← RESOURCES
RESOURCES · SN

Flowridium Secure Note

Share a password, API key or sensitive note with a link that works exactly once. Everything is encrypted right here in your browser before it leaves your machine—our server only ever stores scrambled bytes, and the decryption key never touches it at all.

No account, no email address, nothing to sign up for. Write your note, get a link, send it however you like. The moment someone opens it, it's gone for good—and there's no way for us to recover it, because we never had it to begin with.

Expires after
Whichever comes first: being read once, or this expiry.

How it works

  1. Write your note. It's encrypted right here in your browser, using a random 256-bit key generated on your device with the Web Crypto API—the same cryptography API built into every modern browser.
  2. Only the encrypted bytes get sent. Our server stores that encrypted blob against a random ID. It never sees your note, and it never sees the key.
  3. You get one link. The random ID and the decryption key are both in it—but the key sits after the #, in the URL fragment, which browsers never send to any server. It only ever exists on devices that have the link.
  4. Send it however you like. Chat, email, a ticket—wherever. Whoever opens it decrypts the note locally, in their own browser.
  5. One read, then gone. The moment the note is fetched, it's deleted from the server in the same operation—there's no way to read it twice, by us or anyone else. Anything never read is deleted automatically once it expires.

The zero-knowledge details

  • Client-side encryption only. Encryption and decryption both happen in your browser via crypto.subtle, using AES-256-GCM. Plaintext never reaches our server in either direction.
  • Atomic read-then-delete. Fetching a note and deleting it happen as a single database operation, so two people can't both load the same link a moment apart—whoever gets there first gets the only read.
  • Expiry cleanup runs separately. Notes that are never opened are deleted automatically once their expiry passes, on their own schedule, not by anyone requesting them.
  • Minimal logging. We don't log which IP address requested which note ID—there's no record linking a reader back to a specific note.
  • Built to be self-hosted. This tool is being open-sourced as its own standalone project so anyone can run it themselves. The version here is our own hosted instance of it.

Limits and terms

  • Notes can be up to 20,000 characters, and can be set to expire after 1 hour, 1 day, 3 days or 7 days.
  • A note is deleted the moment it's read, or at its expiry—whichever happens first.
  • There is no recovery. Once a note is deleted, it's gone—we can't retrieve it, restore it, or tell you what it said. We can't recover a lost link either, since the decryption key was never ours to have.
  • We can't access the contents of any note, read or unread, at any point—there's nothing stored on our server that we could decrypt even if asked to.
  • Don't use this for anything you're not comfortable losing if the link goes to the wrong person before they read it—treat the link itself as the secret.

For developers

  • POST /api/notes—create a note. Body: { "ciphertext": "<base64url>", "ttl_seconds": 3600 }. Returns { "id": "<note id>" }.
  • GET /api/notes/{id}—fetch and permanently delete a note in one step. Returns { "ciphertext": "<base64url>" }, or a 404 if it's already been read, expired, or never existed.
  • GET /api/notes/{id}/exists—check whether a note is still unread, without consuming it. Returns { "exists": true } or { "exists": false }.

This tool is being open-sourced as a standalone, self-hostable project—once the repository is public, a link will replace this note.

Flowridium Ltd · Company registration number 17392408 · VAT number 527 3323 04 · Registered address: 3 High Ridge Close, Arundel, BN18 9ES Privacy Policy