Your message is encrypted in your browser and passed between connected browsers. The registry coordinates connections and availability; it does not receive the message or its decryption key.
The full link is the key.
Anyone with the complete link can read while a holder is reachable. Share it with care. The key stays in the link fragment, outside the network request for the page.
Open tabs keep it available.
By default, the creator's original tab must stay connected. Closing it, reloading, or going offline can end the message. The carried-message mode lasts while at least one connected holder remains. The creator can end either message mode from the original session. Groups have no creator-only End control: the final participant leaving ends the room.
One tab per browser profile.
Only one tab in this browser profile can hold a room. Automatic mode produces a different public identity for each room. Creating or restoring a saved identity explicitly uses the same public ID across future messages and rooms, so other participants can recognize it. It stays selected in this browser until changed, signed out, or removed by clearing Held site data. Simple messages carry a verified sender ID inside their encrypted package. Participant IDs are exchanged only over secure peer connections while you hold a message or room. Group aliases and signatures also travel only between peers. Sharing a cross-room proof is optional. Other browsers and private windows are separate unless you restore an encrypted identity backup. Clearing site storage loses the identity without a backup; restoring never recovers old messages or creator control. Your black or white theme preference is also saved only in this browser.
A relay is optional.
Connection relay is off by default when creating a message or group. Enabling it allows encrypted traffic through a relay if a direct connection is blocked. This trades some connection privacy for reliability: the extra relay provider sees network addresses, timing, and traffic volume, but cannot read the content. Direct connections do not guarantee anonymity either. The required holders must still stay connected; it adds no server mailbox. The setting travels with the secret link and cannot be changed for an existing room.
Your voice stays in the attachment.
The microphone starts only when you choose Record. Voice messages use the same encrypted transfer and lifetime as other files. Disguised mode changes the sound in your browser before recording; it does not guarantee anonymity. What you say, speech patterns, and background sounds can still identify you. Anyone who saves a recording can keep their copy.
Peers carry the available history.
New group participants receive messages still held by connected peers: up to 200 messages and 512 KiB of text. History stays in memory and is cleared when a tab leaves or loses its required connection. There is no server archive. Attachments transfer between peers, using the optional encrypted relay if enabled and needed. Files are received on request in messages and groups. Participants share verified pieces while connected; every piece must remain held somewhere for a complete download. Received pieces use independent encrypted temporary storage for each room, capped at 5 GB per room subject to available browser storage. They are removed when you leave, cancel, or lose your session. Cache keys stay only in memory. After a browser crash, leftover encrypted files are removed on your next visit. Saved downloads remain yours.
Short links give you a choice.
Traditional is the default: a 25-character link on held.cat, including https://. Held stores the full destination until expiry and can read it. Encrypted links are 40 characters: your browser encrypts the destination, and Held stores only the encrypted address and its expiry. The key stays in the part of the complete link after #; the app does not send the destination or key to Held. Anyone with either complete link can open it until expiry, and neither option adds click tracking. Your latest 100 destinations and complete links remain in this browser’s local history, including expired entries, until removed or cleared. That history is never uploaded. Previously created links keep their original format and expiry. Secret Held message and chat invitations must be shared directly. Encryption depends on trusted browser code and cannot erase copied links, destinations, or browsing history.
Feedback goes to Held’s team.
Your feedback and optional reply email are saved for Held’s team to read and respond to until the team deletes them. If you leave an email address, expect a reply within a couple of days. Feedback is not encrypted like a Held message. It does not include your current page address, secret invitation key, or signing identity unless you type them into your note. An unsent draft stays only in the current tab and clears on reload. A spam check processes browser and network information when you open Feedback; its verification token is not stored with your message.
Public activity shows totals.
The registry counts newly created message links and groups, and estimates active peer connections. Public stats contain no room IDs, names, message contents, IP addresses, or signing identities. One person can count as multiple peers.
Ending cannot erase a saved copy.
Ending asks cooperating tabs to clear the message. Recipients can still copy, save, photograph, or modify their client to keep it.
This does not make you anonymous.
Connection services and other browsers may see your IP address. Browser code can access the decrypted message, so privacy also depends on trusting the code delivered by this site and your device.