All articles

How to share sensitive information safely

Kent — founder, former banking CTO/CIO · August 11, 2026

The babysitter needs the insurance card. The lender wants a W-2. The new landlord asks for “a quick photo of your ID.” So you do what everyone does: snap a picture, hit send, move on. Nobody meant any harm — and that’s exactly what makes this the most ordinary risk in your digital life.

The problem isn’t the person you sent it to. It’s that every send creates a copy you no longer control — one that doesn’t expire, lives in places you’ll never see, and can’t be taken back. Here’s why the usual channels are riskier than they feel, and the small set of habits that covers almost all of it.

Where the copies end up

Send a document the usual way and it quietly multiplies:
Email
Sits in two inboxes indefinitely — plus their backups. One breached account, years from now, and your ID is part of the haul.
Texts & chat apps
Synced to clouds, backed up to devices you've never seen, and sitting in a thread anyone borrowing the phone can scroll.
Camera rolls
The photo you took "just to send it" lives on — auto-backed-up, synced, and carried into every phone you'll ever migrate to.
Shared drives & links
"Anyone with the link" means anyone, indefinitely — links get forwarded, and shared folders outlive the reason they existed.
The common thread: none of these let you expire a copy, see who has it, or take it back. The send is instant — the exposure is permanent.

What “safe sharing” actually means

It’s not about paranoia or refusing to share — life requires handing things over. Safe sharing just means the exchange keeps four properties: only the intended person can open it (encryption, not an open channel), they get only what they need (the field, not the file), it doesn’t live forever (you can expire or revoke it), and you know what’s out there (a record, not a guess).

Miss all four — which is what a texted photo does — and you’ve traded a minute of convenience for a permanent copy in the wild.

Two hands passing a document across a warm kitchen table — a deliberate, trusting handover.

The playbook

Five habits, in order of how often they'll save you:
1
Share the field, not the document. Most requests need a value — the policy number, the account digits, the date — not an image of the whole card. Read it over the phone or type the number itself, and the sensitive artifact never leaves your hands.
2
If it must be a file, make it expire. A protected link you can revoke beats an attachment that lives forever. Password-protect the file and send the password over a different channel than the link.
3
Strip what isn't needed. Crop and redact before sending: cover the SSN if they only need the income line, send the front of the card if the front is enough. The recipient loses nothing; you lose less if it leaks.
4
Delete your copies afterward. The photo in the camera roll, the scan in Downloads, the sent attachment — the transaction ended, and the copies shouldn't outlive it. This one habit quietly shrinks years of accumulated exposure.
5
Keep the originals somewhere built for sharing. One encrypted place that shares by field, per person, revocably — so next time, you share from the vault instead of the camera roll, and nobody else can read what's stored.

Before you hit send

Three questions and one red flag:

"Could I share a number instead of an image?" If yes, do that — it's faster than it sounds and removes most of the risk.
"Can I expire or take this back later?" If the channel has no answer to that, it's the wrong channel for anything sensitive.
"Would I be fine if this exact message surfaced in three years?" Because that's the realistic lifespan of a sent copy.
The red flag: anyone pressuring you to send an ID, SSN, or bank details right now over text or email. Urgency plus sensitive data is the signature move of a scam — real institutions have secure portals and can wait an hour.

Where Simply Once fits

Sharing is the reason Simply Once exists — done the way this whole guide wishes it worked. The babysitter gets exactly tonight's card, the lender gets exactly the field it asked for: scoped per person and per detail, revocable any time, with a record of who has what — and zero-knowledge encryption means what you store is readable by you and the people you choose, and no one else. Ever.

Get the monthly note

One useful, jargon-free email a month on keeping your digital life organized and protected — no spam, unsubscribe anytime.

No spam, ever. Unsubscribe anytime.