---
title: "Secure Note Sharing"
description: "Write a note and get a link to share it. The note is encrypted in your browser with AES-256-GCM and travels inside the link; nothing is stored."
url: https://findutils.com/security/secure-note-sharing/
category: security
---

# Secure Note Sharing

Write a note and get a link to share it. The note is encrypted in your browser with AES-256-GCM and travels inside the link; nothing is stored.

**Use this tool:** [Secure Note Sharing](https://findutils.com/security/secure-note-sharing/)

## Programmatic access

- Browser-only: this tool works on a file, the DOM, or a browser API and has no REST or MCP id.

## Why share a note this way?

Pasting a password or an API key straight into chat or email leaves it readable in that thread for as long as the thread exists. This tool encrypts the note in your browser with AES-256-GCM and puts the encrypted note inside the link, after the # sign. Browsers do not send that part of a link to any server, so the note is never uploaded and nothing is stored. Add a password and the link alone is no longer enough to read it. The honest limit: because nothing is stored, a link cannot expire or delete itself after reading. It works for as long as someone has it.

## Tips

- Use a password for anything sensitive, and send it through a different channel from the link.
- Send the whole link. If a chat app cuts it short, the note will not open; send it as a file or in a different app.
- The link cannot be revoked. Rotate a password or key you shared once it has been used, rather than relying on the link going away.
- Anything that stores the link, such as a chat history or browser history on the sender's side, keeps a copy that can open the note.
- Use a long, random password; the Password Generator can make one.

## Frequently Asked Questions

### How is the note encrypted?

In your browser, with AES-256-GCM. With no password, a random 256-bit key is generated and put in the link after the # sign together with the encrypted note. With a password, the key is derived from it with PBKDF2-SHA-256 at 600,000 iterations and a random salt, and the key is not in the link.

### Is the note stored anywhere?

No. The encrypted note is inside the link itself. It is not uploaded to a server and not saved in your browser's storage. Browsers do not send the part of a link after # to any server, and it is not included in the Referer header.

### Who can read the note?

Anyone who has the full link, if you set no password. If you set a password, they need both the full link and the password. This is zero-knowledge only in that precise sense: the site never receives the note or the key.

### Can I delete a note?

No. Nothing is stored, so there is nothing to delete, and a link keeps working for as long as someone has it. To keep a note private, do not share the link, or share it only with a password and send the password another way.

### Does the note expire or self-destruct after reading?

No. Expiry and burn-after-reading need a server that holds the note and can delete it, and this tool stores nothing. The recipient can open the note as many times as they like with the same link.

### Why is a note link so long?

Because the whole encrypted note is inside it. The link grows with the note: the encryption adds a fixed overhead, and the encrypted bytes are written as base64url text, which takes about four characters for every three bytes. A link with no password also carries the 256-bit key.

### How long can a note be?

Up to 4,000 characters. The limit keeps the link short enough to paste into chat apps and email. For longer text, use the Text Encryption tool and share the result another way.

### What happens if the password is wrong or the link is cut short?

The note does not open. AES-GCM checks the data while decrypting, so a wrong password or any missing or changed character fails with an error instead of producing garbled text. Ask the sender to check the password or send the full link again.

### Why does the part after # disappear when I open a note?

After the note is revealed, the page removes the fragment from the address bar so the key is not left sitting in the open tab. The note stays on screen until you hide it or leave the page. The link in the original message still works.

### Is it safe to send the link and the password together?

No. Anyone who sees that one message could open the note. Send the link one way and the password another, for example the link by email and the password by phone.

## Related Tools

- [Text Encryption](https://findutils.com/security/text-encryption/)
- [RSA Encryption Tool (PEM)](https://findutils.com/security/pgp-encryption-tool/)
- [Password Generator](https://findutils.com/security/password-generator/)
- [Password Strength Checker](https://findutils.com/security/password-strength-checker/)
- [Random Key Generator](https://findutils.com/security/random-key-generator/)
- [Hash Comparison Tool](https://findutils.com/security/hash-comparison-tool/)
