ShareSafeNote
New Live code sharing, end-to-end encrypted

Share a secret.
It self-destructs.

Encrypted in your browser. Read once. Then it’s gone. No account, no tracking, free.

Security

Built so that we can't read a thing

Encryption happens on your device, not ours. The server only keeps unreadable text, and not for long.

Encrypted in your browser

AES-256-GCM through the Web Crypto API. One random key per note, generated on your device and placed in the link, never transmitted.

const key = await crypto.subtle.generateKey( { name: "AES-GCM", length: 256 }, true, ["encrypt"] ) // stays in your browser

Read once

The note is deleted the moment it is opened. A second click finds nothing.

Pick an expiry

10 minutes, 1 hour, 24 hours or 7 days. After that the note is destroyed, read or not.

Live code

You type, your guests watch in real time with syntax highlighting. Nothing is written to disk.

No account

No sign-up, no email, no password. What we never collect cannot leak.

Hosted in Canada

OVHcloud server in Beauharnois, Québec. Scripts served by us, no third-party trackers on the pages where your notes live.

Verifiable

Open your browser's Network tab: you will see ciphertext go out, never your note or its key.

How it works

Three steps, ten seconds

01

Write

Type your note. Nothing leaves the page yet.

02

Encrypt

Your browser encrypts it locally. The key never reaches our servers.

03

Share

Send the link. It self-destructs after the first read.

Why not just send an email?

A password sent by email or chat stays there. It sits in the sender's outbox, in the recipient's inbox, in the server's backups, and often in the history of a phone that will change hands one day. Six months later that password is still there, in plaintext, in four places nobody is watching.

ShareSafeNote inverts the problem: the content is encrypted before it leaves your browser, and it erases itself. What you share has an end date decided in advance.

What the server actually sees

Encryption happens in your browser, using AES-256-GCM. The key is placed in the URL fragment — the part after the # — and browsers never send that part to a server. We therefore store a block of ciphertext we are unable to read, because we do not hold the key.

You can check this: open your browser's developer tools, Network tab, and watch what leaves when you generate a link. You will see ciphertext, never your note.

What people use it for

Frequently asked questions

Can you read my notes?

No, and that is not a matter of internal policy: it is a technical impossibility. The decryption key never reaches us. Even under compulsion, all we could hand over is unusable ciphertext.

What happens if I lose the link?

The note is gone for good. Because the key lives in the link, losing it means losing the only thing that can decrypt the content. We cannot restore it.

How long does a note last?

A one-time note disappears on first read. Otherwise you pick an expiry between ten minutes and seven days. With no expiry set, it lasts until it is read.

Do I need an account?

No. There is no sign-up, no password and no email address to give. That is deliberate: data you never collect cannot leak.

Is it free?

Yes, entirely.

What is a live code session?

A space where you type code that your viewers see appear in real time, with syntax highlighting. The content stays end-to-end encrypted and lives only in server memory, never on disk.

What are the limits?

The link contains the key: whoever gets it gets the note. A browser history, a synced clipboard or a screenshot is enough to compromise it. Send the link over a different channel than the one you would have used for the secret itself.

See all questions →

Learn to share secrets safely

Plain-language guides to sharing passwords, keys and code without leaving secrets behind in inboxes and chat histories.

All guides →

Ready when you are

No sign-up, no setup. Write the note, share the link, and it takes care of erasing itself.

Create a secure note