Now, What?

Your private recovery page for when the phone is dead.

One link you'll never forget, open from any borrowed phone - so your trip keeps going. Your mom's number, your bank freeze line, and your next move.

Not even we can read your page. Protected by AES‑256 - the trusted encryption standard used by Signal, WhatsApp and 1Password.

Built in BerlinHosted in the EU

Try it. This one's real.

This is an actual recovery page, loaded live from nowwhat.page/alex.26. It arrives locked - exactly what a stranger who found the URL would see.

Unlock it like the owner would - name: Alex · PIN: 121212

nowwhat.page/alex.26

A real page, live

Loads the genuine encrypted page - not a mock-up.

Don't remember the URL? Type what happened.

DeadPhone.pageLostPhone.pageStolenPhone.pageRecovery.pageNowWhat.page

All of them lead to your recovery page.

One link.
Everything you need.

You fill it in once, on a calm Sunday. It waits quietly for the day you need it.

Fill yours in

No account needed.

NowWhat.page/pagename
Who to callfew numbers
Cards & accountsfreeze hotlines
Insurance & embassy24/7 claims line
Hotel & tripaddress, contact
Emergency detailsanything you might need
Your checklistcalm-you → panicked-you

Start free. Upgrade only when you want a name you'll remember.

Start free with a page on every domain, unlimited edits, and mandatory end-to-end encryption. Upgrade only when you want a name you'll remember.

Free, forever
  • A recovery page, live on every domain
  • Unlimited edits, forever
  • Mandatory end-to-end encryption
  • An auto-generated page name
  • Safely link to page from your own https://website.com/recovery

No card required.

See the paid plans - for a shorter, memorable name

Flexible

€9/month

  • 1 recovery page
  • Any name, any length
  • Cancel anytime
BEST VALUE

Safe

from €19/year

  • 1 recovery page
  • Any name, any length
  • "Remember the page?" reminders
  • Custom domain

Shorter names, higher price - full table at checkout.

Only you can read it. Not even us.

E2E encrypted. The key is made from two things - your name and your PIN - and never leaves the browser. Our server only ever sees the scrambled text it cannot read. Someone who stumbles on your URL sees exactly what you saw above: a locked page, and nothing else.

NowWhat.page/pagename
On your device· in your browser

your name

in your head

your PIN

in your head

key

built here · never leaves

locked before anything is sent
only scramble is sent
On our server

9f2a3b7e…c81d04af

ciphertext only

AES-256-GCM encryption · key built on-device, never sent · 600,000-round stretching · rate-limited unlocking · the actual scheme
key        = HKDF-SHA-256( PBKDF2-SHA-256(name + PIN, 600k)  ‖  OPRF(server) )
ciphertext = AES-256-GCM(content, key)   // header bound as AAD

Everything is encrypted and decrypted in your browser (Web Crypto). Your name and PIN are never transmitted - not even hashed.

The server's share of the key comes from an oblivious PRF (VOPRF, RFC 9497, P-256/SHA-256): it mixes in a server-held secret without ever seeing your inputs or the resulting key, and it rate-limits every evaluation. Guessing a PIN therefore means online, throttled round-trips - an offline attack on the stored ciphertext would also require stealing the server's key, which lives apart from the data.

The stored blob is a self-describing envelope; its parameters are authenticated as AES-GCM additional data, and decryption rejects weakened KDF settings or unknown suites - a tampering server can't downgrade it.

Read the full security design.

Fair questions

On different days we won't forget, we each just wished, that a few things had been written down somewhere we could always reach.

Dejan
Dejan

It was 10pm, I'd just taken the garbage down, and the door slammed shut behind me. My phone was still on the kitchen counter. My partner was asleep inside. Our doorbell was turned down to a whisper so it wouldn't wake our toddler. That's when it hit me: I didn't know her number by heart. So I rang the bell, and waited. And rang, and waited. Three hours in, she opened the door. Just one number kept somewhere I could reach, would have made it few minutes.

Daniela
Daniela

I lost my phone on holiday, and with it every way to reach home. I couldn't remember my mum's number, and I had no way to send her a simple I'm okay. In the end I asked the neighbours at our hotel to add her on social media - a slow, awkward chain of strangers just to get one message through. It worked, eventually. But it should never have been that hard.

You choose a 6-digit PIN or a longer passcode (recommended) when you set up. If it's truly gone, you can reset it from your account email and re-enter your details. We can't recover the old content for you. We genuinely cannot read it.

The URL is public on purpose - that's what makes it reachable from any borrowed device. But the content is end-to-end encrypted with a key made from your name + PIN, plus a secret from our server. A random stranger with your URL sees a locked page and scrambled text - they don't know the name of the person behind the page nor the PIN. And they can't sit there guessing: every unlock attempt goes through our server, which slows down and challenges repeated tries.

No - and this is the part we're proudest of. Unlocking isn't a local check; every single guess needs a round-trip to our server, which throttles repeated attempts and escalates to a human check, without ever learning your name, your PIN, or what's on your page. A million PIN combinations is nothing for a computer working offline - and hopeless when each guess is one rate-limited request. Prefer more margin? Pick a longer passcode instead of a PIN.

Your content is sealed in your browser with AES-256-GCM. The key is derived from your name + PIN via PBKDF2-SHA-256 (600,000 rounds), combined with the output of a rate-limited oblivious PRF (VOPRF, RFC 9497) evaluated by our server - which contributes a server-held secret without ever seeing your inputs or the key. So offline brute-force against the stored ciphertext also requires breaching the separately-held server key, and online guessing is throttled. The server stores ciphertext only, and decryption rejects downgraded parameters. The full design - threat model included - is written up at NowWhat.page/p/security.

You don't need email to use your page - only the page name, your name, and your PIN, all of which live in your head. Email is only needed to edit the page itself.

No. You set it up in any browser, on any phone or computer. That's rather the point - it exists entirely outside your phone.

Nothing changes. Your page isn't tied to a device, so there's nothing to re-pair or restore. You put it back in your pocket - the page just goes back to waiting.

Then type what happened instead. deadphone.page, lostphone.page, stolenphone.page, recovery.page (we own more) all open the exact same page. Remember whichever one sticks. Oh, and we'll email you periodically to remind you about your page.

Yes - each person gets their own page, with its own handle, name, and PIN. You can even build and pay for theirs and hand over the link. Handy when the person who'd normally rescue you is standing next to you, equally phoneless.

You fill it in on a calm Sunday. It saves you on the worst night of your trip.

Ten minutes to set up. Yours the moment you need it, from any browser on Earth.

NowWhat.page/