One-time secret tools
Open-source burn-after-reading services you can self-host, ideal for teams with compliance rules.
Independent guide
Privnote lets you write a note, share one link, and have the message erase itself the moment it is read. This guide explains the encryption model, the real security limits, and when a different tool serves you better.
Privnote is a free web service for sending messages that destroy themselves after being read once. You type text into a box, press a button, and receive a unique URL. Whoever opens that URL sees the note once; after that the link is dead for everybody, including you.
There is no registration, no inbox, and no message history. The service is designed for the short-lived secret: a Wi-Fi password, a recovery code, a bank detail, a private sentence you do not want sitting in a chat log forever.
Read also:Privnote security: how safe are self-destructing notes?How to use Privnote: step-by-step tutorial with options explained
The note text is encrypted in your browser and the decryption key lives in the part of the link after the # symbol, which browsers never send to the server. That means the server stores ciphertext it cannot read on its own. This is a genuinely strong design.
The weak point is never the maths — it is the link. Anyone who obtains the URL can read the note, so the transport channel matters. Sending a Privnote link over the same messenger you were trying to avoid logging gains you very little. Add a password and share it through a second channel.
Be aware of phishing clones: many look-alike domains copy the Privnote interface and quietly keep a copy of your note. Always check the address bar before pasting anything sensitive.
Read also:Best Privnote alternatives for one-time secrets in 2026Privnote password protection: when a password is worth it
Open the site and type your message into the text area. Plain text only.
Optionally add a password, choose an expiry window and request an email when it is read.
Press create. A unique URL appears — copy it immediately, it is shown only once.
Send the link and any password through two different channels, then confirm it was read.
How to use Privnote: step-by-step tutorial with options explained
Best Privnote alternatives for one-time secrets in 2026
Open-source burn-after-reading services you can self-host, ideal for teams with compliance rules.
Secure sharing built into 1Password or Bitwarden gives you audit logs and revocation.
Signal with disappearing messages covers ongoing conversations rather than one-off secrets.
For documents rather than text, use a service with end-to-end encrypted uploads and expiry.
Eight in-depth Privnote articles: security, passwords, phishing clones, team usage, troubleshooting and alternatives.
A technical but readable audit of the Privnote encryption model, the threats it stops, and the three ways a Privnote link still leaks.
Read article →TutorialEvery Privnote option in order, from writing the note to confirming the read receipt, with the settings most people forget to switch on.
Read article →ComparisonWhen Privnote is not the right fit — file support, audit logs, compliance — these are the alternatives that solve each specific gap.
Read article →SecurityThe Privnote password field is optional — here is when it turns a convenient link into real protection.
Read article →SecurityPrivnote clones do not break encryption — they simply ask you to type the secret into their own server.
Read article →BusinessPrivnote is a great handoff tool and a poor system of record. Knowing the difference keeps audits calm.
Read article →TroubleshootingMost Privnote failures are not bugs — something opened the note before your recipient did.
Read article →PrivacyPrivnote hides the content of a note. Anonymity is a separate property, and it is not guaranteed.
Read article →No. The first successful open destroys the note. If a recipient says the link is dead, assume someone or something opened it before them.
No. Deletion is permanent by design and no copy is kept, so always keep your own record of anything you still need.
No. Encryption and decryption happen in the browser, so JavaScript must be enabled on both ends.
Yes, the core service is free to use in most countries; you remain responsible for the content you send.
Chat apps, mail scanners and antivirus tools often pre-fetch links to build previews, and that counts as the single read.
Privnote password protection: when a password is worth itPrivnote not working: link expired, blank page and other fixesIs Privnote anonymous? Privacy, logs and legal reality