[-] eld.

Here. For a while.

Between open tabs

Here. For a while.

An encrypted message, passed directly between browsers.

Plain text · up to 32 KiB
Up to 5 files · 1 GB each
◌

A room held by its people.

Everyone can write. Messages pass directly between peers and stay only in open browsers.

A name is generated for the group. Share its secret link to invite someone. The room ends when its last participant leaves.

Up to 16 participants · Available history travels with peers
How long should it stay?

In the first mode, closing, reloading, or going offline can end the message.

Once created, the message cannot be edited.

Held between us

Your message is here.

Keep this tab connected to hold the message.

1holding open
While the creator's original tab is herePlain text · read only
Signed by

Receiving shares verified pieces while you are here. Up to 5 GB of encrypted cache per room, removed when you leave.

Anyone with the full link can read while the message is available.

[-]

Nothing held here

This message is unavailable.

It may have ended, or no connected tab can pass it on.

Write a new message ↗
Encrypted in your browser.

Between devices

Share to another device

Choose how to connect. You will approve the other device before sharing.

On the receiving device, open Held and choose Receive.

Open Held, choose Receive, and type this code.

  1. On the other device, open the message or room you want to share.
  2. Tap Share, then Scan QR code.
  3. Point its camera at this screen.

On the receiving device, choose Receive → Show QR code.

Do both screens show these same numbers?

Compare the numbers, then approve on the device sharing with you.

Keep the sharing device connected while receiving. Files you save on this device remain after you leave Held.

This session

Room details

This room, right now

Participants

You and the other participants holding this room. An identity appears once your secure peer connection is ready.

    A reconnecting participant is still in the room. Departure notices appear in the chat when someone leaves; they stay in your current tab.

    Across Held

    A little activity.

    —Message links created
    —Groups created
    —Active peers

    Loading aggregate activity…

    Created links, not message deliveries.

    A new simple-message link counts once. Opening or forwarding it adds no new message. Individual posts inside peer chats are not counted.

    Connections, not unique people.

    Active peers estimates admitted connections holding messages or groups. One person in two different rooms counts twice. Updates can lag briefly.

    Totals from existing room activity.

    These counts use creation and connection information the registry already handles. They add no tracking cookies or browser identity reporting. Historical activity before counting began is not included.

    Signature verified

    This message’s sender.

    This generated identity signed the message and was authorized by its original creator. It stays with the message as other browsers carry it.

    To recognize this sender later, keep the full sender ID and message ID. Use Identity → Prove a past identity with a fresh challenge. A signature proves control of a key; it does not identify a person.

    No account. No chosen username.

    Your signing identity.

    Each message or group gets a different generated identity. A recovery backup lets another device prove it holds the same key.

    Make this identity portable

    Save an encrypted backup and its separate recovery code. Anyone with both can act as these identities. Neither is sent to Held.

    Download encrypted backup
    Restore on this device

    Restoring replaces this browser's identity for future joins. Active sessions keep their current keys. There is no account recovery if your backup is lost.

    Prove a past identity

    Use the original message or room ID, a fresh challenge from the verifier, and the full public identity they already trust. A signature proves control of a key.

    Sharing a cross-room proof lets people connect this identity with other rooms where you explicitly share it. Other rooms remain separate.

    A little context

    What privacy means here.

    Your message is encrypted in your browser and passed directly between connected browsers. The registry coordinates connections and availability; it does not receive the message or its decryption key.

    The full link is the key.

    Anyone with the complete link can read while a holder is reachable. Share it with care. The key stays in the link fragment, outside the network request for the page.

    Open tabs keep it available.

    By default, the creator's original tab must stay connected. Closing it, reloading, or going offline can end the message. The carried-message mode lasts while at least one connected holder remains. The creator can end either message mode from the original session. Groups have no creator-only End control: the final participant leaving ends the room.

    One tab per browser profile.

    Only one tab in this browser profile can hold a room. A random signing seed saved locally produces a different identity for each room, without device details. Simple messages carry a verified sender ID inside their encrypted package. Group aliases and signatures also travel only between peers. Sharing a cross-room proof is optional. Other browsers and private windows are separate unless you restore an encrypted identity backup. Clearing site storage loses the identity without a backup; restoring never recovers old messages or creator control.

    Peers carry the available history.

    New group participants receive messages still held by connected peers: up to 200 messages and 512 KiB of text. History stays in memory and is cleared when a tab leaves or loses its required connection. There is no server archive. Attachments transfer directly between peers. Files are received on request in messages and groups. Participants share verified pieces while connected; every piece must remain held somewhere for a complete download. Received pieces use independent encrypted temporary storage for each room, capped at 5 GB per room subject to available browser storage. They are removed when you leave, cancel, or lose your session. Cache keys stay only in memory. After a browser crash, leftover encrypted files are removed on your next visit. Saved downloads remain yours.

    Public activity shows totals.

    The registry counts newly created message links and groups, and estimates active peer connections. Public stats contain no room IDs, names, message contents, IP addresses, or signing identities. One person can count as multiple peers.

    Ending cannot erase a saved copy.

    Ending asks cooperating tabs to clear the message. Recipients can still copy, save, photograph, or modify their client to keep it.

    This does not make you anonymous.

    Connection services and other browsers may see your IP address. Browser code can access the decrypted message, so privacy also depends on trusting the code delivered by this site and your device.