Creating and sharing a private note takes just three steps.
1. Write
Type your confidential message. No account or registration required.
2. Encrypt
Your message is encrypted with AES-256 in your browser. Only the ciphertext is sent — the key stays in the link and never reaches us.
3. Share
Send the link to the recipient. The note is deleted automatically after reading.
Zero-Knowledge, Ephemeral Messaging
Share sensitive information safely and privately. Your note is encrypted in your browser with AES-256 before it is sent — we only ever store ciphertext we cannot read (zero-knowledge). It can be viewed only once by the recipient.
How to Create a Private Note
Write your message, click Create, and share the generated link with your recipient. The decryption key is part of the link, so keep it private. Once the note is opened, it is permanently deleted and cannot be viewed again.
Why Use This Tool?
Every note is encrypted in your browser and deleted immediately after reading. The decryption key travels only in the link and never reaches our servers, so we cannot read your notes. No registration required.
Looking for a Privnote alternative? You are not alone. After Krebs on Security exposed multiple Privnote phishing clones in 2024, plus growing GDPR concerns about US-hosted note services, more people are evaluating their options. Here is an honest comparison of the four most popular self-destructing note services in 2026.
Quick Answer
All four services can send a note that disappears after reading. They differ in whether encryption happens in your browser, whether they require an account, and where the servers are located. Privacy Share encrypts notes in your browser (zero-knowledge) — the key never reaches the server — and combines that with optional OTP email verification of the recipient, no account requirement, and German hosting.
Comparison Table
Feature
Privacy Share
Privnote
OneTimeSecret
Bitwarden Send
Free
✓
✓
✓
✓ (basic)
Zero-knowledge (in-browser) encryption
✓ (client-side, closed source)
✓ (client-side, closed source)
✓ (open source)
✓ (open source)
OTP email verification of recipient
✓
✗
✗
✗
No account required
✓
✓
✓
✗
Auto-delete after read
✓
✓
✓
Configurable
Set expiration time
10 min – 30 days
~30 days
Configurable
1h–30 days
File attachments
✗
✗
Limited
✓
Server location
Germany (EU)
Not publicly disclosed
Self-host or hosted
US or EU region
Data verified: July 2026. Competitor pricing and features may have changed since — always check the provider's current site.
Privnote
Best for:
Quick, low-stakes notes when convenience matters more than verifiable architecture.
Watch out for:
Privnote publicly describes a client-side encryption model (the key stays in the link), but like most such tools it is closed-source, so that model cannot be independently verified. The bigger real-world risk is impersonation: phishing clones (privnote.online, privnote.net, and dozens more) have been documented since 2024 by Krebs on Security. Always verify you are on privnote.com exactly.
OneTimeSecret
Best for:
Privacy-conscious users who want open-source software they can audit, contribute to, or self-host.
Watch out for:
There is no built-in way to verify the recipient — anyone with the link can read the message. Self-hosting is the recommended path for sensitive use cases.
Bitwarden Send
Best for:
People already using Bitwarden's password manager.
Watch out for:
You need a Bitwarden account to create a Send. That is friction in the classic use case ("I need to share one secret with one person, right now"). The recipient does not need an account — but you do.
Privacy Share
Best for:
Sending sensitive credentials, secrets, or confidential text with zero-knowledge encryption (done in your browser, so we can't read it) plus proof the right person opened it via optional OTP email verification — without forcing anyone to create an account. Hosted on servers in Germany; the note itself stores no personal data — no plaintext (zero-knowledge) and no email (with OTP, the address is used once to send the code, then discarded).
Tradeoff:
No file attachments. Text-only by design.
GDPR considerations for EU users
For EU users — especially in B2B contexts — GDPR compliance is often decisive:
Privacy Share:Servers in Friedersdorf, Germany (host: ALL-INKL.COM). The note itself stores no personal data — no plaintext (zero-knowledge) and no email even with OTP (used once to send the code, then discarded). Like any website, standard server logs briefly contain IP addresses.
OneTimeSecret:Open-source and fully controllable when self-hosted in the EU. For the hosted service, check its current data location before relying on it.
Bitwarden Send:Bitwarden offers a US or EU data region, chosen at signup. Selecting the EU region keeps data in the EU; the US region typically requires Standard Contractual Clauses (SCC) for EU personal data.
Privnote:Server locations are not publicly disclosed, which makes a GDPR impact assessment difficult upfront.
Which one should you use?
Sharing a password with a friend or family member?Privnote works for low-stakes cases. Privacy Share's optional OTP gives you confirmation the right person opened it.
Sharing internal company secrets?OneTimeSecret if you self-host; Privacy Share if you do not want to maintain infrastructure.
Sharing files in addition to text?Bitwarden Send (account required) or use a dedicated file-transfer tool.
Need to evaluate against compliance or audit requirements?Open-source tools (OneTimeSecret, Bitwarden Send) let you or your security team review the actual implementation. Tools without published technical details are difficult to assess.
GDPR-regulated data (EU)?Privacy Share (Germany) or self-hosted OneTimeSecret in the EU. Tools hosted or routed through the US typically require additional contractual safeguards.
Frequently Asked Questions
Is Privnote actually safe?
Privnote has been operating since 2008 and is widely used. It publicly describes a client-side encryption model where the key stays in the link, so its servers are not able to read the note. Like most such services — including this one — it is closed-source, so that model cannot be independently verified; you are trusting the operator either way. In practice the more common risk is fake "Privnote" clone sites, so always check the exact address.
Can a self-destructing note be recovered after reading?
With tools that document zero-knowledge encryption (Privacy Share, OneTimeSecret, Bitwarden Send), the note and its key are designed to be destroyed on read. With any tool, encrypted blobs may temporarily exist in backups depending on the operator's data-retention policy.
What is the actual difference between Privacy Share and Privnote?
On encryption they are similar: both encrypt the note in your browser with the key in the link, and both are closed-source. The concrete differences are operational — Privacy Share is run from Germany with a full legal imprint and under the GDPR, offers optional OTP email verification of the recipient, and is available in German. Whether that matters depends on whether an identifiable EU operator and recipient verification are important for your use case.
Do I need JavaScript to read a Privacy Share note?
Yes. Because encryption and decryption happen in your browser (that is what makes it zero-knowledge), reading a note requires JavaScript. This is the same tradeoff other client-side-encrypted tools make.
Why does Privacy Share ask for an email when I enable OTP?
Only when you toggle OTP on. The email address is used once to send a 6-digit verification code to your recipient and is not stored afterwards. The default mode requires no email at all.
Are these tools GDPR-compliant?
Privacy Share is hosted in Germany, and the note itself stores no personal data — the content is encrypted in your browser and the email is never kept — which simplifies GDPR compliance for EU senders. As with any website, standard server logs briefly contain IP addresses. OneTimeSecret can be self-hosted in any region. Bitwarden offers a US or EU data region chosen at signup; the EU region keeps data in the EU, while the US region typically requires additional safeguards for EU personal data. For Privnote, server locations are not publicly disclosed, which makes GDPR impact assessments more difficult.
What happens if someone screenshots the note before it self-destructs?
No self-destructing tool can prevent screenshots — Privnote, OneTimeSecret, Bitwarden Send and Privacy Share all share this limitation. If screenshot risk is critical, deliver the secret in person or via a managed secrets vault, not a note tool.
What is Privnote?
Privnote (privnote.com, running since 2008) is a web service for creating notes that self-delete after being read — the link carries the key, and the note disappears once opened. Privacy Share offers the same core principle plus optional OTP recipient verification, a German-language interface, and hosting in Germany.
Can I send a secure note over WhatsApp?
Yes. Create the note here, copy the generated link, and send it over WhatsApp, Signal, email or any messenger. The recipient opens the link, the note is decrypted in their browser and deleted after reading — so the content does not stay in the chat history.