Guide · Choosing a method

How to do Secret Santa: a hat, an email generator, an app, or sealed links

Five ways a group ends up with one name each, compared on two columns this genre never includes: who is left holding everyone's email address, and what is still lying around in February. A hat at a party is genuinely excellent and needs no technology at all — and the blind version of it fails about 63% of the time on the first attempt.

Methods compared5 Blind hat draw fails63% Addresses collected here0 Messages you send1 per person

The five methods, side by side

All five work. They differ in what they ask of the group, what they leave behind, and who ends up knowing something they did not need to know.

Method Who holds every email address What still exists in February Does the organizer end up knowing Remote group Someone drops out What it costs
Names in a hat, at a party Nobody. None are needed. A folded slip, if it missed the bin. No, if they draw too. No. Redraw on the spot. Paper, a bowl, one room.
Hat drawn over a video call The calendar invite, visible to every guest. The recording and the chat log. Usually: someone holds the bowl. Yes, if all attend at once. Reconvene the call. One hour everyone is free.
Email generator site The site, its mail provider, every mailbox. A database row, sent mail, often a mailing list. Not on screen. The server can reproduce it. Yes. Re-run, re-send to all. Your address list.
App with accounts The app, tied to a login each. The account, profile, wish lists, group history. Not on screen. The server can reproduce it. Yes, and it chases people. Re-run, everyone rechecks. An account per person.
Sealed links (this site) Nobody. There is no field for one. The message in whatever thread carried it. No screen here shows it; the organizer holds every link. Yes, with no shared hour. Re-seal one link. One message per person, sent by you.

The 63% number, and why group size barely changes it

Everyone writes a name, everyone picks at the same moment, and then you ask whether anybody got themselves. About 63 times in 100, somebody did — and that hardly depends on the size of the party. A draw in which nobody picks their own name is a derangement, and the share of all possible draws that qualify settles almost immediately on 1/e, about 0.368. For four people, 9 draws out of 24 work: 37.5%. For six, 265 out of 720. For ten, 1,334,961 out of 3,628,800, still 36.8%. A family of five and an office of fifty face the same odds of starting again.

What happens next is where the fairness quietly leaves the room. The usual repair — whoever drew themselves swaps with the person beside them — is quick, cheerful, and no longer a random draw: the outcome now depends on who stood where, and that one pairing is certain rather than one possibility among many. Picking one at a time with a put-it-back rule only defers the problem to the last person, left holding their own name. If you redo it, redo all of it.

That is what this tool does, with the redo cost taken off you: shuffle, check against every rule, discard the whole shuffle if anything breaks, until one survives. Conditioning a uniform distribution on a rule leaves it uniform over the survivors, so the draw you keep is evenly likely among all the draws your rules allow — at an expected cost of about 2.72 shuffles, with fewer than one draw in a thousand needing more than sixteen.

One party method dodges the redraw entirely: seat everyone in a random circle, each giving to the next. That is Sattolo's algorithm wearing a paper hat, and every result it produces forms a single loop. It can never produce the three four-person draws where two pairs simply swap, and its reach falls away with size: about 67% of valid draws at four people, 27% at ten, 14% at twenty.

What each method leaks, to whom, and when

Names in a hat, at a party

Leaks to nobody, provided the slips are identical, folded the same way, and the bowl is not transparent. The realistic failure is physical: a slip left face-up, or two told apart by a crease. The organizer draws with everyone else, so no privileged position exists. It is the best method here, and it costs the one thing many groups cannot arrange — everybody in a room at once.

Hat drawn over a video call

Leaks to whoever holds the bowl, at the moment they pick, because somebody has to read out what comes out. It leaks to the call as well: a recording holds the entire draw, and the calendar invite that arranged it shows every address to every guest.

Email generator site

Leaks the address list to the operator, permanently, the moment you paste it in. That is architecture rather than bad intent: a server cannot deliver a result without an address to send it to. The mapping sits there too, and the features say so more reliably than the promises do — a site that can resend a lost assignment can reproduce that assignment. Whether anyone looks is policy, and a policy is something you take on trust.

App with accounts

Leaks the same address list plus a durable identity per person: everyone ends up with a login they did not have, often on a reused password. In exchange the app does real work, chasing people who have not opened anything and absorbing a drop-out without you thinking about it. For a sixty-person office that can be the right trade. It is still a trade.

Sealed links, the method here

Leaks nothing to us: nothing you type is transmitted by this site, and the whole draw runs with your wifi switched off. There is no account, no database, and no server of ours for anything to sit on — each result lives inside its own link, in the part of a URL after the #, which browsers never send to a web server. It does leak to the carrier the moment you press send: Slack, Gmail or WhatsApp stores that message like any other. And in a Quick draw the organizer hands out every link, so they could open one, deliberately, one person at a time, past a screen with someone else's name on it. A sealed envelope, not a vault.

What is still there in February

December is when people compare these tools. February is when the difference shows, because that is when everything made in December is still sitting where it was left.

The paper draw leaves a folded slip in a coat pocket. The video call leaves a recording and a chat log. The generator site leaves a database row per participant per draw, a copy of the assignment email in every mailbox for as long as people keep mail, and often a seasonal mailing list nobody consciously joined. The app leaves an account per person — the longest half-life on the list, since accounts outlive the group and take a support request to remove.

Sealed links leave the messages you sent, in the threads you sent them in, held by whoever runs those threads. That is a real artifact and we will not pretend otherwise. What is missing is the rest: no row, no account, no address book, and nothing on our side to delete, because none of it was created.

Choosing, and what this method costs you

If everyone will be in one room, use paper: identical slips, the organizer draws too, and redo the whole draw rather than patching it. If the group is remote, use sealed links. If it is a large workplace that needs reminders, wish lists, and somebody chased on the 18th, an app will do that work — go in knowing everyone gets an account out of it.

The costs of the method here, stated plainly. Twenty-five people means twenty-five separate messages, and you send every one: there is no send button, because there is no server to send from. A link you send is stored by whatever carried it, which is outside our reach entirely. In a Quick draw the key rides inside the link, so anyone holding a link can open it, including you. A Locked draw seals each assignment to a key the participant's own device made and sent to nobody, so the organizer ends up holding envelopes they cannot open — and it does not remove every exposure: the draw itself runs in the organizer's browser, so an organizer with developer tools open at that instant sees the pairing. We cannot remove that moment without a server, and a server is what every other tool has. If you would rather nobody had that moment, hand the draw to someone who is not playing.

One property applies to every method equally: in a very small group the maths gives the game away. With three people there are only two possible draws, so anyone who sees their own result knows the other two. That is small numbers, not any particular tool.

Frequently asked questions

How do you do Secret Santa without an app?
Two ways, neither needing an account. On paper: identical folded slips, everyone draws at a party, and you redraw if anybody picks themselves. Or draw the names in a browser and send each person their own sealed link in a thread you already use, with no sign-up, no addresses, and nothing to log into later. Paper wins when everyone is in one room; links win when they are not.
How do you do Secret Santa by text message?
Use something that produces one result per person rather than one list, then paste each result into its own message. Here that is a sealed link of about 200 characters, identical in length for everyone in the draw and the same whether the group is 6 people or 50. What scales is the number of messages, not their size. Check the name at the top of the thread before each send: pasting Ana's link into Ben's chat is the classic failure.
Why did our hat draw have to be redone?
Because somebody drew their own name, which happens about 63% of the time. The chance that nobody in a blind simultaneous draw picks themselves converges on 1/e, about 0.368, and it barely moves with group size: 37.5% for four people, 36.8% for ten. That is arithmetic, not bad luck. Avoid it by picking one at a time with a put-it-back rule, or by drawing somewhere that discards an invalid result before anyone has seen it.
Is shuffling everyone into a circle a fair way to do it?
It is valid, but it is not the whole set. A random circle in which each person gives to the next never produces a self-draw, which is why it is popular, and it is Sattolo's algorithm under a friendlier name. Every result it produces forms a single loop, so it can never produce the three four-person draws where two pairs simply swap, and at twenty people it reaches about 14% of the valid draws.
Do I have to collect everyone's email address?
Only if the thing doing the drawing also has to do the sending. A server cannot deliver a result without somewhere to deliver it to, so the address list is the price of that convenience. If you hand the results out yourself, through threads that already exist, there is nothing to collect. This site has no field for an address and no way to send anything.

Related