To send a self-destructing message, put the text in a one-time link instead of a chat thread. Create a self-destructing note, set it to delete after one view or a short time limit, add a passcode if the content is sensitive, and send the link. Once it is read or expires, the link stops working.
Key takeaways
- Disappearing messages in chat apps can still survive in notifications, backups, linked devices and screenshots.
- A one-time link keeps the secret out of the chat thread entirely. All that stays behind is a dead link.
- Set the note to burn after one view and the shortest time limit that works for the recipient.
- Send the passcode through a different channel than the link, such as a phone call or a separate app.
- Nothing stops a recipient from taking a screenshot, so for passwords and keys, change them after they have been used.
What counts as a self-destructing message?
A self-destructing message is one that stops being readable after a set event: someone opens it, a timer runs out, or both. The point is that the content does not sit around in an inbox or chat history for months.
There are two common ways to do it. You can turn on disappearing messages inside a chat app, or you can send a self-destructing note: a link that opens the message once and then stops working.
Both sound similar. They behave very differently once you look at where copies end up.
Do disappearing messages in WhatsApp, Signal and Telegram really disappear?
They disappear from the chat window. That is not the same as disappearing everywhere. Chat apps delete the message from the conversation on schedule, but the content may already have been copied somewhere the timer does not reach.
Here is how the common options compare. Exact behavior depends on app version and settings, so treat this as a guide to where to look, not a guarantee.
| Option | How it deletes | Where copies can still survive |
|---|---|---|
| Signal disappearing messages | Timer set per chat | Notification previews, screenshots, photos of the screen |
| WhatsApp disappearing messages | Timer per chat (such as 24 hours, 7 days or 90 days) | Backups made before the timer ran out, forwards, screenshots, messages a participant chose to keep |
| Telegram secret chats | Self-destruct timer on that device's chat | Notification previews, screenshots where the app cannot block them, photos of the screen |
| Snapchat chats | Clear after viewing by default | Saved chats, screenshots (the sender may be told, but it is not prevented) |
| Gmail confidential mode | Expiry date, sender can revoke access | Your own Sent folder, screenshots, retyped copies |
| One-time link (self-destructing note) | Destroyed after a set number of views or a time limit | Screenshots or copy-paste by the recipient. The chat only holds a link that no longer works |
Notice the pattern. Every option is vulnerable to a determined recipient with a camera. The difference is how many copies get made automatically, without anyone meaning to.
Where do copies of a disappearing message still end up?
Most leaks are not deliberate. They happen because phones and computers are built to save things.
Notifications
If the recipient's phone shows message previews, the text can appear on a locked screen, a smartwatch or a notification history log. Anyone glancing at the phone sees it, whatever the chat timer says.
Backups
Cloud backups capture the chat at the moment the backup runs. If the message was still there at 2 a.m. when the phone backed up, a copy may live in that backup after the chat deletes it.
Linked devices
Many apps sync to a laptop or tablet. A desktop session left open at the office is one more place the message is displayed and possibly cached.
Screenshots and forwards
A recipient can screenshot or forward the message before it vanishes. Some apps notify you or block screenshots for certain message types, but none can stop someone photographing the screen with another phone. Our post on designing secret-sharing workflows that survive screenshots and human error covers how to plan around this.
A one-time link sidesteps the first three. The secret never enters the chat thread, so notification previews, chat backups and synced desktops only ever see a URL. After the note is opened or expires, that URL leads nowhere.
How to send a self-destructing message with a one-time link
Say you are a landlord texting a tenant the code for a key lockbox, or a developer sending an API key to a new hire. Here is the safe way to do it with SecureNotes. It is free and needs no account.
- Open SecureNotes and paste your text. Go to the homepage and create a self-destructing note. Paste the message, up to 10,000 characters. Text only, no attachments.
- Choose when it self-destructs. Pick a view limit (1, 3, 5 or 10 views), a time limit (1 hour, 24 hours, 7 days or 30 days), or both, in which case whichever comes first wins. For a password or code, one view is usually right.
- Add a passcode if the content is sensitive. The recipient will need to enter it before the note opens. This protects you if the link lands in the wrong inbox or gets forwarded.
- Turn on the read notification (optional). SecureNotes can email you when the note is opened, so you know the recipient got it.
- Send the link. Paste it into a text, chat or email, or have SecureNotes email it to the recipient for you.
- Send the passcode another way. If the link went by email, read the passcode out on a call or send it by text. Never put both in the same message.
- Confirm it was received. Once the recipient has what they need, the note is gone. If they say the link was already dead when they tried it, treat the secret as exposed and change it.
Each note is encrypted with AES-256 using its own random key before it is stored, and once the view or time limit is reached the link stops working. For more on choosing and sharing passcodes, read when to use passcode-protected notes and how to send the passcode safely.
Which self-destruct setting should you pick?
Match the setting to how quickly the recipient will act and how bad it would be if someone else read it.
- 1 view, 1 hour: a password you are sending while the person is on the phone with you.
- 1 view, 24 hours: a door code or Wi-Fi password for someone arriving tomorrow.
- 3 views, 7 days: instructions a small group needs to read once each, like a shared alarm code for three cleaners.
- Time limit only: rarely the best choice for secrets, because the note stays readable until it expires.
A view limit means the message deletes after reading. A time limit means it deletes on a schedule, read or not. Combining them gives you a backstop. The trade-offs are covered in more depth in self-destruct vs time-based expiration.
What can still go wrong with a message that deletes after reading?
A self destruct message link removes a lot of risk, but not all of it. These are the mistakes people actually make.
Sending the passcode with the link
Putting "link: ... passcode: 4471" in one email means anyone who reads that email has both. Split them across channels.
Choosing generous limits
Ten views and 30 days is convenient, but it leaves the note readable for a month. Use the tightest settings the recipient can work with.
Leaving your own copy behind
The note self-destructs, but the text you typed might still be in your clipboard, a draft email or a notes app. Clear it.
Forgetting the recipient can save it
Nothing technical stops a screenshot or a paste into a document. If you are sending a password, ask the recipient to store it in a password manager and plan to rotate it if the access is temporary.
Sending to the wrong person
Check the address or contact before you hit send. A passcode is your safety net here, which is one more reason to use it for anything sensitive.
Ignoring a dead link
If the recipient reports the note was already gone, do not just send a new one. Someone else may have opened it. Change the secret first.
When a self-destructing note is the wrong tool
One-time links are built for handing something over once. They are not the answer to every privacy problem.
- Ongoing shared passwords: if a team needs the same login every week, use a password manager with shared vaults.
- Payments and card numbers: send a payment link from your payment provider instead of typing card details anywhere.
- Files and documents: SecureNotes is text only. Use a file-sharing tool with access controls and expiry.
- A real conversation: if you need back-and-forth on something sensitive, a phone call or an end-to-end encrypted chat with disappearing messages may suit you better.
- Something that must never be seen by any third party: any hosted service means trusting that service. Weigh that honestly before you send.
If you send secrets from scripts or internal tools, the free SecureNotes REST API lets you generate one-time links automatically instead of pasting keys into tickets.
What to do if you already sent it the normal way
If a password or code is already sitting in a chat or email, deleting the message is a start, not a fix.
- Delete it for everyone, if the app allows that.
- Change the secret. Assume backups, notifications or synced devices have a copy.
- Send the new one as a one-time link so the same thing does not happen twice.
Next time, send a secure note from the start and the chat history will only ever hold a link that no longer works. OWASP's Secrets Management Cheat Sheet is a useful reference if you handle credentials regularly.
Frequently asked questions
Can the recipient screenshot a self-destructing message?
Yes. No app or link can fully stop someone from taking a screenshot or photographing their screen with another phone. Self-destructing messages prevent copies from piling up by accident, not deliberate saving. If you are sending a password or access code, plan to change it once it has served its purpose, especially when the access is temporary.
Will I know when my self-destructing note has been read?
With SecureNotes, you can turn on an optional email notification when you create the note. You will get an email when the note is opened, which confirms delivery. If the recipient later says the link was already dead and you got a notification they did not trigger, assume someone else read it and change the secret.
Can I send a self-destructing message by text message?
Standard SMS has no built-in self-destruct feature, so anything you text stays on both phones until someone deletes it. The workaround is to create a self-destructing note, then text the link instead of the secret itself. The text thread keeps only the URL, which stops working after the note is viewed or expires.
What happens if the link expires before the recipient opens it?
The link stops working and the note cannot be recovered. Just create a new note and send a fresh link. If you are certain nobody opened the original, there is no need to change the secret. If you are unsure, for example because the link may have been forwarded, changing it is the safer choice.
Do I need an account to send a self destruct message link?
Not with SecureNotes. It is free and needs no sign-up. You paste your text, choose the view or time limit, optionally add a passcode, and get a link to share. That makes it practical for one-off situations, like sending a guest a Wi-Fi password or a contractor a temporary login.
Can I create self-destructing notes automatically from a script?
Yes. SecureNotes offers a free public REST API for creating notes from scripts and internal tools. Developers use it to generate one-time links for things like new-hire credentials or temporary API keys, so secrets never get pasted into tickets, shared docs or chat channels. The API documentation is on the SecureNotes website.