Secure Notes

Create encrypted, self-destructing notes with end-to-end encryption. All data is encrypted exclusively in your browser – no one can read the content.











0 / 100.000 Zeichen




For maximum security: recipient needs both the link and this password.


Please accept terms of use and privacy policy.



End-to-End Encryption & Maximum Security


AES-256 Encryption:
All data is encrypted exclusively in your browser with military-grade AES-256 encryption.


Key only in link:
Your encryption key is never transmitted to our server and is contained exclusively in the link fragment (#…).


Hash storage:
The encrypted data is stored as a cryptographic hash in the database and cannot be read without your key.


Automatic deletion:
Contents are automatically deleted after expiration or at the latest after 24 hours.


Optional password protection:
You can activate additional password protection. The recipient will then need both the link and the password.


One-time viewing:
After the first retrieval, the content is immediately and irrevocably deleted. Even we as the provider never have access to your decrypted content.


Nutzungsbedingungen & Datenschutz

Terms of Use for Secure Notes & Password Share

1. Scope

These terms of use apply to the use of the \\\“Secure Notes & Password Share\\\“ tool (hereinafter \\\“Service\\\“) on this website. By using the Service, you agree to these terms.

2. Service Description

The Service allows users to temporarily store encrypted notes and passwords and share them via a link. All content is end-to-end encrypted and automatically deleted after first retrieval or expiration of validity period.

3. Permitted Use

The Service may only be used for legal purposes. In particular, use is permitted for:

  • Secure transmission of passwords
  • Exchange of confidential information
  • Temporary storage of sensitive data
  • Business and private communication

4. Prohibited Use

The following uses are strictly prohibited:

  • Transmission of illegal, harmful, offensive or defamatory content
  • Distribution of malware, viruses or malicious code
  • Copyright infringement or intellectual property violations
  • Spam, phishing or fraudulent activities
  • Harassment, bullying or discrimination
  • Terrorist content or glorification of violence
  • Child pornography or other illegal pornographic content
  • Drug trafficking or other illegal business
  • Identity theft or fraud
  • Violation of third party privacy
  • Automated access or infrastructure abuse

5. User Responsibility

The user is fully responsible for:

  • The legality of transmitted content
  • Compliance with applicable laws in their jurisdiction
  • Secure handling of generated links
  • Damages arising from their use

6. Technical Availability

We strive for high availability of the Service but cannot guarantee 100% availability. Maintenance work will be announced when possible.

7. Disclaimer

The operator is not liable for:

  • Data loss due to technical problems
  • Damages from misuse by third parties
  • Content transmitted by users
  • Indirect or direct damages from use
  • Business losses or lost profits

Liability is limited to intent and gross negligence. Mandatory legal liability provisions remain unaffected.

8. Blocking and Termination

In case of violation of these terms of use, we reserve the right to:

  • Block access to the Service
  • Block IP addresses
  • Initiate legal action
  • Cooperate with law enforcement

9. Changes to Terms

We reserve the right to change these terms of use at any time. Users will be informed of significant changes. Continued use constitutes acceptance of the modified terms.

10. Legal Notes

In case of suspected illegal use, we reserve the right to:

  • Forward log data to authorities
  • File charges for serious violations
  • Cooperate with law enforcement agencies
  • Assert civil law claims

11. Applicable Law

German law applies to these terms of use, excluding the UN Convention on Contracts. Place of jurisdiction is the operator\\\’s registered office.

12. Severability Clause

If individual provisions of these terms of use are invalid, this does not affect the validity of the remaining provisions.

Privacy Policy for Secure Notes & Password Share

1. Data Controller

The data controller for the \“Secure Notes & Password Share\“ tool is the operator of this website. Contact details can be found in the website\’s imprint.

2. Types of Data Processed

When using the tool, the following data is processed:

  • Encrypted content (notes or passwords) – stored with end-to-end encryption
  • Technical data: IP address, browser information, access time
  • Session data for technical functionality

3. Purpose of Data Processing

Data processing serves exclusively to provide the functionality of the Secure Notes tool:

  • Temporary storage of encrypted content
  • Ensuring technical functionality
  • Protection against abuse and spam

4. Legal Basis

Processing is based on your consent (Art. 6(1)(a) GDPR) through active use of the tool.

5. End-to-End Encryption

All content is end-to-end encrypted using AES-256 encryption. The decryption key is generated exclusively in your browser and never transmitted to the server. Even the operator cannot view the content.

6. Storage Duration and Automatic Deletion

Encrypted content is only stored temporarily and automatically deleted:

  • After the first retrieval of content
  • After expiration of the selected validity period (10 minutes to 24 hours)
  • At the latest after 24 hours, even if not retrieved

7. Data Sharing

Your data is not shared with third parties. Technical service providers can only access encrypted data that is unreadable to them.

8. Your Rights

You have the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction (Art. 18 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to lodge a complaint with supervisory authority

9. Cookies and Local Storage

The tool does not use permanent cookies. Temporary session data is only used to ensure technical functionality.

10. Security Measures

We use state-of-the-art security measures to protect your data, including HTTPS encryption and regular security updates.

How to share notes securely

With this tool, you can securely share confidential notes and passwords. Content is end-to-end encrypted and automatically deleted after the first access or after expiration. The tool offers both a simple note function and an advanced password generator. Follow these simple steps:

1

Choose content type

Decide between "Note" for text content with rich text editor or "Password" for secure password transmission with integrated generator.

2

Enter or generate content

For notes, use the rich text editor with formatting options (bold, italic, lists, links). For passwords, you can enter your own or use the generator with customizable options.

3

Use password generator

Configure length (8-32 characters), character sets (upper/lowercase letters, numbers, special characters) and generate secure passwords with strength assessment.

4

Set validity

Choose the lifetime from 10 minutes to 24 hours. After expiration, the content is automatically deleted.

5

Accept legal terms

Confirm the terms of use and privacy policy by checking the checkbox.

6

Create encrypted link

Click "Create secure content" - the tool encrypts your content client-side and creates a secure sharing link.

7

Share link

Copy the generated link and share it via the integrated share buttons (email, WhatsApp, Telegram) or manually.

8

Retrieve content

The recipient can decrypt and view the content once via the link - after that it is automatically deleted from the server.

Secure Notes – Encrypted, Self-Destructing Messages for Maximum Privacy

Secure Notes is a highly secure tool for creating encrypted, self-destructing notes, passwords and sensitive information. With end-to-end encryption (AES-256-GCM) directly in the browser, your data is never transmitted or stored unencrypted – not even the server can read it.

End-to-End Encryption

AES-256-GCM encryption occurs exclusively in your browser. Nobody except the recipient can read the message – absolute privacy guaranteed.

Self-Destruction

Notes are automatically and irrevocably deleted after one-time opening or expiration time – no traces remain.

Optional Password Protection

Additional security layer: Protect notes with a password. Only those who know both link AND password can decrypt the message.

Zero-Knowledge Principle: Create encrypted notes, share the secure link – the recipient can read the message once, then it's deleted forever.

Why are encrypted, self-destructing notes important?

In a digital world where data leaks and surveillance are commonplace, Secure Notes offer absolute security for sensitive information. Unlike emails or messengers, no permanent copies remain – the message exists only temporarily.

AES-256
Military-Grade Encryption
1x
One-Time View
0%
Server Access

Secure Notes offers significant security advantages:

  • Client-Side Encryption: All data is encrypted in your browser before reaching the server – the server only receives encrypted ciphertext
  • No Plaintext Storage: Neither content nor password is ever stored unencrypted – absolute zero-knowledge principle
  • Automatic Self-Destruction: Notes are irrevocably deleted after 1 hour, 24 hours, 7 days or one-time opening
  • No Account Required: Completely anonymous usage – no registration, no login data, no tracking cookies
  • Various Content Types: Supports text, passwords, code snippets, JSON and Markdown with appropriate formatting
  • Secure Link Delivery: Recipient only needs the link – no additional tool or software installation required

Application Areas of Secure Notes

🔐 Passwords & Credentials

Secure sharing of passwords, API keys, access data or credit card information. Ideal for IT teams who need to pass on temporary credentials without email risks.

💼 Business Communication

Securely transmit confidential contracts, NDA documents, price quotes or sensitive business data. After viewing, data is automatically destroyed – no compliance risks.

👥 Personal Secrets

Share private messages, confessions or personal information that should disappear without a trace after reading. Perfect for maximum discretion.

Tips for Secure Use of Secure Notes

  1. Activate Password Protection: For highly sensitive data, additionally activate password protection. Share link and password via separate channels (e.g. link by email, password by phone).
  2. Choose Short Expiration Time: Select the shortest possible expiration time for your application. For one-time handover use "After first opening" – absolute security.
  3. Transmit Link Securely: Send the link only via secure channels. Avoid public chats or insecure messaging apps for highly sensitive information.
  4. Minimize Content: Share only absolutely necessary information. The less data exposed, the lower the risk of compromise.
  5. Inform Recipient: Tell the recipient that the message can only be opened once. Accidental closing leads to permanent data loss.
Important: Secure Notes is not a backup system. Create copies of important information before sending the link. After expiration or opening, data is irretrievably deleted.

Frequently Asked Questions (FAQ)

End-to-end encryption in Secure Notes occurs exclusively in your browser: Step 1: You create a note and optionally choose a password. Step 2: Your browser automatically generates a 256-bit encryption key (AES-256-GCM). Step 3: The content is encrypted locally in your browser – before any data is sent to the server. Step 4: The server only receives encrypted ciphertext and stores it. The decryption key is included in the link and never leaves your browser or the recipient's. Result: Nobody except the recipient can read the message – not even we as operators have access to the plaintext.

Self-destructing means notes are automatically and irrevocably deleted after certain conditions: After first opening: Note is permanently deleted immediately after reading – safest option for one-time handovers. After 1 hour: Note remains available for 1 hour, then automatic deletion – ideal for time-critical information. After 24 hours: Note remains available for 1 day – good for daily password transfers. After 7 days: Note remains available for 1 week – longest expiration time for less urgent information. Important: After expiration or opening, the note is irretrievably deleted – no recovery possible. The encrypted ciphertext is completely removed from the database.

No, absolutely not – and for technical reasons: Zero-Knowledge Architecture: The server only stores encrypted data (ciphertext), never plaintext or decryption keys. Client-Side Encryption: All encryption occurs in your browser with JavaScript – the server never receives unencrypted data. Key in Link: The decryption key is part of the link (after the # character) and is never transmitted to the server. No Backdoors: There are no master keys or admin access – technically impossible for us to decrypt notes. Even with database access: An attacker or administrator only sees useless ciphertext without the key from the link.

Optional password protection offers an additional security layer: Double Authentication: Link AND password are required for decryption – without password the note is unreadable. PBKDF2 Key Derivation: Password is converted into a key with 100,000 iterations of PBKDF2-SHA256 – protection against brute-force attacks. Salted Hash: Each password receives a unique salt – identical passwords generate different hashes. Never in Plaintext: Passwords are neither transmitted nor stored – only the hash is used for validation. Recommendation: Use strong passwords (12+ characters, upper/lowercase, numbers, special characters) for maximum security with highly sensitive data.

Losing the link means permanent data loss: No Access Without Link: The decryption key is exclusively in the link – without the link, the note cannot be recovered. No Recovery Possible: There is no "forgot password" function or account access – the note is permanently lost. No Search Function: The server stores no metadata (sender, time, content description) – links cannot be searched retrospectively. Zero-Knowledge also means: We cannot help you recover lost notes. Prevention: Send the link immediately after creation to the recipient. Save important information separately before creating the note.

This depends on the chosen expiration time: "After first opening": Note can ONLY be opened ONCE – after reading it's permanently deleted. Accidental closing leads to data loss. "After 1/24 hours or 7 days": Note can be opened MULTIPLE times until time expires – then automatic deletion. Security Note: Multiple openings increase risk of third parties intercepting the note (e.g. on shared devices or insecure networks). Best Practice: For maximum security choose "After first opening" – this ensures the note is only read by the intended recipient. Warning: The recipient should know the note can only be opened once.

Secure Notes supports various content types with appropriate formatting: Text: Normal flowing text for messages, notes or information – simple text display without formatting. Password: Special mode for passwords and credentials – monospaced font, show/hide button, copy-to-clipboard function. Code: Syntax highlighting for code snippets – supports JavaScript, Python, PHP, HTML, CSS and more with line numbering. JSON: Automatic validation and pretty-print for JSON data – ideal for API keys, configuration files or structured data. Markdown: Full Markdown support with rendering – headlines, lists, links, code blocks, tables. All Types: Are equally securely encrypted, only the display for the recipient differs.

Secure transmission of the link is crucial: Separate Channels: With password protection: Link via email, password via phone/SMS – prevents complete interception with one compromised channel. Secure Messengers: Use end-to-end encrypted messengers like Signal, WhatsApp or Threema – no public chats or insecure emails. No URL Shorteners: Don't use services like bit.ly – they store the complete link including key in their logs. HTTPS Required: Ensure the recipient opens the link via HTTPS – no insecure HTTP protocol. Avoid: Public forums, social media posts, unencrypted emails for highly sensitive data. Send Promptly: Send the link immediately after creation to minimize the time window.

Yes, there are technical and practical limits: Maximum Size: Notes are limited to 100 KB plaintext (about 100,000 characters or ~50 pages of text). Reason: Browser encryption is resource-intensive – too large notes would overload mobile devices and cause long loading times. Recommendation: For large files use encrypted cloud services with password protection (e.g. Tresorit, ProtonDrive). Secure Notes is optimized for short, sensitive texts. Practical Application: 100 KB is enough for: 50+ passwords, multiple API keys, longer code snippets, multi-page contracts or detailed instructions. Performance: Smaller notes (<10 KB) are encrypted and loaded faster – ideal for mobile use.

Secure Notes offers several crucial advantages over email encryption: No Permanent Copy: Emails remain permanently stored in mailboxes (sender + recipient). Secure Notes exists only temporarily and is completely deleted. No Account Needed: Email encryption (PGP/S/MIME) requires certificates, keys and technical know-how. Secure Notes: simply share link. Guaranteed Encryption: With emails, mistakes can happen (plaintext sent, wrong key). Secure Notes ALWAYS encrypts automatically. Self-Destruction: Emails remain forever – Secure Notes deletes itself automatically after expiration. No forensics possible. Metadata: Emails contain sender, recipient, subject, timestamp. Secure Notes: no metadata stored. Simplicity: Share link vs. exchange PGP keys and install software.

Rating

5.0 out of 5 stars · 2 ratings
Advertisement
Advertisement
Advertisement