Take the keys. Not the liability.
Every project starts the same way: the client needs to give you the WordPress login, the hosting panel, the API key. It arrives by email, lives in the thread forever, and quietly makes you the custodian of a secret you never wanted to store. There's a better opening move.
The problem with the onboarding email
Credentials exchanged over email don't just expose the client — they expose you. That thread now sits in two inboxes, two providers, and years of backups, and if the client's site is ever breached, "the password was in plaintext in the freelancer's Gmail" is a sentence you don't want in the post-mortem. Deleting your copy doesn't delete theirs.
What BurnPony changes
- The thread holds a dead link, not a password. You (or the client) put the credential in a BurnPony note; the email contains a link that burned after use. Future readers of the thread — including attackers — find ash.
- Recipients need nothing. Clients are not going to install a security tool for you. A BurnPony link opens in whatever browser they already have; the note decrypts locally on their machine.
- A passphrase splits the risk. Email the link, then text or speak the passphrase. Neither channel alone yields the secret — an easy professionalism upgrade that takes ten extra seconds.
- Receipts settle the 'did you get it?' dance. The disclosed read receipt tells you the moment the client actually opened the credentials, so the kickoff doesn't stall on silence.
- Project's over? Burn what's pending. Anything unread in your Sent tab dies with one tap, and everything else already burned itself on schedule.
Honest limits
BurnPony fixes the handoff, not the hygiene around it: it can't rotate the client's password after the project, and it can't stop either side from pasting the secret somewhere durable after reading. Composing notes requires an iPhone — clients receiving them need only a browser, but if they must send secrets back and don't have an iPhone, have them reply by a channel you'll then rotate away from. And as always, what a screen displays can be copied.
A sensible pattern
- Agree the pattern with the client at kickoff: credentials travel by burn note, never in the thread.
- Send each secret as its own note — 1–3 views, a few days' expiry, receipt on — with the link in email and any passphrase by text or voice.
- Keep the username and context in the normal thread so the note contains nothing but the secret itself.
- At handover, rotate anything long-lived and burn any unread notes from the Sent tab.
Get BurnPony
Free self-destructing encrypted notes for iPhone. Recipients need only a browser. No accounts, no tracking.