Frequently asked questions
Everything about how ShareSafeNote protects what you share: encryption, one-time links, expiry, live code sessions and privacy.
Security and encryption
Can you read my notes?
No. The note is encrypted in your browser before it is sent, with a key generated on the spot. That key is never transmitted to our server: we only store ciphertext we are unable to decrypt. This is not an internal policy promise, it is a technical impossibility.
What encryption do you use?
AES-256-GCM, through the Web Crypto API built into your browser. Each note gets a random 256-bit key and a unique initialization vector. GCM also guarantees integrity: ciphertext altered in transit is rejected instead of being decrypted.
Where is the decryption key?
In the URL fragment, the part after the #. Browsers never send that part to the server, neither in the request nor in logs. The full link is therefore the only thing that can unlock the note.
How can I check that nothing leaves in plaintext?
Open your browser's developer tools (F12), Network tab, then create a note. The request that goes out contains only an unreadable block of ciphertext, never your text or the key.
Could the server be hacked?
Like any server, yes. But an attacker would only find ciphertext without the keys, so nothing usable. That is the whole point of client-side encryption: the security of your notes does not depend on the security of our server.
Links and expiry
What does "one-time access" mean?
The note is deleted from our database the moment it is opened. If anyone else tries the link afterwards, the note no longer exists. It is the recommended option and is on by default.
How long does a note last?
With one-time access, until its first read. You can also set an expiry of 10 minutes, 1 hour, 24 hours or 7 days: after that, the note is refused and deleted even if nobody read it.
What happens if I lose the link?
The note is gone for good. The key only exists in the link; without it nobody, including us, can decrypt the content. Just create a new note.
The recipient says the note no longer exists. Why?
Either it expired or the link was already opened. Some chat and link-preview tools open URLs automatically to build a thumbnail; to prevent that, ShareSafeNote asks for a click on "Decrypt" before fetching the note. If in doubt, treat the secret as exposed and change it.
How should I send the link?
Use a different channel than the one the secret would normally travel through, for example an encrypted messenger. For a very sensitive password, send the link through one channel and confirm receipt through another.
Live code
What is a live code session?
A space where you type code that your guests see appear in real time, with syntax highlighting. It is handy for a quick code review or for helping someone without sharing your screen.
Is live code encrypted?
Yes, end to end, on the same principle as notes: the key lives in the session link and never leaves the participants' browsers. The server relays ciphertext and keeps it in memory only, never on disk.
How long does a session last?
At most 6 hours, and it closes after 2 hours without activity. Once closed, its content is gone from the server's memory.
Account, cost and privacy
Do I need an account?
No. There is no sign-up, no password and no email address to give. Data we never collect cannot leak.
Is it free?
Yes. ShareSafeNote is funded by a few ads shown only on informational pages (home, guides, FAQ, legal pages), never on the pages where you write or read a note, nor inside a code session.
What data do you keep?
For each note: the ciphertext, its creation date and its optional expiry date. Your IP address is only used briefly, in memory, to limit abuse. Details are in our privacy policy.
Where is the data hosted?
In Canada, on an OVHcloud server in Beauharnois, Québec. Since everything is encrypted before it is sent, the server never holds readable content anyway.
Good practices and limits
Can I share passwords or API keys?
Yes, that is the main use. For a team that shares access continuously, a password manager is still the better tool; ShareSafeNote is made for one-off handovers. See our guide on sharing API keys.
What are the security limits?
The link contains the key: whoever gets it can read the note. A synced browser history, a shared clipboard or a screenshot is enough to expose it. Likewise, if the recipient's device is compromised, no encryption protects what is displayed on screen.
What if a link was intercepted?
If the note has not been read yet, one-time access protects you: whoever opens it first destroys it, and the legitimate recipient will see that it no longer exists. Either way, change the secret as soon as you have a doubt.
Want to dig deeper? Our security guides explain client-side encryption, one-time links and secret sharing in detail. Another question? Get in touch.
Ready when you are
No sign-up, no setup. Write the note, share the link, and it takes care of erasing itself.
Create a secure note