A wish or some feedback about tunnl.? We would love to hear your echo.

Write an echo
New message
Settings
Appearance
Language
DEEN
Admin cockpit

What for

What tunnl. is for

For anything exactly one person should see – and that may disappear afterwards.

An e-mail is a postcard that gets copied. It sits in your mailbox, in theirs, in both backups and often in your employer's archive as well. A chat is a folder nobody ever tidies. Convenient every day – and exactly the problem for anything confidential.

tunnl. is the path that closes behind you. Your message is encrypted in your browser before it leaves your device. The other person opens a link, reads – and afterwards the content is gone. Gone here too, because we could never read it.

The three-question test

  1. Would it bother you if this still sat somewhere in five years? In a mailbox, on an old phone, in the backup of a company that no longer exists.
  2. Does it contain a name, an amount or a password? Then it is interesting to someone, even if you can't imagine who.
  3. Does it only need to arrive – not to be filed? Plenty of things need to go from A to B once. That's all.

Two yeses? Then it belongs in a tunnl., not in a mailbox.

What belongs in it

Passwords and access

The Wi-Fi password for the new colleague. The shop login. The code for the holiday flat's key box. The initial password the customer is supposed to change at first sign-in – and that otherwise sits in their mailbox for ten years.

Money and contracts

The quote before it is accepted. The invoice with its hours. The lease, the payslip, the account number for a refund. Whoever sees your invoice mail knows the amount, the due date and the IBAN – and can send a second, fake one.

Lists with people on them

The football club's address list. The class list with phone numbers. The membership list, the sign-ups for the summer party, the minutes of the club meeting. That list isn't yours – it was entrusted to you. Which is why it shouldn't end up in five mailboxes and three group chats.

IDs and official papers

The copy of your ID for the travel agency. The debt-register extract for a flat application. The tax documents for your accountant. The insurance form. Needed once, never again – and yet it stays forever.

Applications and staff matters

The CV, the reference, the rejection, the salary comparison for the board meeting. Everything nobody is supposed to know yet – and where it gets embarrassing or expensive if the wrong person finds it.

Things needed only briefly

The data export for the accountant. Test data for development. The screenshot with real customer data you send to support. The draft nobody should see archived.

And what doesn't belong in it

  • Anything you need to find again. tunnl. deletes – that's the point. What is your archive belongs in an archive.
  • Ongoing collaboration. For the daily back and forth, a project channel is right.
  • Very large files. Currently 25 MB per file, 5 files per message.

Why not just mail or WhatsApp?

Because none of them was built for this. They are good at what they exist for – and they share one weakness: whatever goes in, stays in.

Question tunnl. E-mail WeTransfer Teams WhatsApp Cloud
Can the provider read it? no yes yes yes no yes
Where does it sit afterwards? nowhere all over service channel devices drive
Does it go away by itself? yes never yes policy optional optional
Second lock via password? yes DIY paid no no partly
Does the other side set anything up? no no no yes yes often
Still correctable? yes no resend traced briefly yes

In full, with the reasoning behind every answer: The comparison in detail · as a PDF (EN) · PDF (DE) · What it costs

Tool by tool

E-mail. Nothing to set up and nobody to invite: you usually know the address already, everyone has a mailbox anyway, and the sender is you – which is why we all use it. But every mail is multiplied: whoever ever gets access to either mailbox reads everything in hindsight. The typical case: an initial password from 2021 still works, because nobody knew it was still there.

WeTransfer. The closest of the bunch: a link instead of an attachment, expiry built in, large files. But your file sits there readable, whoever holds the link downloads it as often as they like, and a password costs money. The typical case: the link to the payroll list gets forwarded internally, “to speed things up”.

Teams and Slack. Unbeatable for ongoing teamwork – the history is the point. Which is exactly why it fails for confidential material: it stays, admins can reach it, and no customer installs Teams for an invoice. The typical case: a draft termination letter sits in a channel later opened to the whole project team.

WhatsApp. The encryption in transit is good – better, honestly, than most business tools. The break comes after: the document lands in the photo gallery and in the phone backup, and business post runs over a private number. The typical case: the club's address list sits in a group chat with 40 people – and on 40 phones.

Cloud link. Right for working together, clumsy for handing something over. The provider holds the keys, “anyone with the link” really means anyone, and the link lives until someone tidies up. The typical case: a share link from the last engagement still works two years on – along with the folder next to it.

And now AI tools join in

More and more tools with artificial intelligence help us through the day. We keep handing them our data and giving them access to our computers and mailboxes – because that is what makes them useful.

What such a tool does with old information, long irrelevant to us, we cannot follow from the outside. The attachment from three years ago is forgotten as far as we are concerned; to a machine searching the mailbox it sits right next to yesterday's. And if we let a tool loose on that data that is careless about data protection – or that carries the data out of a secured environment – then all of it travels along, not just what we meant to show.

That is why clearing up is no longer a question of tidiness but one of security. What never piles up in the first place cannot be read out later – by no tool, no service, no machine. That is exactly where tunnl. comes in: confidential things pass through instead of settling.

What tunnl. does differently

We cannot read it

Not “we don't look”, but: we can't. Encryption happens on your side, before anything leaves.

Under the hood: AES-256-GCM in the browser; the key sits in the link behind the #, and browsers never send that part to a server.

It tidies up behind you

The first message opens once, then its content is gone. If nobody picks it up, it expires – without you doing a thing.

Under the hood: Pick-up window from 1 minute to 3 days, much longer with the seelisbrg or gotthrd option; conversations end 30 days after the last activity.

The other side needs no skills

No account, no app, no invitation. Open the link, read, reply. Including for people who “don't do technology”.

Under the hood: Runs in any current browser, on a phone as on a computer. Nothing to install.

A second lock when it matters

Set a password and pass it along another way: link by mail, password by phone. Then the link alone is useless to anyone – us included.

Under the hood: PBKDF2 with 600,000 rounds in the browser; after 10 failed attempts the conversation deletes itself.

Correctable until someone opens it

Wrong figure, wrong PDF? While the message is unread, you change it. No embarrassing second mail.

Under the hood: The new version overwrites the old one on the server – encrypted, naturally.

For companies: it looks like you

With the gotthrd option you send under your own name: company name, logo and reply address in the mail – the customer sees you, not us. Invoices go out as a run, with the hours as a table inside.

Under the hood: Sender profile in your account; templates and address book are stored encrypted with it.

And where tunnl. is not the right tool

Every tool has its purpose. tunnl. has one too, and it does not cover everything. Where something else serves you better:

  • If we send the mail for you, the link passes through our server at that moment. We don't store it – but technically we could read along right then. To rule that out, set a password or send the link yourself.
  • Large files. 25 MB per file, 5 per message. For video material a file service remains the better choice.
  • Archiving and proof. What you must produce in five years does not belong in a tunnel.
  • Signatures with an audit trail. That needs a signing service.
  • Public beta. Everything works, and some things may still change. What does not change is the encryption in your browser.

Common cases, one by one

  • Sending payslips securely A payslip belongs to one person – and after sending usually sits in four mailboxes.
  • Sending confidential documents by email Email is a postcard that gets copied. Confidential things need an envelope.
  • Passing on a password safely The password does not belong in the same mail. And ideally nowhere it stays.
  • An alternative to IncaMail Both send confidential things. They do not solve the same problem.
  • Sending a file encrypted The attachment is too big for the mailbox – and too sensitive for a service that can look inside.
  • Sending patient data and medical reports securely Health data is especially sensitive – legally and in everyday practice.

Write a confidential message Read on: How tunnl. works · Help · Privacy

We cannot read your messages. We do not store IP addresses.

What for?Help & questionsEcho usPrivacyLegal notice

Beta

xoox ag · bluematic ag · cloud services ag