One developer. No middlemen.
BurnPony is built and maintained by NorseHorse, a solo indie developer — the same hands behind PGPony, ScrubPony, CarrierPony, AgePony, QuorumPony, and RelayPony.
Why BurnPony exists
Everyone eventually needs to send something that shouldn't live forever: a password, a door code, a number that belongs to exactly one moment. The usual channels keep everything — chat logs, mail archives, backups of backups. BurnPony is the opposite bet: a note that is encrypted before it leaves your phone, readable a fixed number of times, and then gone, with a server in the middle that never could read it in the first place.
Trust you can check today
The pitch isn't "trust me." The page a recipient opens is a single self-contained file — no frameworks, no analytics, no external requests, a strict Content-Security-Policy — so View Source shows everything it does with the key in your link. The cryptography is deliberately boring: AES-256-GCM, HKDF-SHA256, and PBKDF2, the standard primitives used the standard way, and the app and the browser viewer are verified against each other with independently generated test vectors. New app, old bones. That's on purpose.
The rules of the family
Every app in the Pony family follows the same rules:
- No accounts. The tools work the moment you open them — and with BurnPony, recipients don't even need the tool.
- No tracking. No analytics, no telemetry, no ad IDs, on the apps or the websites.
- Inspectable crypto. The important parts are open to inspection — BurnPony's viewer is readable on every note link today, and the crypto core and relay server are headed for public release.
Get in touch
Questions, bug reports, ideas: NorseHorse@norsehor.se. Prefer to write encrypted? Grab the PGP key. One developer reads everything.
Curious about the rest of the family? See all seven apps on one page.