Secure Note Sharing
Write a note and get a link to share it. The note is encrypted in your browser with AES-256-GCM and travels inside the link; nothing is stored.
- Free, no sign-up
- Updated
- Reviewed by Olgun Ozoktas
Share the password another way, not in the same message as the link.
The note is encrypted before the link is made.
How to share an encrypted note
-
Write the note
Type or paste the text into the Note box. It can be up to 4,000 characters, and the counter shows how many you have used. -
Add a password if you want one
Leave the password empty and the link alone opens the note. Set one and the recipient also needs the password, which you should send another way, such as a phone call or a different app. -
Create the link
Select Create link. Your browser encrypts the note and builds a link that contains it. Copy the link with the Copy link button. -
The recipient opens it
When they open the link, this page shows Someone sent you a note. They select Reveal note (entering the password if there is one), and their browser decrypts it. The part after # is then removed from their address bar.
When it helps
Sending a password or API key
Wi-Fi details for a guest
Short setup instructions
Keeping the text out of the message itself
Why share a note this way?
Secure Note Sharing turns a short note into a link that contains the note, encrypted. Your browser encrypts the text with AES-256-GCM before the link is made. With no password, a random 256-bit key is generated and placed in the link after the # sign, next to the encrypted note, so anyone with the full link can read it. With a password, the key is derived from the password with PBKDF2-SHA-256 at 600,000 iterations and is not in the link at all, so the link alone is not enough. AES-GCM checks the data as it decrypts, so a wrong password or a single changed character makes the note fail to open instead of showing scrambled text.
Nothing is stored anywhere: not on a server and not in your browser's storage. That is why the link can be long, why the note has a 4,000-character limit, and why there is no expiry time and no burn-after-reading. The note exists for as long as the link does. Browsers do not include the part after # in the requests they send or in the Referer header, so the note is not sent to this site when the page loads. The page itself loads analytics and ads like every page on the site; they see the page address but not the part after #. When the recipient opens the note, the page removes the part after # from their address bar.
If you need to encrypt longer text or keep it as a file, the Text Encryption tool encrypts text with a password without a length limit set by a link. For public-key encryption between two people who have exchanged keys, use the PGP Encryption Tool. To make a strong password for the note, use the Password Generator, and check one you already have with the Password Strength Checker.
How it compares
Many secret-sharing services store the encrypted note on their server and give you a link to it. That design is what allows a note to expire or be deleted after one view, and it means the note depends on the service keeping it. This tool takes the other approach: the encrypted note is inside the link, so nothing is stored, nothing needs to be deleted, and the link keeps working without any server holding your data. The cost is that a link cannot expire or burn after reading, and the note has to be short enough to fit in a link.
Compared with PGP, there are no key pairs to create or exchange; the link (and the password, if set) is the secret. That makes it quick for one-off sharing but gives none of PGP's identity checks. Compared with pasting text into chat or email, the text is not readable in the message, but whoever holds the link can read it, so use a password and a separate channel for anything that matters.
Tips
- Use a password for anything sensitive, and send it through a different channel from the link.
- Send the whole link. If a chat app cuts it short, the note will not open; send it as a file or in a different app.
- The link cannot be revoked. Rotate a password or key you shared once it has been used, rather than relying on the link going away.
- Anything that stores the link, such as a chat history or browser history on the sender's side, keeps a copy that can open the note.
- Use a long, random password; the Password Generator can make one.