The fundamental problem with this:
There's no way to prove that the secret has been deleted and / or not copied. You have access to the plaintext and the password / url (presumably an encryption key). You (the malicious server operator or the compromised server) can do anything you want with the information.
This would be interesting if you could:
1) Offer end-to-end encryption. This would require encryption in the client which has its own issues.
2) Be able to provide proof that the information has been made inaccessible. This is not the same thing as having the link return a 404 the second time.