INPLAIN.SITE
INTERFACE 2.4 // CRYPTO CONSOLE
MODE ENCODELINK LOCALCLK 10:53:28
REFERENCE

PRIVACY TIPS

INPLAIN.SITE · LOCAL ONLY · NO UPLINK

Privacy Tips for Safe Use

These tips help you stay as private and secure as possible when using inplain.site. They're easy to follow, practical, and written to support users of all technical levels.

1. Use a strong, unique password

Your password is the only thing protecting your encrypted message.

Good passwords:

  • 12–16+ characters
  • Mixed uppercase/lowercase, numbers, and symbols
  • Not reused anywhere else

Avoid anything predictable (names, birthdays, common phrases).

If someone guesses your password, they can decrypt your message even if the image remains hidden perfectly.

2. Use a private way to access the site (optional but powerful)

If your situation requires a higher level of privacy, or if you simply don't want your browsing to be easily traced, consider one of the following:

Use Incognito / Private Browsing

This prevents browsing history from being stored, cached images from being saved, and some types of autocomplete/credential filling. It does not hide your IP address, but it reduces local traces on your device.

Use a VPN

A VPN masks your real IP address, prevents your ISP or local network (school, workplace, public Wi-Fi) from seeing that you visited the site, and encrypts the connection between you and the VPN endpoint. Choose a reputable VPN provider, not a free one.

Use the Tor Browser (highest anonymity)

If the risk is high or privacy is crucial: Tor hides your IP, routes your traffic through multiple relays, and makes it extremely difficult to track that you accessed the site. Performance is slower, but anonymity is stronger. Use Tor only with HTTPS sites – and inplain.site uses HTTPS by default.

3. Keep your hidden images as PNGs

PNG is lossless. That means every pixel remains exactly the same, and your hidden bits survive. JPEG, on the other hand, recompresses images and destroys the LSB-embedded data. You can upload PNG, JPEG, non-animated GIF, or WebP files, but the app flattens and converts inputs to PNG before embedding.

Never convert your encoded PNG to JPG. Never upload the encoded PNG to a platform that might convert it automatically.

4. Avoid platforms that compress or resize images

Many popular services automatically modify images, including:

  • WhatsApp
  • Messenger
  • Instagram
  • Facebook
  • Twitter / X
  • Discord (unless sent as file attachment)
  • Some email providers (depending on the client)

These modifications will usually destroy the hidden message, even though the picture looks the same.

Safer methods of sending:

  • Send the PNG as a file attachment
  • Upload inside a ZIP file
  • Use Signal, which preserves file integrity

5. Be careful with cloud storage previews

Google Drive, iCloud, Dropbox and others generate preview versions of images, often smaller or recompressed. Those previews do not preserve the hidden message.

Advise recipients: Always download the file, not just view it. Save the file locally before decoding.

6. Protect your screen and device

Even though the tool processes everything locally, someone watching your screen, a recorded screen share, remote desktop software, notifications, or auto-screenshot features could reveal sensitive text or passwords.

For sensitive use:

  • Work alone
  • Disable screen sharing / recording tools
  • Close background apps
  • Consider a secondary, offline or non-work device

7. Check the site URL

Always make sure you are on: https://inplain.site

Attackers can clone the interface to steal passwords or intercept messages. Bookmark the real URL to protect against phishing.

8. Clear traces after use

Even though the app does not store anything on servers, your browser or OS might keep local data: temporary files, downloaded images, recently opened documents, local storage (if future features use it), browser history entries.

For sensitive use:

  • Use Incognito Mode or Tor
  • Delete downloaded files when finished
  • Close the browser tab after decoding
  • Clear your browser's recent history if not in private mode

9. Verify the message before sending

Before relying on the stego image:

  • Encode it.
  • Immediately decode the result.
  • Confirm the message returns cleanly.

This ensures the hidden message fits within capacity, downscaling hasn't caused unexpected changes, and your password works.

10. Remember: steganography is subtle, not invisible

Steganography hides the existence of a message, and encryption hides its content. A determined analyst with specialised tools can detect that pixels have been modified.

If someone suspects steganography, they may run tests and challenge the image. For extremely high-risk scenarios, use it as part of a privacy strategy, not the whole strategy.

inplain.site is best used when you want strong privacy, message confidentiality, and prefer a message to blend into normal images – but not when you expect adversaries with advanced digital forensics tools.

11. Never lose your password

AES-GCM cannot be bypassed or brute-forced easily. If you forget the password, the message is permanently unrecoverable. There is no backdoor, and even the developers cannot retrieve an encrypted message.

For important content:

  • Store the password in a secure password manager
  • Keep a backup copy (encrypted) if needed

Summary: Fast best practices

Do:

  • Use a strong password
  • Access the site via Incognito, VPN, or Tor for better privacy
  • Keep encoded output as PNG
  • Send files as attachments, not previews
  • Decode the file once before sending
  • Secure or delete local traces after use

Don't:

  • Convert to JPEG
  • Upload to compressing platforms (Instagram, WhatsApp, Messenger)
  • Use weak or reused passwords
  • Forget the password if the message matters
  • Assume steganography is impossible to detect