Encrypted in your browser · opens once

Send a secret that burns after reading.

Your note is locked with AES-256 on this device before it goes anywhere. The key rides in the link after the #, which browsers never send to a server. The first open deletes it.

Server sees ciphertext onlyOne-time readExpires in 10 min – 7 daysWe never ask for your seed phrase.
0 / 30,000 bytesEncrypted before it leaves this tab
This looks like a seed phrase. Do not send a seed phrase to anyone, by any tool, ever. Anyone who has it owns the wallet. Real support teams never ask for it.
AES-256-GCM · random key per note
Link ready

Send this link to one person. It works once.

The part in orange is the decryption key. It exists only in this link — we can't recover the note if you lose it.

Someone sent you a secret note

Checking the note…

How it works

We hold a locked box. You hold the only key.

Everything that can read your note happens in your browser tab. Open your browser's network panel and look: the only thing sent is gibberish.

Encrypt here

Your browser makes a fresh random 256-bit key and encrypts the note with AES-GCM using the built-in Web Crypto API. No libraries, no plaintext on the wire.

Store the locked box

We store only the ciphertext, a random IV, and the expiry. The key goes into the link after # — the fragment — which browsers never send in requests.

Open once, then gone

When the recipient presses Reveal, the server hands over the ciphertext and deletes it in the same step. A second open finds nothing. Unopened notes are deleted at expiry.

Exact format. key = 32 random bytes (base64url in the fragment). iv = 12 random bytes. ct = AES-256-GCM(key, utf8(note)). With a passphrase: key' = key XOR PBKDF2-HMAC-SHA256(passphrase, 16-byte random salt, 600,000 iterations, 32 bytes), so the link alone is not enough. Server request: POST /api/sn_put {ct, iv, salt?, ttl} → id. Read: GET /api/sn_get?id= returns and deletes. Link: https://host/#id.key. Crypto code: /sn.js (40 lines, readable). The page's Content-Security-Policy only lets it connect to its own server.

FAQ

Plain answers.

Can SecretNote read my note?

No. We never receive the key, so what we store is unreadable to us. What we do see: the ciphertext size, the expiry, when it was created and opened, and — like any website — your IP address in ordinary request handling. We don't add tracking.

Can a note disappear before it's opened?

Yes. Notes live on a small server disk; a redeploy or restart of the service can wipe them, so a note may expire early. Treat this as a courier, not a vault. For files you need to keep, use VaultBox.

What if a chat app previews the link?

Link previews fetch the page, not the note: the note is only taken when someone presses Reveal, and the key after # is never sent to anyone's server. Some messengers do store the full link in their chat history, so a passphrase shared another way adds a second lock.

Should I send a seed phrase or private key with this?

No. Never send a seed phrase or private key to anyone, with any tool. We never ask for your seed phrase, and nobody legitimate will. If someone asks you to "verify" or "sync" a wallet with one, it's a theft attempt.

How big can a note be?

30,000 bytes of text (about 30,000 English characters, fewer for emoji). The server refuses anything over 32 KB of ciphertext.

The recipient got "note does not exist". Why?

Someone opened it already (maybe a person, maybe you testing it), you burned it, it expired, or the server lost it in a restart. If the recipient didn't open it and you didn't either, assume someone else saw the link and rotate whatever was in it.