Skip to content

Our Security Model

Security is the entire point of SneakNote, so we believe you deserve a straight explanation of how it works, what we can see, and what we deliberately cannot. No marketing fog, just the model.

End-to-End Encryption

Your note is encrypted in your browser before it is ever sent to our servers. The decryption key lives in the link fragment, the part of the URL after the # symbol, which browsers never transmit to the server. That means we store ciphertext we cannot read, and only someone with the full link can decrypt the note.

One-Time Access and Self-Destruction

Notes are designed to be read once. After a note is opened, or after its expiration timer elapses, the encrypted record is permanently deleted from our database. There is no archive, no trash, and no recovery path, by design. If a note is gone, it is gone for everyone, including us.

Optional Password Protection

You can add a password that the recipient must enter before the note can be decrypted. This protects the contents even if the link is intercepted, an extra layer on top of the encryption key in the URL. We never store this password.

What We Do Not Do

  • We do not store the plaintext of your notes.
  • We do not require an account or collect personal profiles to send a note.
  • We do not retain notes after they are read or expired.
  • We do not sell your data.

Responsible Disclosure

No system is perfect, and we welcome scrutiny. If you believe you have found a security issue, please report it so we can address it quickly. You can review our broader privacy commitments in our Privacy Policy.

Want the Plain-Language Version?

For a less technical walkthrough, see how end-to-end encryption works and whether SneakNote is safe.

Create a Secure Note Now

No sign-up required. Encrypted in your browser, deleted after reading.

Create a Private Note

Automatically send the note via email

Add an extra layer of security with a password

Get notified when the note is read

Choose when the note will be destroyed