VorstufeNothing here is real. Data and mail stay inside.

Help & questions

Messages

What does “Beta” mean?

Hooray! We are proud and delighted to show tunnl. to the world as a public beta.

That means: everything described here is yours to use – messages, files, account, options. It also means we are still polishing. Things may change, a corner may still be rough, or we may only notice a bug because you ran into it.

What does not change: your messages are encrypted in your browser and we cannot read them. That is the core, not a promise for later.

Something you dislike, something missing, something broken? Send us an Echo – encrypted, direct, and we read every one.

How does tunnl. work?

You write your message and your browser encrypts it before it leaves your device. You get a link. The key is in the part after the # – browsers never send that part to the server.

The recipient opens the link and their browser decrypts the message. The first message can be opened only once, then its content is deleted. After that you can keep writing confidentially in the same conversation.

More: How tunnl. works →

What is the optional password for?

The password is a second lock: the link alone is useless without it. It is also only used in the browser and never sent to us.

After 10 wrong attempts the conversation is deleted. We cannot recover forgotten passwords.

What does “Must be picked up within” mean?

This is how long the first message waits to be opened – between 1 minute and 3 days. If it isn't opened in time, it is deleted.

Once opened, the conversation stays for 30 days after the last activity.

or – what's the difference?
  • stays readable: the reply stays visible to both of you until the conversation expires or is deleted.
  • read once: the reply can be shown once, then its content is deleted on the server. Attached files are deleted after the first download.
Can I change a message afterwards?

Yes, as long as it is unread. Tap the pencil on your message, change the text, add or remove images and files, and save. Your browser encrypts the new version, the old one is overwritten on the server.

The message then shows “edited” to both of you. Once the other person has opened it, the pencil disappears.

Why can't I reply yet?

Replies are possible once the recipient has opened the first message. That way nobody can fill a conversation before it has even arrived.

“The link is incomplete” – what now?

The part after the # is missing – that's where the key is. Some apps or mail programs cut links off. Ask the sender to send the complete link again, for example via a different messenger.

When is what deleted?
  • First message: right after it is opened, or if it isn't picked up in time.
  • replies: after being shown once.
  • Whole conversation: 30 days after the last activity, after 10 wrong passwords, or when someone clicks “Delete conversation”.
  • For 7 more days tunnl. only shows that the conversation existed – without any content.
Replying to a particular message

Hover over a message and press the curved arrow at its top right. A strip then appears above the writing box with the author and the first line – that is what your reply refers to. The cross removes it again.

To quote a particular passage, just select it. A small Quote button appears, and the wording then sits in your reply. Clicking the quote jumps back to the message it came from.

You cannot quote from a message, and you cannot reply to one that has burned. Otherwise the passage would outlive the burning – which is exactly what it must not do.

The reference and the quote are part of your encrypted message. Our server does not even learn which reply belongs to which message.

Sending out the accesses of a group

Every participant gets their own access – that is the only way “once” can mean that each person sees the message exactly once. Anyone in your address book gets it delivered sealed and needs no link at all.

For everyone else the links are on the page, and wherever you entered an address there is a Send the invitation button beside it. You write the subject and covering text once for everyone; Invite everyone sends them one after another, and each row reports for itself how it went.

What that costs: the e-mail carries the access link – and with it the key. While sending, it passes through our server; we do not store it, but we do see it at that moment. If you would rather we did not, copy the link and send it yourself – then it never passes us at all. And with a password the e-mail alone is useless to anyone, including us.

What is a notice board?

A notice board is the counterpart to the group message: one link, any number of readers, and only whoever created it can write. Whoever opens the link reads along – with no account, no name, and without a record anywhere that they were there.

There is a QR code and a printable sheet to go with it. Put it on a door, show it on a screen, drop the link into a chat. For a club notice, site information, a meeting point.

What a notice board cannot do: it does not tell you who read it – that is deliberate, not a missing feature. And whoever has the link can pass it on; you cannot exclude anyone afterwards. If something should only reach particular people, use the group message: there everyone gets their own access.

The content is encrypted like everything at tunnl.: the key sits in the link behind the # and never reaches our server. We cannot see a notice board either.

Newest message at the top

By default a conversation runs like an exchange of letters: it starts at the top, the newest sits at the bottom, and the writing box below that.

If you prefer it the other way round, switch it in Settings under Display. The newest message then sits at the top with the writing box just above it – so you do not have to scroll back down to reply.

The choice stays in this browser and only changes how things look here. Nothing changes about the messages themselves, and nothing changes for the other side.

Account

Do conversations from before signing in move to my account?

Yes. Conversations you created or opened without an account in the same browser tab are added automatically as soon as you sign in or create an account. The easiest way is the button “Sign in to keep this conversation in your account”.

If you have closed the tab since, open the conversation again via its link and save it to your account there.

How do I find out about new messages?

While tunnl. is open in a tab and you are signed in, tunnl. checks every 30 seconds (every 2 minutes in the background). New messages appear as an orange dot on the “Account” button and as a number in the tab title, and the account list updates itself.

In Settings under “New message alerts” you can also turn on:

  • E-mail: arrives even when tunnl. is closed – without content, at most one per hour and with some delay (up to about 20 minutes).
  • Browser alerts: your computer shows an alert while tunnl. is open in a tab – even in the background, without content or names.
  • Expiry alert: if nobody has opened one of your messages by half the pickup deadline, you get one e-mail. That way you notice a message stuck in spam before it expires.
Do I need an account?

No. Sending and replying works without an account. You need one for:

Your conversation list is encrypted with a key only you have.

How do I sign in? The code doesn't arrive.

There is no password: you enter your e-mail address and get a 6-digit code. It is valid for 15 minutes.

  • No code? Check your spam folder; the sender is no-reply@tunnl.ch.
  • You can request at most 3 codes per 15 minutes. After 5 wrong entries you need a new code.
  • A passkey is faster.
What does “Remember device for 30 days” do?

When ticked you stay signed in for 30 days and your key stays stored in this browser. Without it, sign-in ends after 12 hours and the key is forgotten when you close the browser – next time you'll need your recovery code.

Only tick it on your own devices.

What is the recovery code?

Your saved conversations are encrypted with a key that only lives in your browser. The recovery code brings that key to a new device or browser.

  • Store it in a password manager or print it. Don't e-mail it to yourself.
  • We don't have it and can't recover it – that's the price of us not being able to read anything.
  • Even with a passkey you need it once on every new device.
I lost my recovery code.

On a device where you are still signed in, everything keeps working. On a new device choose “Lost your code? Start over”: you get a new key and code.

Your previous list is removed because it can't be read without the old key. The conversations themselves remain and can still be reached via their links.

Which name does the other person see?

You can set a name in Settings. If you leave it empty you get a random fantasy name like “Swift Otter”. The other person sees the name once you save the conversation to your account.

Your e-mail address is never shown.

One exception: anything sent through the invoice run or the single send shows your company instead of your name – there that is exactly the point.

Your mailbox: tunnl.ch/to/yourname

An address you can put in your mail signature. Whoever opens it writes you something confidential – no account, no sign-in, and without the two of you ever having exchanged a key. The message lands in your list, with a little mailbox mark in front of it.

Why this works with no preparation: your account has two keys. Everyone may see the public one – it can only lock. The private one stays in your browser and never goes anywhere. Your visitor rolls a key for their message, locks the text with it, and puts that key into a box that your public key snaps shut. Only you can open it.

Setting it up: in Settings under “Your mailbox”, choose a handle – three to thirty characters, letters, digits and dashes. A few words are reserved for tunnl. itself.

For your signature – one of these:

  • Plain: Something confidential? Please send it encrypted: tunnl.ch/to/yourname
  • Shorter: For anything confidential: tunnl.ch/to/yourname — encrypted, no account.
  • With the image: Send it to me through the tunnel: tunnl.ch/to/yourname

The third is the nicest and the riskiest – it assumes people already know the name. I would never drop the “no account”: that is the reason someone clicks instead of backing away.

The other person keeps their own link and reads your reply through it. After that you carry on as in any other conversation. The message stays for thirty days so the reply has time.

What you should know: you cannot pre-sort what comes in – an open mailbox also takes what you would rather not read. It accepts 40 messages a day, 5 from the same corner of the net. You can close it at any time; the handle becomes free again, and anyone who still has it in an old signature of yours lands nowhere.

In German, tunnl.ch/an/yourname points at the same page.

How do I reach the tunnl. team?

With an echo: you write to us directly through tunnl. – encrypted like any other message. Our reply appears in your account in the conversation “Echo to tunnl.”.

Echoes need an account so the reply reaches you safely. You can send 5 echoes per day.

How do I delete my account?

At the very bottom of Settings under “Delete account”. This deletes your account, your e-mail address, your list, your passkeys and your attachments. The conversations themselves expire normally.

Passkeys

What is a passkey?

A passkey replaces the e-mail code: you sign in with your fingerprint (Touch ID), face (Face ID) or your device PIN. Nothing to type and nothing anyone could intercept.

A passkey only replaces signing in. For a new device to read your conversations it also needs the account key – easiest via pairing a device.

How do I add my phone?

The quickest way is the QR code – nothing to type:

  1. On the device you are signed in on, open Settings and press Pair device under Another device.
  2. Point your phone's camera at the code and tap the notification.
  3. That is it. The phone is signed in and can read your conversations.

The code is valid for two minutes and can be redeemed exactly once. After that it is worthless – even to someone who photographed it.

Your account key travels encrypted. The key that opens it sits inside the QR code itself and never reaches our server. So we could not open the package even if we wanted to.

The key belongs to a browser, not to the device. So scan with the browser you intend to use afterwards – many browsers have their own QR reader for this. If you want tunnl. as an app on your home screen, put it there first, open it and pair from inside: on iOS a home-screen app has its own storage and inherits nothing from the browser.

Without a camera the recovery code still works. And to get rid of a device again: sign out on all devices in Settings.

How do I set up a passkey?
  1. Sign in once with an e-mail code.
  2. In Settings under Passkeys, optionally enter a name (e.g. “MacBook”) and click Add passkey.
  3. Confirm with Touch ID, Face ID or PIN.
  4. From now on choose Sign in with passkey on the sign-in page.
My browser only offers “phone/tablet” or “USB security key” – no Touch ID.

Then there is no passkey for tunnl.ch saved on this device yet. Browsers only offer Touch ID or Face ID when they find a matching passkey.

  • Not set up yet? Cancel, sign in with a code and add a passkey.
  • Created in another browser or profile? Depending on settings, Chrome keeps passkeys in the Chrome profile, Safari in iCloud Keychain.
  • Passkeys only work on the address they were created for. Passkeys from an earlier address don't work on tunnl.ch.
Does my passkey work on several devices?

If your passkey storage syncs (iCloud Keychain, Google Password Manager, 1Password …), yes. Otherwise add a separate passkey on each device. Remove passkeys you no longer need in Settings.

Options

What do the “seelisbrg” and “gotthrd” options do?

Options extend how long tunnl. keeps something open. They apply to your account and can currently only be unlocked with a activation code (enter it in Settings under “Options”).

  • Standard: pick-up period from 1 minute to 3 days. The first message can be opened once.
  • seelisbrg: adds 7 days and 9.25 days – the length of the Seelisberg tunnel.
  • gotthrd: adds 7 days, 16.942 days – the length of the Gotthard road tunnel – plus 1, 2, 3, 6 and 12 months.
  • With either option you can tick “Readable more than once” when writing: the first message stays readable until it expires instead of deleting itself on first opening. Attachments stay available just as long.

Made for documents that should not vanish after the first look – invoices, contracts, project credentials. Confidentiality is unchanged: encryption still happens only in the browser.

Why “seelisbrg” and “gotthrd”?

The options are named after the two longest road tunnels in Switzerland – and their length in kilometres is also the longest pick-up period in days. They are spelled like tunnl. itself: lower case and without the last vowel.

Gotthard-Strassentunnel · 16.942 km 16.942 days pick-up period Seelisbergtunnel · 9.25 km 9.25 days pick-up period
Name and measure: the length in kilometres is also the longest pick-up period in days.
  • Gotthard road tunnel: 16.942 km, opened in 1980, the longest road tunnel in Switzerland and the Alps.
  • Seelisberg tunnel: 9.25 km, also opened in 1980, part of the A2 between Beckenried and Seedorf – Switzerland’s second-longest road tunnel.

Our own drawing rather than a photo: no third-party image rights needed – and it matches the orange dot at the end of the tunnl.

What is “your sender identity”?

With the gotthrd option tunnl. can send the notification e-mail for you – with your logo, your company name and your reply address. You set this up once in Settings.

  • Sender: technically it stays tunnl.ch, visibly it reads “Your company via tunnl.”. That is needed so the mails don't end up in spam. If you want your own domain in the sender, you can have it – see sending from your own domain.
  • Reply: if someone replies to the e-mail, it reaches your address.
  • Logo: it travels inside the e-mail, so nothing is fetched from a server. Opening the mail reveals nothing.

In the invoice run, Preview shows you the finished e-mail with its envelope – from, reply-to, subject – before you send anything.

Company name, reply address and logo are stored in the clear – they belong in the e-mail and are visible there anyway. Text blocks and address book stay encrypted.

Sending from your own domain

With the gotthrd option your mail can go out from your own domain instead of ours: no-reply@your-company.com rather than no-reply@tunnl.ch. For that you add three records at your DNS provider – wherever your domain is managed.

  • DKIM – the signature. We generate a key pair; the public half goes into the record, the private half stays with us. Being able to set that record is at the same time your proof that the domain is yours – a separate confirmation code would be the same proof a second time.
  • SPF – permission to send in your name. Careful: a domain may have exactly one SPF record. With two in place neither counts, and nothing warns you. That is why we do not say “add this”, but show your existing line with our part spliced into the right place. Replace the old one, never add a second.
  • DMARC – optional but recommended: it tells you when somebody writes in your name. Start with p=none and watch for two weeks.

Settings show the finished line for each record; one click copies it. Then press Check now – it usually takes minutes, with some providers a few hours, until the records are visible everywhere.

Nothing switches over before it has been checked. While a record is missing, mail keeps going out through us. That is deliberate: mail under your name without the records would land in spam, or nowhere. If a record disappears later – when moving to another provider, say – sending falls back to tunnl.ch quietly and you get an e-mail about it.

None of this touches the content: it stays encrypted behind the #. What gets signed is the notification mail, not the message.

Several colleagues sending from one domain

One person enters the domain – it is theirs. In settings, below it, sits Who else may send: that is where they add colleagues, and each of them then sends under their own name before the @ – anna@your-company.com instead of no-reply@your-company.com.

Two conditions, both deliberate: the address must be on that domain, and there must already be an account for it. The first stops anyone from trying out foreign addresses to learn who has an account with us – on their own domain they know that anyway. The second is there because we do not create accounts for people unasked.

What is shared is the identity, not the mail. Key, selector and checks belong to the domain; every conversation still belongs to the account it sits in. Whoever entered the domain sees nothing of the others' mail – there is no function for it, not even for us.

To be honest: as long as the domain belongs to a person, it hangs on that person. If they give up the domain or delete their account, sending falls back to tunnl.ch quietly for everyone else. If that is not what you want, set up a company and hand it the domain – then every administrator manages it, and it outlives any single account.

Your company: several people, one identity

In settings you set up a company and add colleagues. There are two roles: administrator manages – add, remove, set roles – and member sees who is in. You can add anyone who already has a tunnl. account, and an account belongs to at most one company.

The company administers, it does not read – day to day. Your conversations sit under your account key, and that key is in your browser. Being an administrator does not show you a single letter.

Two exceptions, important enough to spell out here: when someone leaves the company, and when a stand-in has been declared. For those two cases, everything sent under the company identity – through the company domain or with the company brand – is also encrypted for the company as it is sent. An administrator can then open it. Not secretly: every opening is logged, and the person concerned is told.

The reason is uncomfortably concrete. A trustee whose employee resigns otherwise cannot reach the client mail any more – and we cannot hand it over, because we never had it. This cannot be repaired afterwards: what was not encrypted for the company when it was sent never reaches it. So it happens at sending time or not at all.

How a stand-in comes about: you can declare one for yourself before going on holiday – you know about it anyway. Or an administrator declares one for you when you drop out at short notice; then you get an e-mail before anything is opened. A stand-in is always time-limited, at most half a year, and either side can end it early.

What you see afterwards: your settings show Who opened your mail – with date, name and count. That list is never deleted and never overwritten, and it stays yours even after you leave the company. On top of that you get an e-mail on every access. An access nobody notices would be something other than what is written here.

What explicitly does not exist: a reason called “because I am an administrator”. Without someone having left and without a running stand-in our server does not hand out the seals – and without seals the company key is of no use either.

What stays private: everything you send without the company domain and without the company brand. The company cannot reach it, not later, not with our help. The same goes for your text blocks, templates and address book.

And the key is not with us. The company has its own key pair; the half that unlocks sits with its administrators – each holding a copy under their own account key. That route does not go through us either: a new administrator gets it from one who already has it. That is why two administrators are mandatory. If the only one loses their access, the company key is gone – and with it the mail the company was counting on.

Two administrators are mandatory, and the last one can neither remove nor demote themselves. The reason is uncomfortably concrete: if the only administrator loses their access, nobody could reach the administration any more – and we cannot hand it back, because we never had it.

When someone leaves, their account stays, with everything in it. What ends is the membership – with a date, so it stays clear who was in when.

The domain can belong to it. Settings show Hand over to your company below your domain. After that every administrator manages it, and it outlives any single account – if whoever entered it gives up their account, everyone else keeps sending undisturbed. Handing it over changes nothing about sending: no new key, no DNS record to touch, no interrupted mail. And it goes back – any administrator can take the domain onto their own account again.

The identity can belong to it too. Under Your sender identity there is Hand over to your company. After that everyone sends under the same company name, reply address and logo, and every administrator can change it. A member sees the name they send under but cannot change it. This goes back as well.

What does not come along: your text blocks, templates and address book. They sit encrypted under your account key, and we do not have it – so the company does not get them, even if it wanted to. The same boundary covers your conversations: the company cannot reach its people's mail. That is not a setting, it is the construction.

What is a “message by email”?

A single message with your sender identity – for quotes, workshop results or whatever else comes up. You find it behind the arrow on the red New message button – it is on every page, and it lists Message by email, Invoices by email and below them your own templates.

  • Title: used as the subject of the e-mail and shown at the top of the message.
  • Text for the e-mail: the covering text your recipient reads in their inbox. It is unencrypted – so keep confidential things out of it. “Remember the e-mail text” brings it back next time.
  • Text for the message: the confidential part, encrypted in your browser.
  • Attachments: as everywhere else, up to 5 files – encrypted, file names included.

Recipient and password come from the same encrypted address book as the invoice run. The preview shows you beforehand how the e-mail arrives.

Your brand: anything sent this way carries your sender identity into the conversation as well: the name shown there is your company instead of your display name. It comes from the sender profile and is held by us in the clear anyway; it becomes visible only to whoever holds the link. Your logo stays in the e-mail.

Templates: once a message looks the way you need it again and again, hit Save as template and give it a name – “Quote”, “Workshop results”. Title, both texts, the recipients and the period are stored, encrypted in your account. The template then appears behind the arrow on the red button.

Several recipients: separate the addresses with commas – they all get the same e-mail with the same link, controlling and accounts payable for instance. So the first person does not burn the message for everyone else, it then stays readable more than once automatically. The invoice run works the same way.

Address book: tick “Remember recipients as”, give it a name – “Meier AG”, “Controlling & AP” – and next time you type the name into the recipient field and get all the addresses back. Remove one and remember again, and it is gone. The address book covers both ways and is stored encrypted in your account.

Can a colleague take over my conversation?

Yes. At the bottom of every conversation there is Cover for me: share access. Behind it is the link that opens this conversation – the same one you use. Give it to the person covering for you; they see everything, can reply and carry on, and can keep the conversation in their own account.

To be honest: it is your access, not a smaller one. Whoever has it can edit and delete too. And it cannot be taken back – whoever has the link keeps it until the conversation expires or you delete it. So share it only with people you trust with this conversation, and preferably by a different route than the one it arrived on.

If the conversation has a password, the link alone is useless – send the password separately.

There is deliberately no shared account for several people: the account key lives only in your browser, and a shared key could never be collected back in.

Can I show that something was delivered?

Every conversation has Delivery record at the bottom. It states the conversation reference, the start, the first pickup, the expiry, and per message: from whom, sent when, picked up when, which attachments, and a checksum of the stored ciphertext. You can print it or save it as a PDF.

The record is put together in your browser from what is there anyway – nothing extra is stored for it and nothing is sent to us. Both sides see the same reference so two records match up.

To be honest: it shows that the link was used to pick up – not who picked up. It is not a legally recognised proof of delivery; that needs an officially recognised delivery platform. For everyday use (“I can show when it was picked up”) it does the job.

How do I send several invoices at once?

In the invoice run you drop several files. tunnl. reads what it can from each file name – following a pattern you set once, such as {nr}_{kunde}_{periode}.

You get a check list: one row per invoice with number, period, customer, recipient, subject and password. Everything is editable and rows can be removed. Nothing happens until you send – each invoice becomes its own encrypted message with its own link.

About the password: if tunnl. sends the e-mail, the link with the key passes through our server at that moment; it is not stored. With a password the link alone is useless to anyone – including us. For regular customers you can keep a fixed password in the address book; it is stored encrypted and filled in automatically next time.

Your brand: every invoice sent this way shows your company as the sender in the conversation – see single send.

Timesheet: drop the invoice and the CSV together – tunnl. works out from the file names what belongs together (customer, number, period) and makes one sending out of it. Your customer then sees the invoice, below it the hours as a table, and below that the CSV to download.

Serial sending with a list: nobody types forty addresses for forty payslips. Drop the files and read in a list (CSV) – one row per sending, with the columns file, recipient, customer, subject, password. tunnl. matches them by file name and fills in the rows; whatever does not match is named. The list is read in your browser only and never uploaded. A sample list to fill in is on the page.

As long as an invoice has not been picked up you can still change it from your account.

Images & files

How do attachments work?

Files are encrypted in the browser just like messages, including the file name. Uploading requires an account; anyone with the link can download.

  • up to 25 MB per file, at most 5 files per message
  • 100 MB storage per account – only files not yet burned count
  • every file burns automatically after 1, 3 or 7 days – tunnl. is for sending, not storing
Can tunnl. show a table directly?

Yes. For a CSV file – a timesheet from your CRM, say – there is “Show as table” next to Download. The table unfolds below the file, with a header row, numbers aligned right, dates left – and a total under the last numeric column.

  • Semicolon, comma and tab are detected automatically, as are quotes and accented characters from older exports.
  • Beyond 300 rows we show the first 300 and say how many follow. Downloading still works.
  • The file is read only after decryption, in your browser. The server never sees a single cell.

The invoice run works the other way round: there you drop the timesheet together with the invoice, and it sits below the PDF without a click – as a table, with the file underneath.

An Excel export (.xlsx) is not shown as a table yet – save it as CSV if you want that.

Do I have to upload the same file every time?

No. Tap the paper clip: under Already uploaded you find your files that have not burned yet. Pick one and the same encrypted file is attached instead of being stored a second time. If you pick the same file from your device again, your browser recognises it by itself.

It counts only once towards your storage and appears only once under Storage and attachments – with a note how often it is attached. Each new message uses the period chosen there. If you burn the file there, it disappears from all messages.

What does “burn” mean?

Burning means the file is permanently deleted. Your account lists all attachments with their remaining time. You can burn them right away or shorten the time – extending isn't possible.

Attachments on a message burn after the first download. Uploads that were never sent are deleted after one hour.

“No space left” – what now?

Your 100 MB are used up. Burn files under Storage and attachments that have already been downloaded, or wait until they expire. If tunnl. says storage is full in general, please try again later.

Security & privacy

Can tunnl. read my messages?

No. Encryption and decryption happen only in your and the other person's browsers (AES-256-GCM). The key is in the link after the #, and that part is never sent to the server. An optional password is turned into a key with PBKDF2 (600,000 rounds).

The server only holds encrypted gibberish. Even someone who copies the database can't read anything.

Encryption in detail →

What data does tunnl. store?
  • tunnl. itself stores no IP addresses. To prevent abuse tunnl. counts requests using an anonymous value that changes daily.
  • Encrypted messages and files, expiry times and check values (hashes) of links.
  • With an account: your e-mail address – stored encrypted –, your encrypted list, your display name and public passkey keys.

As with any website, our hosting provider logs technical access data (such as IP address, time and requested page) for operation and security and deletes it according to its retention periods. These logs contain no content, no keys and no indication of which conversation was opened – token and key are in the link after the #, and that part is never sent to the server.

Everything is deleted automatically, see When is what deleted? Details are in the privacy policy.

What doesn't tunnl. protect against?
  • Anyone with the complete link (and the password, if set) can open the message.
  • An infected device, screenshots, or a person passing the content on.
  • Someone knowing that you sent a message – e.g. by seeing the link in your mail history. That's why the content deletes itself.
How do I report abuse?

Did you receive something illegal or harassing through tunnl.? Send us an echo or write to echo@tunnl.ch. With the link to the conversation we can delete it and block the account behind it, if there is one.

Important: anyone with the complete link can read the message. Only share it if you are fine with us being able to see the content – for deleting, the part up to the first dot after the # is enough.

Which browsers work?

All current browsers: Safari, Chrome, Firefox, Edge – on computer and phone. JavaScript must be enabled because encryption runs in the browser.

Can I choose light or dark mode?

Yes, with the round button at the top next to “Account”: automatic (like your system) → light → dark. The choice is only stored in your browser.

Nothing found? Send us an echo · Send a confidential message