Sample link: <a href="https://secretink.co/read/2atelv15n5hqip59416c7c3c0q" rel="nofollow">https://secretink.co/read/2atelv15n5hqip59416c7c3c0q</a><p>Why does it send the decryption key to the server (presuming the data is even actually encrypted server-side)? Just use the megaupload model, where you link to an address containing a #, and then client-side javascript to decrypt.<p>Is it perfectly secure? Of course not, but at least then this company itself can't read them. Now there's nothing NSA-resistent about it. Just NSL secretink.