neverstored: hand over a secret without leaving traces

Andrea Fontana nospam at example.org
Mon Sep 14 15:07:37 UTC 2026


Hi everyone,

I just wanted to share a small project I wrote called neverstored.

The idea is simple: sometimes you need to share a password, an 
API key, or a config file with a colleague. If you drop it in 
Slack or email, it's there forever in the backups. Even if you 
use a one-time link service, your secret is still parked on some 
server's database until it's opened.

neverstored takes a different route: it doesn't store anything at 
all. You write the secret, and it stays local. You share a link, 
both parties verify 4 matching symbols on screen to prevent MitM, 
and the clients establish an end-to-end encrypted connection. The 
server just passes the AES-encrypted bytes from one connection to 
the other and forgets them instantly.

The backend is written in D using serverino, and it compiles into 
a single, zero-dependency binary. I also built a terminal CLI (in 
D as well) that can talk seamlessly to the browser clients.

Repo is here if you want to take a look: 
https://github.com/trikko/neverstored
You can try it live at: https://neverstored.com

Let me know what you think!

Andrea


More information about the Digitalmars-d-announce mailing list