Your content is encrypted on your device
Encyptify encrypts the message, title, filenames, and files before uploading them. New notes use AES-256-GCM by default, with AES-128-GCM available as an option. The decryption key stays in your private link.
Keep your link and QR code private
Anyone with the complete link or QR code can open your note within its sharing limits. The QR code is generated on your device. Encyptify does not send your link to an external QR service.
The key appears after the # symbol in the link. Browsers do not send that part to the note server. A messaging app you paste it into, browser extensions, or someone using your device may still see it. Lost links cannot be recovered.
The sharing page keeps the link only while it is open. The reader removes the key from the address bar. If you reload, use the original complete link to return. Encyptify does not save drafts or decryption keys in browser storage.
Views, downloads, and expiry
Selecting Open note uses one view. Limits apply to viewing sessions, not verified individual people. A random token in your tab lets you resume the same active session without using another view. That token is cleared when you close the note or the active page expires.
Download limits count visits allowed to download, not the number of files. Reaching the view limit prevents new visits; people already reading can continue until their visit ends or the note expires. The expiry time always takes priority.
Access ends at the selected expiry time, up to seven days after creation. Expired content is removed from active storage asynchronously. Deleting a note from the sharing page removes its content from active storage immediately. Incomplete uploads expire within one hour or the note’s earlier expiry.
Downloaded files, screenshots, and other copies cannot be recalled. Provider backups and logs may have separate retention periods, so expiry is not a guarantee that every copy is erased at that instant.
What is stored
The service stores encrypted content, random identifiers, file sizes and counts, sharing settings, timestamps, and usage counters. Access and viewing-session tokens are stored as hashes. Global capacity limits use aggregate counters rather than visitor profiles.
Your light or dark theme preference is saved in your browser. It does not contain note content or keys.
Encyptify uses Netlify and MongoDB to host and operate the service. These providers can process IP addresses, request metadata, and security cookies. You do not need an Encyptify account to create or open a note. Encyptify does not add advertising, analytics, or session-replay tools.
Security limits
Encryption depends on the security of your device, browser, and the website delivering the code. A compromised device, browser extension, or website could capture content or keys. Clearing a page cannot guarantee that every trace is removed from device memory.
Encyptify is in beta and has not undergone an independent security audit. Provider log and backup retention have not been independently verified. Use test content during this phase; Encyptify does not promise complete anonymity, zero infrastructure logs, or erasure of every copy.
Updated October 4, 2026