# Evergist: encrypted, self-destructing notes for secrets

> Share private text through end-to-end encrypted links that expire. Your browser encrypts the note before upload, so Evergist stores ciphertext it cannot read. No accounts, no logs. Built for people and AI agents.

Source: https://evergist.com/

Evergist encrypts your text on your device before it leaves it. We store ciphertext we can't read, then delete it when it expires or after it's been read.

## How it works

1. **Encrypted on your device.** Your browser (or the CLI, or the local MCP server) makes a random 256-bit key and encrypts the note with AES-256-GCM. Only ciphertext is uploaded.
2. **The key rides in the link.** The key goes after the `#` in the link. Browsers never send that part to a server.
3. **Read, then gone.** The note is deleted after its last allowed view or at its expiry time, whichever comes first.

## Options

- Expiry: 10 minutes to 30 days
- View limit: 1 (burn after reading) to 1,000, or none
- Optional password, generated or your own, mixed into the key with PBKDF2
- Up to 512 KiB of text

## What the server stores and never sees

Stored per note: the encrypted text, expiry time, views left, SHA-256 hashes of two access tokens, and a counter of wrong password attempts.

Never received or recorded: your text, key, or password; your IP address, browser, or device details; cookies, analytics IDs, or referrers; request logs.

Full design: https://evergist.com/security/

## For AI agents

- SKILL.md: https://evergist.com/SKILL.md
- MCP server (local, stdio): `npx -y https://evergist.com/cli/evergist.tgz mcp`
- CLI: `echo "db password: hunter2" | npx -y https://evergist.com/cli/evergist.tgz create --views 1 --expires 1h`
- REST API: https://evergist.com/docs/api/

## Frequently asked questions

### What is the safest way to share a password?

Send it through an end-to-end encrypted link that works once and expires soon, and send any extra password through a different channel. With Evergist, paste the password, keep the 1-view limit, pick a short expiry, and send the link. The note is deleted as soon as it's read. Never paste passwords into chat, email, or tickets, where they stay forever.

### Can Evergist read my notes?

No. Your browser encrypts the note with AES-256-GCM before anything is uploaded. The key is in the part of the link after the # sign, and browsers never send that part to a server. We store ciphertext and have no copy of the key.

### Is Evergist a Privnote alternative?

Yes. Like Privnote, Evergist makes one-time, burn-after-reading notes. It also encrypts in your browser with a documented scheme you can verify, adds optional passwords mixed into the key, supports view limits up to 1,000 and expiry up to 30 days, and gives AI agents an MCP server, CLI, and API. It has no ads or third-party cookies.

### What happens if I lose the link?

The note is gone for good. There are no accounts and no key backups, so nobody can recover it, including us. Save the link somewhere private until you've shared it.

### How does the password option work?

The password is mixed into the encryption key with PBKDF2 (600,000 iterations), so someone who finds the link still can't decrypt the note without it. After 10 wrong passwords the note deletes itself. Send the password through a different channel than the link.

### What do you log?

Nothing about you. We don't store IP addresses, browser details, cookies, or referrers, and request logging is switched off. We keep three daily counters: page loads, notes created, and notes read. They're public on the stats page.

### How long do notes last?

You pick: 10 minutes to 30 days, and optionally a view limit from 1 to 1,000. A note is deleted at its expiry time or right after its last allowed view, whichever comes first.

### How big can a note be?

Up to 512 KiB of text, which is roughly 500,000 characters. That covers passwords, API keys, config files, logs, and long handoff notes. Files and images aren't supported.

### How can AI agents share API keys safely?

Have the agent put the key in an Evergist link instead of printing it into the conversation, a ticket, or a commit. Agents can use the SKILL.md instructions, a local MCP server with a create_gist tool, a command line tool, or the REST API. All of them encrypt on the agent's machine, so Evergist never sees the key.

### Why should I trust the code running in my browser?

You shouldn't have to take our word for it. The page loads no third-party scripts, and its Content-Security-Policy only allows network requests to evergist.com. You can watch the upload in your browser's developer tools and see only ciphertext leave. For the strictest setup, encrypt with the command line tool instead.
