# Private note sharing compared: Privnote, Doppler Share, Enclosed, PrivateBin, Yopass, and more (2026)

> We checked seven self-destructing note tools against their docs, code, and live pages: who encrypts in the browser, who can read your notes, limits, and APIs.

Source: https://evergist.com/blog/private-note-sharing-compared/
Published: 2026-09-29

If you need to send someone a password or an API key, a self-destructing note beats pasting it into chat. But these services differ a lot in one question that matters more than any feature: **can the operator read what you send?**

We looked at seven popular options plus our own. For each one we read the service's own documentation, its source code where it's public, and its live pages and JavaScript. Everything below was checked on September 29, 2026. Where we couldn't confirm something from a primary source, we say so.

Full disclosure: we make Evergist, one of the tools in this comparison. We've tried to be fair, and we point out where other tools are the better choice.

## The quick answer

- **The operator can't read your notes** with Privnote (per its policy), Doppler Share's web app, Enclosed, PrivateBin, Yopass, and Evergist. All of them encrypt in the browser and keep the key out of the server's reach.
- **The operator can technically read your notes** with Jotary, which says so plainly, and Onetime Secret, which encrypts on the server.
- **Want to self-host?** PrivateBin, Yopass, Enclosed, and Onetime Secret are open source.
- **Need to share files?** Enclosed, PrivateBin, and Yopass support attachments.
- **Building with AI agents?** Evergist is the only one we found with an MCP server. Jotary, Doppler, and Onetime Secret have REST APIs. Enclosed and Yopass have CLIs.

## Comparison table

| | Encrypts in browser | Operator can read? | Open source | Expiry | View limit | Password | API / CLI / MCP |
|---|---|---|---|---|---|---|---|
| **Privnote** | Yes, per its policy | No, per its policy | No | 1h to 30d | Burn after reading | Yes | None found |
| **Doppler Share** | Yes (web) | No (web). Its Slack app and plaintext API encrypt server-side | No | 1 day to 3 months | 1 to 50, or unlimited | Generated passphrase, can be sent separately | REST API, Slack app |
| **Enclosed** | Yes | No | Yes, Apache-2.0 | 1h to 1 month, or never | Burn after reading | Yes | CLI |
| **Jotary** | No | Yes | No | 10 min to 1 year | 1, 5, 25, or unlimited | Yes, as an access gate | REST API |
| **Onetime Secret** | No, server-side | Yes, technically | Yes, MIT | 7 to 30 days by plan | 1 | Yes | REST API |
| **PrivateBin** | Yes | No | Yes, Zlib | 5 min to 3 days on privatebin.net | Burn after reading | Yes | JSON API |
| **Yopass** | Yes | No | Yes, Apache-2.0 | 1h, 1d, 1w | One-time | Yes | CLI |
| **Evergist** | Yes | No | Not yet | 10 min to 30 days | 1 to 1,000, or none | Yes, mixed into the key | REST API, CLI, MCP, SKILL.md |

## Service by service

### Privnote

The original burn-after-reading site. Privnote says the link is generated in your browser, the decryption key exists only in the link, and "nobody (including Privnote's administrators) can read a note." It offers optional passwords, expiry options, and email read notifications. Unread notes are deleted after 30 days.

Two caveats. Privnote's privacy policy says it uses non-functional cookies placed by third parties for advertising. And there's no public source or published cipher, so the encryption claims can't be verified independently. There's no API.

Sources: [privacy policy](https://privnote.com/info/privacy), [FAQ](https://privnote.com/info/faq).

### Doppler Share

Doppler's free sharing tool is well engineered. The browser generates a random 64-character passphrase, derives an AES-GCM key with PBKDF2-SHA256, and sends only the ciphertext and a hash of the passphrase. The passphrase goes in the URL fragment, or you can leave it out of the link and send it separately. The live code runs PBKDF2 at 1,000,000 iterations, higher than the 100,000 its docs mention. You can allow 1 to 50 views, or unlimited, and expiry up to three months.

The catch: the Slack app and the `POST /v1/share/secrets/plain` API endpoint encrypt on Doppler's side, and Doppler documents that. The web app is end-to-end encrypted. Those two paths aren't. The page loaded no third-party trackers when we checked.

Sources: [share security docs](https://docs.doppler.com/docs/share-security), [API reference](https://docs.doppler.com/reference/share-secret).

### Enclosed

An open source (Apache-2.0) app that's easy to self-host with Docker or on Cloudflare. The browser generates a base key, combines it with an optional password through PBKDF2-SHA256, and encrypts with AES-GCM. The key lives in the URL fragment. Enclosed supports file attachments, expiry, and delete after reading, and has a CLI. The self-hosted default size limit is 50 MB. We found no analytics in its bundle.

If you want to run your own instance or share files, Enclosed is a strong pick.

Sources: [GitHub](https://github.com/CorentinTh/enclosed), [configuration docs](https://docs.enclosed.cc/self-hosting/configuration).

### Jotary

Jotary is a pastebin built for agents, with a clean REST API, `llms.txt`, and an agents page. It's not a secret-sharing tool, and to its credit it says so. Its privacy policy: "Password protection is an access gate, not content encryption. The jot's content itself is not encrypted at rest," and it asks users not to put passwords or credentials in jots. Limits are 512 KB and 10 creates per hour per IP. No trackers, no accounts.

Good for non-sensitive text you want an agent to share. Not for secrets.

Sources: [privacy policy](https://jotary.com/privacy), [API](https://jotary.com/api).

### Onetime Secret

A long-running open source (MIT) project with a hosted service and paid plans. Encryption happens on the server, with keys derived from the server's own secret. The project's own July 2026 audit document says new secrets use XChaCha20-Poly1305 and that the passphrase is "not a KDF input", meaning it works as an access check rather than part of the encryption key. That contradicts an older line in its About FAQ. The practical upshot: the operator can decrypt in principle. Anonymous secrets last 7 days with a 100 KB limit, and paid plans go to 30 days.

Sources: [encryption audit](https://github.com/onetimesecret/onetimesecret/blob/main/docs/architecture/encryption-at-rest-dpa-audit.md), [pricing](https://onetimesecret.com/en/pricing).

### PrivateBin

The veteran of zero-knowledge pastebins. PrivateBin encrypts in the browser with AES-256-GCM, puts the key in the URL fragment, and mixes an optional password in with PBKDF2. It supports burn after reading, discussions, and file attachments, and it's easy to self-host with PHP. The public privatebin.net instance loads only local scripts.

Its README is refreshingly honest that you have to trust the server admin not to serve malicious JavaScript, which is true of every browser-based tool on this list, including ours.

Sources: [GitHub](https://github.com/PrivateBin/PrivateBin), [encryption format](https://github.com/PrivateBin/PrivateBin/wiki/Encryption-format).

### Yopass

An Apache-2.0 project that encrypts with OpenPGP in the browser. The key goes in the link or can be sent separately. Expiry is one hour, one day, or one week, and secrets are one-time by default. There's a CLI, and larger files and SSO come with a paid license. The demo app at share.yopass.se loads no trackers, but the marketing site loads Google Analytics, which its privacy policy acknowledges.

Sources: [GitHub](https://github.com/jhaals/yopass), [privacy policy](https://yopass.se/privacy).

### Evergist

Our tool. It encrypts in the browser with AES-256-GCM and keeps the 256-bit key in the URL fragment. The server also requires a token derived from the key before it releases ciphertext, so someone who only knows a note's ID can't download it or burn its views. Passwords go through PBKDF2 (600,000 iterations) into the key itself, and 10 wrong passwords delete the note. Notes can be up to 512 KiB of text, last 10 minutes to 30 days, and allow 1 to 1,000 views.

What's different is the agent tooling: a [local MCP server](https://evergist.com/agents/#mcp-server) that runs through `npx` with no install, a CLI, a SKILL.md, and a [REST API](https://evergist.com/docs/api/). There are no cookies, no analytics, and no request logs. We keep three public daily counters.

Where it falls short today: no file attachments, and the source isn't public yet, so you can't self-host it. The [security page](https://evergist.com/security/) documents the full scheme and includes an independent Python script that decrypts notes without our code.

## How to choose

1. **If the content is a real secret,** rule out anything that encrypts on the server. That leaves Privnote, Doppler Share (web), Enclosed, PrivateBin, Yopass, and Evergist.
2. **If you must control the server,** self-host PrivateBin, Enclosed, or Yopass.
3. **If you share files,** use Enclosed or PrivateBin.
4. **If agents are doing the sharing,** use a tool that encrypts on the agent's machine. Evergist's MCP server and CLI do that. So do Enclosed's and Yopass's CLIs.
5. **Whatever you use,** set one view and a short expiry for credentials, and send any password through a different channel than the link.

## Methodology

We checked each service's documentation, privacy policy, source repository where available, and the HTML and JavaScript served by its live site on September 29, 2026. Where a service's docs and code disagreed, we reported what the code does and noted the difference. If anything here is out of date, email [contact@evergist.com](mailto:contact@evergist.com) and we'll correct it.