until it expires.

Your short links

Saved only in this browser, including expired links. Your most recent 100.

Links you shorten here will appear here.

    Once created, the message cannot be edited.

    Held between us

    Your message is here.

    Keep this tab connected to hold the message.

    While the creator's original tab is herePlain text · read only
    Signed by

    Voice

    Disguised changes your voice’s pitch and tone in this browser. It does not guarantee anonymity.

    0:00

    Up to 5 minutes. Attach your recording, then listen before sending.

    Receiving shares verified pieces while you are here. Up to 5 GB of encrypted cache per room, removed when you leave.

    Leaving removes the message and temporary attachments from this tab. Files you already downloaded are kept.

    Anyone with the full link can read while the message is available.

    Nothing held here

    This message is unavailable.

    It may have ended, or no connected tab can pass it on.

    Write a new message ↗
    Encrypted in your browser.— message links— groups— active peers
    How it worksPrivacyFeedback

    Between devices

    Share to another device

    Choose how to connect. You will approve the other device before sharing.

    On the receiving device, open Held’s Receive page.

    Open Held’s Receive page and type this code.

    1. On the other device, open the message or room you want to share.
    2. Tap Share, then Scan QR code.
    3. Point its camera at this screen.

    On the receiving device, open Held’s Receive page and choose Show QR code.

    Do both screens show these same numbers?

    Compare the numbers, then approve on the device sharing with you.

    Keep the sharing device connected while receiving. Files you save on this device remain after you leave Held.

    This session

    Room details

    Holding this message open

    This counts tabs holding a copy of this message, including yours. It counts open tabs, not unique people.

    This room, right now

    Participants

    You and the other participants holding this room. An identity appears once your secure peer connection is ready.

      A reconnecting participant is still in the room. Departure notices appear in the chat when someone leaves; they stay in your current tab.

      Across Held

      A little activity.

      —Message links created
      —Groups created
      —Active peers

      Loading aggregate activity…

      Created links, not message deliveries.

      A new simple-message link counts once. Opening or forwarding it adds no new message. Individual posts inside peer chats are not counted.

      Connections, not unique people.

      Active peers estimates admitted connections holding messages or groups. One person in two different rooms counts twice. Updates can lag briefly.

      Totals from existing room activity.

      These counts use creation and connection information the registry already handles. They add no tracking cookies or browser identity reporting. Historical activity before counting began is not included.

      Signature verified

      This message’s sender.

      This generated identity signed the message and was authorized by its original creator. It stays with the message as other browsers carry it.

      To recognize this sender later, keep the full sender ID and message ID. Use Identity → Prove a past identity with a fresh challenge. A signature proves control of a key; it does not identify a person.

      No account. No chosen username.

      Your signing identity.

      Use one saved identity across messages and rooms, or use a different automatic identity for each one.

      Saved public ID

      Identity backup and recovery code

      Each new backup creates an encrypted .json file and a fresh recovery code that unlocks only that file. Your identity and public ID stay the same.

      Previously downloaded backup-and-code pairs remain valid. Keep each file with its matching code. One saved pair is enough to restore your identity.

      Keep both items private, ideally in separate locations: the .json backup in one place and its matching recovery code in another. Anyone with both can use your identity. Neither is sent to Held.

      Save both items below as a matching pair.

      1. Encrypted .json backup

      Download .json backup

      2. Recovery code for this backup

      Download recovery code
      Restore on this device
      Prove a past identity

      Sharing a cross-room proof lets people connect this identity with other rooms where you explicitly share it. Other rooms remain separate.

      Share your short link

      Scan this link.

      Scan to open the short link.

      Expires

      A note to the creator

      Send feedback

      Ideas, problems, or a note for Held’s creator.

      0 / 5,000 characters

      Leave an address if you would like a reply.

      No account or signing identity is needed.

      Spam check

      Cloudflare Turnstile checks that this feedback comes from a person.

      The spam check loads when you open Feedback.

      Closing this card keeps your draft in this tab. Reloading clears it.

      A little context

      What privacy means here.

      Your message is encrypted in your browser and passed directly between connected browsers. The registry coordinates connections and availability; it does not receive the message or its decryption key.

      The full link is the key.

      Anyone with the complete link can read while a holder is reachable. Share it with care. The key stays in the link fragment, outside the network request for the page.

      Open tabs keep it available.

      By default, the creator's original tab must stay connected. Closing it, reloading, or going offline can end the message. The carried-message mode lasts while at least one connected holder remains. The creator can end either message mode from the original session. Groups have no creator-only End control: the final participant leaving ends the room.

      One tab per browser profile.

      Only one tab in this browser profile can hold a room. Automatic mode produces a different public identity for each room. Creating or restoring a saved identity explicitly uses the same public ID across future messages and rooms, so other participants can recognize it. It stays selected in this browser until changed, signed out, or removed by clearing Held site data. Simple messages carry a verified sender ID inside their encrypted package. Participant IDs are exchanged only over secure peer connections while you hold a message or room. Group aliases and signatures also travel only between peers. Sharing a cross-room proof is optional. Other browsers and private windows are separate unless you restore an encrypted identity backup. Clearing site storage loses the identity without a backup; restoring never recovers old messages or creator control. Your black or white theme preference is also saved only in this browser.

      Your voice stays in the attachment.

      The microphone starts only when you choose Record. Voice messages use the same encrypted transfer and lifetime as other files. Disguised mode changes the sound in your browser before recording; it does not guarantee anonymity. What you say, speech patterns, and background sounds can still identify you. Anyone who saves a recording can keep their copy.

      Peers carry the available history.

      New group participants receive messages still held by connected peers: up to 200 messages and 512 KiB of text. History stays in memory and is cleared when a tab leaves or loses its required connection. There is no server archive. Attachments transfer directly between peers. Files are received on request in messages and groups. Participants share verified pieces while connected; every piece must remain held somewhere for a complete download. Received pieces use independent encrypted temporary storage for each room, capped at 5 GB per room subject to available browser storage. They are removed when you leave, cancel, or lose your session. Cache keys stay only in memory. After a browser crash, leftover encrypted files are removed on your next visit. Saved downloads remain yours.

      Short links have a deadline.

      Shortening stores the destination address on Held until its chosen expiry. It is not encrypted like a message. Visits redirect without click counts, accounts, or added tracking parameters. Expired destinations are removed from server storage. Your latest 100 created links, including their original addresses and expired entries, stay in this browser’s local history until you remove or clear them. That history is never sent to Held. Secret Held message and chat invitations cannot be shortened, so their keys stay in the browser.

      Feedback goes to Held’s creator.

      Feedback stores the message and any optional reply email in Cloudflare, where Held’s creator can read them until they delete them. It is not encrypted like a Held message. Feedback does not include your current page address, secret invitation key, or signing identity unless you type them into your note. An unsent draft stays only in the current tab and clears on reload. Opening Feedback loads Cloudflare Turnstile, which processes browser and network information to check for spam. The verification token is checked before saving and is not stored with your feedback.

      Public activity shows totals.

      The registry counts newly created message links and groups, and estimates active peer connections. Public stats contain no room IDs, names, message contents, IP addresses, or signing identities. One person can count as multiple peers.

      Ending cannot erase a saved copy.

      Ending asks cooperating tabs to clear the message. Recipients can still copy, save, photograph, or modify their client to keep it.

      This does not make you anonymous.

      Connection services and other browsers may see your IP address. Browser code can access the decrypted message, so privacy also depends on trusting the code delivered by this site and your device.