BetaWe are looking forward to your Echo!

Help & questions

Messages

What does “Beta” mean?

Hooray! We are proud and delighted to show tunnl. to the world as a public beta.

That means: everything described here is yours to use – messages, files, account, options. It also means we are still polishing. Things may change, a corner may still be rough, or we may only notice a bug because you ran into it.

What does not change: your messages are encrypted in your browser and we cannot read them. That is the core, not a promise for later.

Something you dislike, something missing, something broken? Send us an Echo – encrypted, direct, and we read every one.

How does tunnl. work?

You write your message and your browser encrypts it before it leaves your device. You get a link. The key is in the part after the # – browsers never send that part to the server.

The recipient opens the link and their browser decrypts the message. The first message can be opened only once, then its content is deleted. After that you can keep writing confidentially in the same conversation.

More: How tunnl. works →

What is the optional password for?

The password is a second lock: the link alone is useless without it. It is also only used in the browser and never sent to us.

After 10 wrong attempts the conversation is deleted. We cannot recover forgotten passwords.

What does “Must be picked up within” mean?

This is how long the first message waits to be opened – between 1 minute and 3 days. If it isn't opened in time, it is deleted.

Once opened, the conversation stays for 30 days after the last activity.

♾️ or 🔥 – what's the difference?
  • ♾️ stays readable: the reply stays visible to both of you until the conversation expires or is deleted.
  • 🔥 read once: the reply can be shown once, then its content is deleted on the server. Attached files are deleted after the first download.
Can I change a message afterwards?

Yes, as long as it is unread. Tap the pencil on your message, change the text, add or remove images and files, and save. Your browser encrypts the new version, the old one is overwritten on the server.

The message then shows “edited” to both of you. Once the other person has opened it, the pencil disappears.

Why can't I reply yet?

Replies are possible once the recipient has opened the first message. That way nobody can fill a conversation before it has even arrived.

“The link is incomplete” – what now?

The part after the # is missing – that's where the key is. Some apps or mail programs cut links off. Ask the sender to send the complete link again, for example via a different messenger.

When is what deleted?
  • First message: right after it is opened, or if it isn't picked up in time.
  • 🔥 replies: after being shown once.
  • Whole conversation: 30 days after the last activity, after 10 wrong passwords, or when someone clicks “Delete conversation”.
  • For 7 more days tunnl. only shows that the conversation existed – without any content.

Account

Do conversations from before signing in move to my account?

Yes. Conversations you created or opened without an account in the same browser tab are added automatically as soon as you sign in or create an account. The easiest way is the button “Sign in to keep this conversation in your account”.

If you have closed the tab since, open the conversation again via its link and save it to your account there.

How do I find out about new messages?

While tunnl. is open in a tab and you are signed in, tunnl. checks every 30 seconds (every 2 minutes in the background). New messages appear as a number on the “Account” button and in the tab title, and the account list updates itself.

In your account under “New message alerts” you can also turn on:

  • E-mail: arrives even when tunnl. is closed – without content, at most one per hour and with some delay (up to about 20 minutes).
  • Browser alerts: your computer shows an alert while tunnl. is open in a tab – even in the background, without content or names.
Do I need an account?

No. Sending and replying works without an account. You need one for:

Your conversation list is encrypted with a key only you have.

How do I sign in? The code doesn't arrive.

There is no password: you enter your e-mail address and get a 6-digit code. It is valid for 15 minutes.

  • No code? Check your spam folder; the sender is no-reply@tunnl.ch.
  • You can request at most 3 codes per 15 minutes. After 5 wrong entries you need a new code.
  • A passkey is faster.
What does “Remember device for 30 days” do?

When ticked you stay signed in for 30 days and your key stays stored in this browser. Without it, sign-in ends after 12 hours and the key is forgotten when you close the browser – next time you'll need your recovery code.

Only tick it on your own devices.

What is the recovery code?

Your saved conversations are encrypted with a key that only lives in your browser. The recovery code brings that key to a new device or browser.

  • Store it in a password manager or print it. Don't e-mail it to yourself.
  • We don't have it and can't recover it – that's the price of us not being able to read anything.
  • Even with a passkey you need it once on every new device.
I lost my recovery code.

On a device where you are still signed in, everything keeps working. On a new device choose “Lost your code? Start over”: you get a new key and code.

Your previous list is removed because it can't be read without the old key. The conversations themselves remain and can still be reached via their links.

Which name does the other person see?

You can set a name in your account. If you leave it empty you get a random fantasy name like “Swift Otter”. The other person sees the name once you save the conversation to your account.

Your e-mail address is never shown.

One exception: anything sent through the invoice run or the single send shows your company instead of your name – there that is exactly the point.

How do I reach the tunnl. team?

With an echo: you write to us directly through tunnl. – encrypted like any other message. Our reply appears in your account in the conversation “Echo to tunnl.”.

Echoes need an account so the reply reaches you safely. You can send 5 echoes per day.

How do I delete my account?

At the very bottom of your account under “Delete account”. This deletes your account, your e-mail address, your list, your passkeys and your attachments. The conversations themselves expire normally.

Passkeys

What is a passkey?

A passkey replaces the e-mail code: you sign in with your fingerprint (Touch ID), face (Face ID) or your device PIN. Nothing to type and nothing anyone could intercept.

A passkey only replaces signing in. On a new device you still need your recovery code once.

How do I set up a passkey?
  1. Sign in once with an e-mail code.
  2. In your account under Passkeys, optionally enter a name (e.g. “MacBook”) and click Add passkey.
  3. Confirm with Touch ID, Face ID or PIN.
  4. From now on choose Sign in with passkey on the sign-in page.
My browser only offers “phone/tablet” or “USB security key” – no Touch ID.

Then there is no passkey for tunnl.ch saved on this device yet. Browsers only offer Touch ID or Face ID when they find a matching passkey.

  • Not set up yet? Cancel, sign in with a code and add a passkey.
  • Created in another browser or profile? Depending on settings, Chrome keeps passkeys in the Chrome profile, Safari in iCloud Keychain.
  • Passkeys only work on the address they were created for. Passkeys from an earlier address don't work on tunnl.ch.
Does my passkey work on several devices?

If your passkey storage syncs (iCloud Keychain, Google Password Manager, 1Password …), yes. Otherwise add a separate passkey on each device. Remove passkeys you no longer need in your account.

Options

What do the “seelisbrg” and “gotthrd” options do?

Options extend how long tunnl. keeps something open. They apply to your account and can currently only be unlocked with a gift code (enter it in your account under “Options”).

  • Standard: pick-up period from 1 minute to 3 days. The first message can be opened once.
  • seelisbrg: adds 7 days and 9.25 days – the length of the Seelisberg tunnel.
  • gotthrd: adds 7 days, 16.942 days – the length of the Gotthard road tunnel – plus 1, 2, 3, 6 and 12 months.
  • With either option you can tick “Readable more than once” when writing: the first message stays readable until it expires instead of deleting itself on first opening. Attachments stay available just as long.

Made for documents that should not vanish after the first look – invoices, contracts, project credentials. Confidentiality is unchanged: encryption still happens only in the browser.

Why “seelisbrg” and “gotthrd”?

The options are named after the two longest road tunnels in Switzerland – and their length in kilometres is also the longest pick-up period in days. They are spelled like tunnl. itself: lower case and without the last vowel.

Gotthard-Strassentunnel · 16.942 km 16.942 days pick-up period Seelisbergtunnel · 9.25 km 9.25 days pick-up period
Name and measure: the length in kilometres is also the longest pick-up period in days.
  • Gotthard road tunnel: 16.942 km, opened in 1980, the longest road tunnel in Switzerland and the Alps.
  • Seelisberg tunnel: 9.25 km, also opened in 1980, part of the A2 between Beckenried and Seedorf – Switzerland’s second-longest road tunnel.

Our own drawing rather than a photo: no third-party image rights needed – and it matches the orange dot at the end of the tunnl.

What is “your sender identity”?

With the gotthrd option tunnl. can send the notification e-mail for you – with your logo, your company name and your reply address. You set this up once in your account.

  • Sender: technically it stays tunnl.ch, visibly it reads “Your company via tunnl.”. That is needed so the mails don't end up in spam.
  • Reply: if someone replies to the e-mail, it reaches your address.
  • Logo: it travels inside the e-mail, so nothing is fetched from a server. Opening the mail reveals nothing.

In the invoice run, Preview shows you the finished e-mail with its envelope – from, reply-to, subject – before you send anything.

Company name, reply address and logo are stored in the clear – they belong in the e-mail and are visible there anyway. Text blocks and address book stay encrypted.

What is a “customer message”?

A single message with your sender identity – for quotes, workshop results or whatever else comes up. You find it in your account under the Send button, which lists Invoice, Customer message and below them your own templates.

  • Title: used as the subject of the e-mail and shown at the top of the message.
  • Text for the e-mail: the covering text your recipient reads in their inbox. It is unencrypted – so keep confidential things out of it. “Remember the e-mail text” brings it back next time.
  • Text for the message: the confidential part, encrypted in your browser.
  • Attachments: as everywhere else, up to 5 files – encrypted, file names included.

Recipient and password come from the same encrypted address book as the invoice run. The preview shows you beforehand how the e-mail arrives.

Your brand: anything sent this way carries your sender identity into the conversation as well: the name shown there is your company instead of your display name. It comes from the sender profile and is held by us in the clear anyway; it becomes visible only to whoever holds the link. Your logo stays in the e-mail.

Templates: once a message looks the way you need it again and again, hit Save as template and give it a name – “Quote”, “Workshop results”. Title, both texts, the recipients and the period are stored, encrypted in your account. The template then appears under the Send button.

Several recipients: separate the addresses with commas – they all get the same e-mail with the same link, controlling and accounts payable for instance. So the first person does not burn the message for everyone else, it then stays readable more than once automatically.

How do I send several invoices at once?

In the invoice run you drop several files. tunnl. reads what it can from each file name – following a pattern you set once, such as {nr}_{kunde}_{periode}.

You get a check list: one row per invoice with number, period, customer, recipient, subject and password. Everything is editable and rows can be removed. Nothing happens until you send – each invoice becomes its own encrypted message with its own link.

About the password: if tunnl. sends the e-mail, the link with the key passes through our server at that moment; it is not stored. With a password the link alone is useless to anyone – including us. For regular customers you can keep a fixed password in the address book; it is stored encrypted and filled in automatically next time.

Your brand: every invoice sent this way shows your company as the sender in the conversation – see single send.

Timesheet: drop the invoice and the CSV together – tunnl. works out from the file names what belongs together (customer, number, period) and makes one sending out of it. Your customer then sees the invoice, below it the hours as a table, and below that the CSV to download.

As long as an invoice has not been picked up you can still change it from your account.

Images & files

How do attachments work?

Files are encrypted in the browser just like messages, including the file name. Uploading requires an account; anyone with the link can download.

  • up to 25 MB per file, at most 5 files per message
  • 100 MB storage per account – only files not yet burned count
  • every file burns automatically after 1, 3 or 7 days – tunnl. is for sending, not storing
Can tunnl. show a table directly?

Yes. For a CSV file – a timesheet from your CRM, say – the button reads “Show as table”. The table then appears right in the message, with a header row, numbers aligned right and dates left.

  • Semicolon, comma and tab are detected automatically, as are quotes and accented characters from older exports.
  • Beyond 300 rows we show the first 300 and say how many follow. Downloading still works.
  • The file is read only after decryption, in your browser. The server never sees a single cell.

The invoice run works the other way round: there you drop the timesheet together with the invoice, and it sits below the PDF without a click – as a table, with the file underneath.

An Excel export (.xlsx) is not shown as a table yet – save it as CSV if you want that.

Do I have to upload the same file every time?

No. Tap the paper clip: under Already uploaded you find your files that have not burned yet. Pick one and the same encrypted file is attached instead of being stored a second time. If you pick the same file from your device again, your browser recognises it by itself.

It counts only once towards your storage and appears only once in your account – with a note how often it is attached. Each new message uses the period chosen there. If you burn the file in your account, it disappears from all messages.

What does “burn” mean?

Burning means the file is permanently deleted. Your account lists all attachments with their remaining time. You can burn them right away or shorten the time – extending isn't possible.

Attachments on a 🔥 message burn after the first download. Uploads that were never sent are deleted after one hour.

“No space left” – what now?

Your 100 MB are used up. Burn files in your account that have already been downloaded, or wait until they expire. If tunnl. says storage is full in general, please try again later.

Security & privacy

Can tunnl. read my messages?

No. Encryption and decryption happen only in your and the other person's browsers (AES-256-GCM). The key is in the link after the #, and that part is never sent to the server. An optional password is turned into a key with PBKDF2 (600,000 rounds).

The server only holds encrypted gibberish. Even someone who copies the database can't read anything.

Encryption in detail →

What data does tunnl. store?
  • tunnl. itself stores no IP addresses. To prevent abuse tunnl. counts requests using an anonymous value that changes daily.
  • Encrypted messages and files, expiry times and check values (hashes) of links.
  • With an account: your e-mail address – stored encrypted –, your encrypted list, your display name and public passkey keys.

As with any website, our hosting provider logs technical access data (such as IP address, time and requested page) for operation and security and deletes it according to its retention periods. These logs contain no content, no keys and no indication of which conversation was opened – token and key are in the link after the #, and that part is never sent to the server.

Everything is deleted automatically, see When is what deleted? Details are in the privacy policy.

What doesn't tunnl. protect against?
  • Anyone with the complete link (and the password, if set) can open the message.
  • An infected device, screenshots, or a person passing the content on.
  • Someone knowing that you sent a message – e.g. by seeing the link in your mail history. That's why the content deletes itself.
How do I report abuse?

Did you receive something illegal or harassing through tunnl.? Send us an echo or write to hi@xooxag.com. With the link to the conversation we can delete it and block the account behind it, if there is one.

Important: anyone with the complete link can read the message. Only share it if you are fine with us being able to see the content – for deleting, the part up to the first dot after the # is enough.

Which browsers work?

All current browsers: Safari, Chrome, Firefox, Edge – on computer and phone. JavaScript must be enabled because encryption runs in the browser.

Can I choose light or dark mode?

Yes, with the round button at the top next to “Account”: automatic (like your system) → lightdark. The choice is only stored in your browser.

Nothing found? Send us an echo · Send a confidential message