privnofe.com encrypts every message directly in your browser before it ever touches our servers — meaning we have no technical ability to read what you send. Once your recipient opens the link, the message self-destructs permanently, leaving no trace behind.
Five precise steps. Zero compromises. Your message is encrypted before it leaves your device and destroyed the moment it is read.
Write your secret message
Type your sensitive message directly into the browser editor. Before anything leaves your device, privnofe.com encrypts the text client-side using AES-256. Your plaintext never touches our servers — only the ciphertext is transmitted.
Set your security options
Customise how and when your note expires. Choose a time window from one hour up to seven days, add an optional passphrase that the recipient must enter before decrypting, and enable email delivery notification so you know when your message has been read.
Get your one-time URL
Click 'Create Secret Note' and privnofe.com instantly generates a unique, single-use URL. The decryption key lives only in the URL fragment — cryptographically tied to your message. The link is copied to your clipboard automatically.
Send through any channel
Paste the link into any messaging platform — email, Slack, WhatsApp, SMS, or a secure messenger. privnofe.com is channel-agnostic. Even if the channel is compromised, the message itself remains encrypted until the recipient opens it.
Read once. Gone forever.
When the recipient opens the link, the note is decrypted in their browser and displayed. The moment it is rendered, privnofe.com permanently deletes the ciphertext from our servers. A second visit returns nothing — the message is cryptographically erased.
No account required. No logs. It takes under 30 seconds.
This is not a marketing claim. Below is a factual description of the cryptographic model and server policies that protect every note on privnofe.com.
Authenticated encryption with 256-bit keys. Provides both confidentiality and integrity verification, detecting any tampering before decryption.
Encryption keys are generated and held exclusively in the sender's browser using the Web Crypto API. Keys are never transmitted to our servers under any circumstances.
privnofe.com servers store only the encrypted blob. Without the key — which only exists in the URL fragment — the stored data is computationally indistinguishable from random bytes.
All client-server communication is encrypted in transit. We enforce HTTPS-only access and use HSTS headers to prevent downgrade attacks.
No cookies, no analytics, no session identifiers are attached to note creation or retrieval requests. Note content is never associated with any user identity.
Upon first successful retrieval of a note, the ciphertext is immediately and permanently deleted from the server. No backup copies are retained.
The decryption key is passed as a URL fragment (#key=…). Fragments are never sent to the server by any browser — this is a defined property of the HTTP specification.
Server cannot read your note
The server only ever receives and stores an encrypted blob. The decryption key never reaches the server. Even if our infrastructure were fully compromised, an attacker would obtain only ciphertext — indecipherable without the key that only the sender shared via the link.
Honest answers about how privnofe.com works, what we can and cannot see, and what happens to your data.
No. Notes are encrypted client-side before they ever leave your browser. The encryption key is embedded in the URL fragment — the part after the # — which is never sent to our servers. This means our servers store only ciphertext. Even if we wanted to read your note, we technically cannot.
If the recipient never opens the link, the note stays on our servers until its expiry time is reached — the default is 7 days. Once that window closes, the encrypted data is automatically and permanently deleted. No one, including us, can retrieve it after deletion.
The note is destroyed when the expiry time elapses, whether or not it has been read. The recipient will see a clear message stating that the note no longer exists. This is intentional: expiry is a hard deadline, not a suggestion. Pro users can extend expiry up to 30 days.
Free accounts can send notes up to 10 KB of plaintext — roughly 10,000 characters, which covers most sensitive messages, credentials, and short instructions. Pro accounts raise that ceiling to 500 KB, suitable for longer documents, configuration files, or multi-step instructions.
Yes — if the note has not yet been opened. When you create a note, you receive a unique deletion token along with the share link. Use that token via your dashboard or the deletion URL to permanently destroy the note before anyone reads it. Once the note has been opened and self-destructed, the deletion token becomes void.
Pro unlocks: extended expiry windows (up to 30 days), larger note sizes (up to 500 KB), optional passphrase protection as an additional authentication layer, read receipts so you know when a note was opened, custom expiry per note, and full REST API access for programmatic integration. All Pro notes benefit from the same zero-knowledge encryption as free notes.
Yes. Pro subscribers get access to our RESTful API, which lets you create, check, and delete notes programmatically. The API uses standard HTTPS with bearer-token authentication. Client-side encryption libraries are provided in JavaScript, Python, and Go so you can maintain zero-knowledge guarantees in your own applications. Full documentation is available in the developer portal after signing in.
Yes. We are designed with privacy-by-default principles that align tightly with GDPR requirements. We collect only the minimum data necessary to operate the service (an anonymous session identifier and encrypted note ciphertext). We do not sell, share, or process personal data for advertising. Notes are deleted on schedule without manual intervention. Our infrastructure is hosted in EU data centres. A Data Processing Agreement (DPA) is available for Pro customers upon request.
Still have questions? Our team responds within one business day.
Send a secret. It self-destructs after being read. End-to-end encrypted, zero-knowledge, no traces left behind.
© 2026 privnofe.com. All rights reserved.