Mission briefing
How it works
Self Destruct Note is built so that we can't read your messages, even if we wanted to. Here's how, in plain English.
- You write a note. Your browser scrambles (encrypts) it with a brand-new random key before anything leaves your device.
- We store only the scrambled version. To us it looks like random gibberish. We never receive the key.
- The key rides in the link, after the #. Browsers never send the part of a link after "#" to a website's server. So the person with the link has the key, and we don't.
- The reader taps "Reveal". Only then do we hand over the scrambled note and delete it from our database in the same instant. Their browser unscrambles it on their screen.
- It burns. The note is already gone from our servers. The countdown and fire are the fun part.
Why there's a "Reveal" button
Apps like iMessage, Slack, WhatsApp and many email systems open links automatically to build previews or check for viruses. If opening the link burned the note, a robot would "read" it before your friend did. So opening the link is safe. The note only burns when a human taps Reveal.
Truly one-time
Handing over a note and deleting it happen as a single database operation. If two people somehow tap Reveal at the same moment, exactly one of them gets it. The other sees "this message doesn't exist."
Passwords (optional)
Add a password and it gets mixed into the encryption key, so the link alone isn't enough. Send the password a different way than the link. After 5 wrong guesses, the note destroys itself.
Your private status link
When you create a note you also get a status link, just for you. It tells you whether the note has been read, and lets you destroy it early. It never shows the message, and no account is needed.
Honest limits
- The link is the key. Whoever opens it first reads it. Send it to one person, through a channel you trust. Whatever app you send it with (text, email, WhatsApp…) carries the key, so it's only as private as that app.
- Our host sees normal web traffic. Like every website, our host (Cloudflare) sees visitors' IP addresses and when requests happen. It never sees the part of the link after the "#", so it can't read notes either.
- Screens can be captured. The reader can always take a screenshot or a photo. Self-destructing doesn't stop that.
- You're trusting this website's code to do the encryption properly, the same as with any web-based tool. The code runs in your browser and anyone can inspect it.
- Unread notes don't last forever. They're destroyed after the expiry you chose (30 days at most).
Technical details, for the curious: AES-256-GCM via the browser's built-in Web Crypto API. A 256-bit random key per note. Optional passwords are stretched with PBKDF2-SHA-256 (310,000 rounds) and combined with the key using HKDF. The server stores the ciphertext, a hash of a key-derived check value, and unencrypted metadata (created/expiry times and whether a password is set). The note is only released to someone who can produce the check value, so a mangled link never burns a note; a password note burns after 5 wrong guesses. Status tokens are stored as SHA-256 hashes; rate-limit counters use a keyed hash of the IP and expire hourly.