Strong encryption
AES-256-GCM, with the key made from your passphrase by PBKDF2-SHA-256 at 600,000 rounds, a fresh random salt, and a fresh random IV every time.
Need to send someone a password, a Wi-Fi key, or account details? Lock it with a passphrase here, send the encrypted text or link, and give them the passphrase another way. It's encrypted on your device and never uploaded.
Last updated
Your note never reaches our server or anyone else's. Only the scrambled text travels, and it's useless without the passphrase.
AES-256-GCM, with the key made from your passphrase by PBKDF2-SHA-256 at 600,000 rounds, a fresh random salt, and a fresh random IV every time.
Encryption and decryption run in this page with the Web Crypto API. A link keeps the note after the # sign, which browsers never send to a server, and this page clears it from the address bar.
Send the encrypted text by email or chat and the passphrase by phone call or text message. Someone who sees only one can't read the note.
There is no copy anywhere but the message you send, so there is nothing for us to delete, and no way to recover a note if the passphrase is lost.
No. The note is encrypted and decrypted by code running in your browser. It is never sent to our server or anyone else's. With a link, the note sits after the # sign, a part of the address browsers never send to servers, and this page removes it from the address bar as soon as it opens.
The note can't be opened. There is no reset and no copy on any server, which is what keeps it private. Send it again with a new passphrase.
Yes, as long as the passphrase travels separately. Without the passphrase the text is unreadable. Use a strong passphrase: the suggested six words are about 78 bits.
No. Anyone with the text and the passphrase can open it at any time, so delete the message after it has been read, and change any shared password that should stay secret.
AES-256 in GCM mode, which also detects any change to the text. The key comes from your passphrase through PBKDF2 with SHA-256 and 600,000 iterations, the level OWASP recommends, with a random 16-byte salt and a random 12-byte IV for every note. All of it runs in your browser's Web Crypto API.
Monitoring assessments, NOC runbooks, network administration, and hands-on hardware deployment from a service-disabled veteran-owned small business in Waco, Texas.