1 · Add names
Start with names, not inboxes. Invite the whole group without creating a single account.
Private gift exchanges
Create a gift exchange people actually look forward to — with exclusion-safe matching, no signup, and a little more delight.
One link. One secret. Zero inbox clutter.
Set the guardrails, make the draw, then hand each person their own moment. Everything runs in your browser — nothing is stored on a server.
0 people added — you need at least two.
You are the organizer: this is the only place the full list ever appears. Everyone else sees just their own link.
| Giver | Draws |
|---|
Receipt — publish this with your group
SHA-256 commitment to the exact draw, made before anyone reveals. Anyone can check it on the verification page.
Copy each link to its person by whatever channel you like — messaging, paper, whisper. The link shows only their own pairing, and carries the proof that it was part of the committed draw.
Keep these links. Nothing is stored anywhere else — the links are the exchange. Lost links cannot be recovered (see retention).
Start with names, not inboxes. Invite the whole group without creating a single account.
Keep couples apart and get a clear, honest answer when the rules cannot work — no draw is invented to save face.
Hand out private links, then let each person have their own little moment. No emails, no handoffs you can’t see.
MerryShuffle turns the technical part into quiet confidence: every assignment is one-to-one, every exclusion is honored, and the draw can be checked after the reveal.
When you shuffle, the tool commits to the exact draw by publishing a SHA-256 receipt. Each private link carries a cryptographic proof that its pairing was part of that commitment — so a curious participant can confirm the draw wasn’t quietly rearranged.
What the receipt can and cannot prove is spelled out plainly on the verification page.
receipt
7f3a…c41d ✦ committed before any reveal
your link proves
Ada → Grace ∈ receipt ✓
Alice not-with-Bob since the incident. Fine. The exclusions hold, nobody sees why, HR never hears about it.
Couples who refuse to draw each other, the sibling pair that always rigs it — guardrails set in ten seconds.
Three time zones, one reveal moment per person, whenever they open their link. No group-call scheduling.
The draw happens in your browser. Nothing you type is sent to or stored on any server — there is no server side to this tool at all. Each link carries exactly one pairing, obfuscated in the URL fragment, which your browser never transmits to us.
We do measure aggregate traffic with Google Analytics 4 (see privacy); it never sees your names or links.
No. There are no accounts, no emails, no logins. The organizer makes the draw in their browser and hands out links.
The matching step only accepts a strict one-to-one draw with no self-assignments and every exclusion honored — the engine retries with fresh randomness up to 250 times, and if the rules are too tight it tells you honestly instead of bending them.
That the pairing inside each link was committed — hashed into the published receipt — at the moment of the draw, before anyone revealed. It cannot prove the organizer delivered every link; that part still runs on trust (or on comparing receipts in the group chat).
Not by eye — the pairing is obfuscated inside the URL fragment. But obfuscated is not encrypted: anyone who holds a link can decode that one pairing. Treat links as personal.
They are the only copy — the exchange is stateless by design. Keep them somewhere safe until the reveal (see retention).
This is the fleet home of MerryShuffle: same concept, rebuilt to run entirely in your browser, with an open verification page and honest limits.