Four simple steps to secure note sharing
Think of any memorable word or phrase. This is your encryption key. Only people who know this codeword can access your notes.
Click "Open" to enter your encrypted vault. Your browser generates a unique encryption key from your codeword using PBKDF2.
Type your notes, paste images, or upload files. Everything is encrypted using AES-256-GCM on your device. Changes auto-save every 2 seconds.
Send your codeword to others via any channel (email, messaging, in-person). They enter the same codeword and see your notes in real-time.
Yes. Everything is encrypted with AES-256-GCM before leaving your browser. The server never has access to your codeword or plaintext. We physically cannot decrypt your data.
There's no "forgot password" recovery. Your codeword is your encryption key. If you forget it, your vault is permanently inaccessible (by design—this is security). Write it down or use a password manager.
Theoretically yes, but with 600,000 PBKDF2 iterations, a brute-force attack would take centuries. Use a strong, unique codeword (e.g., "BlueMountainVibes2026Jan17") instead of simple words.
Indefinitely, unless you manually delete the vault. We don't have a retention policy. Your encrypted data stays on our servers until you delete it.
No. We have zero knowledge of your plaintext. Your codeword is never sent to us. All encryption happens client-side. It's cryptographically impossible for us to read your data.
Yes! Our source code is available on GitHub. You can audit the encryption implementation, deploy it yourself, or verify our claims.
Yes. EncodeNote is a Progressive Web App. Install it on your home screen and it works offline. Background sync queues changes when you reconnect.
Completely free. Forever. No ads, no premium tier, no hidden costs. We believe secure communication should be accessible to everyone.