OncePad changelog

Material product, security, privacy, and documentation changes

— trust and discoverability

  • Removed Pirsch and all other remotely hosted JavaScript from every page; the CSP now allows scripts only from OncePad itself.
  • Published the disclosure policy, operator page, encryption-format specification, conformance vectors, audit status, and incident-history statement.
  • Added canonical host and trailing-slash redirects, sitemap lastmod dates, explicit OAI-SearchBot rules, IndexNow support, breadcrumbs, and new task-focused guides.
  • Published a service-comparison hub and sourced comparisons with Bitwarden Send, Yopass, and PrivateBin.
  • Standardized the displayed product name as OncePad.

— encrypted file sharing

Added browser-encrypted file handoff up to 25 MB. Filenames and MIME types are sealed inside the encrypted manifest; the storage provider receives ciphertext and transfer metadata, and one successful redemption retires the file capability.

— public launch

Launched the passphrase-only, key-less-link design with AES-256-GCM, a generated 7-word passphrase, one atomic reveal, 24-hour expiry, RAM-only text storage, strict CSP, and SRI-pinned browser code.