Take the keys. Not the liability.

Every project starts the same way: the client needs to give you the WordPress login, the hosting panel, the API key. It arrives by email, lives in the thread forever, and quietly makes you the custodian of a secret you never wanted to store. There's a better opening move.

The problem with the onboarding email

Credentials exchanged over email don't just expose the client — they expose you. That thread now sits in two inboxes, two providers, and years of backups, and if the client's site is ever breached, "the password was in plaintext in the freelancer's Gmail" is a sentence you don't want in the post-mortem. Deleting your copy doesn't delete theirs.

What BurnPony changes

Honest limits

BurnPony fixes the handoff, not the hygiene around it: it can't rotate the client's password after the project, and it can't stop either side from pasting the secret somewhere durable after reading. Composing notes requires an iPhone — clients receiving them need only a browser, but if they must send secrets back and don't have an iPhone, have them reply by a channel you'll then rotate away from. And as always, what a screen displays can be copied.

A sensible pattern

Get BurnPony

Free self-destructing encrypted notes for iPhone. Recipients need only a browser. No accounts, no tracking.