Ash QR
Exchange one-time encrypted messages across the web, iOS, and Android while cryptographic operations stay on the current device
Cross-platform use and security boundary
The website, iOS app, and Android app interoperate: the recipient creates an inbox code, the sender creates a message code, and the original recipient opens it. Loading the web page requires a connection, but QR processing and cryptography stay on the device. Analytics are disabled here.
A web inbox private key exists only in the current page's memory, so its inbox code lasts about 30 minutes. Apps can retain keys longer in secure device storage. A message keeps the expiration encoded in its inbox code; sending it does not restart the clock.
iOS hides content when the system reports a screenshot or screen recording. Android uses a secure window to block screenshots and insecure casting. A website cannot block system screenshots, and no platform can stop another device from photographing the screen. Use a trusted channel.
Related tools
Share temporary text through an encrypted link that works once and expires in 5 minutes
Generate TOTP codes from a Base32 secret or otpauth URI in your browser
Generate QR codes from text or URLs — download as PNG
Upload a QR code image and decode its text or link in your browser