Documentation
Client SDK
Anonymous encryption

Anonymous encryption

Anonymous encryption lets a visitor who has no Secrecy account send you confidential data. You publish your public key, the visitor encrypts to it in their own browser, and only your logged-in client can decrypt the result. No account, no login and no sender keys are involved on their side.

The ciphertext carries no sender identity. Nothing inside it links the data back to whoever submitted it, which is what makes the collection anonymous — not the removal of fields from the payload.

How anonymous encryption works

The flow has two sides. On the sending side, the visitor calls encryptAnonymous with the bytes to protect and your public key. It is a standalone function exported by the library, and not a method of the client, precisely because the sender has neither an account nor a secrecyClient.
On the receiving side, you call secrecyClient.decryptAnonymous, which reuses the key pair of your current identity to open the ciphertext.

Under the hood this is a sealed box: the library generates a throw-away key pair for the sender, uses it to encrypt to your public key, and discards it. That is why there is no sender identity to trace, and also why the sender cannot decrypt their own message afterwards.

Choosing the right feature

Three features move data between people, and they differ by who the other party is and which way the data flows. Sharing files and folders targets a known Secrecy user, identified by their public key. A transfer sends data out to someone without an account, through a public link. Anonymous encryption is the mirror image of a transfer: it brings data in, from a stranger to you.