GhostXStudio tools

A free Privnote alternative that sends files, too

GhostSend gives you a one-time, self-destructing link for a secret or a file — end-to-end encrypted in your browser, with no account and no email.

Privnote made the self-destructing note famous: paste some text, get a link, and the note destroys itself after it’s read. It’s a simple, useful pattern, and if you only ever need to share short pieces of text, it works well.

GhostSend follows the same one-shot philosophy but extends it: alongside up to 100 KB of text, you can attach a file up to 100 MB — a PDF, a keystore, a config bundle, a photo of a document — and everything is encrypted with AES-GCM-256 in your browser before a single byte leaves your device. The decryption key rides in the part of the link after the #, which browsers never send to a server, so we hold only unreadable ciphertext. One open, and it’s gone.

What Privnote does well

Privnote is one of the longest-running self-destructing note services and deserves credit for popularizing the whole category. The core flow is about as simple as it gets: type a note, copy the link, and the note is destroyed after being read.

It requires no signup, it’s free, and it typically offers useful extras like configurable expiration times, an optional manual password, and read-notification emails. Privnote also states in its own documentation that notes are encrypted so the service can’t read them. For quick, text-only secrets, it remains a perfectly reasonable choice.

Where GhostSend differs

  • Files, not just text

    Privnote is built around text notes. GhostSend sends up to 100 KB of text or a file up to 100 MB with the same one-time, self-destructing link — no separate file-sharing service needed.

  • Encryption you can pin down

    GhostSend encrypts everything in your browser with AES-GCM-256 before upload. The key lives only in the URL fragment (the part after the #), which browsers never transmit to a server — so even if our entire database leaked, the contents would be unreadable.

  • One open, then wiped — plus a timer

    The moment the recipient opens the link, the ciphertext is deleted in the same transaction; a second visit shows it’s gone. If nobody opens it, it auto-expires on the timer you pick: 1 hour, 24 hours, or 7 days.

  • No identity, ever

    No account, no email, no phone number — for you or the recipient. We store opaque ciphertext plus an expiry, with no name or identity attached to either end.

  • Part of a free, privacy-first family

    GhostSend lives alongside GhostBeam (peer-to-peer transfer), GhostSign (free e-signatures), and the rest of the GhostX tools — all free, all built browser-first.

GhostSend vs Privnote at a glance

Feature GhostSend Privnote
One-time self-destructing link Yes Yes
File attachments Yes — up to 100 MB No — text notes
Text size Up to 100 KB Short notes
Encrypted in your browser AES-GCM-256; key rides the URL fragment Yes, per its documentation
Auto-expiry if never opened 1 hour, 24 hours, or 7 days Configurable expiry
Signup or email None None
Price Free Free

When Privnote is still the better pick

If you specifically want read-notification emails — a message telling you the moment your note was opened — Privnote offers that and GhostSend currently doesn’t.

Privnote’s long track record also counts for something: it’s been doing one thing for many years, and for a quick text-only secret between two people, either tool will serve you well. This page exists because we think the architecture and the file support matter — not because Privnote is a bad product.

Frequently asked questions

  • Is GhostSend really free?

    Yes. One-time encrypted sends — text up to 100 KB or files up to 100 MB — are free, with no account, no trial, and no paid tier gating the core feature.

  • Can GhostSend send files as well as text?

    Yes — that’s the biggest practical difference from a text-only note service. Attach any file up to 100 MB; it’s encrypted in your browser before upload and self-destructs after one open, just like a text note.

  • Can GhostX read what I send?

    No. Everything is encrypted client-side with AES-GCM-256 and the key lives only in the link’s URL fragment, which browsers never send to a server. We hold opaque ciphertext plus an expiry — no filename, no plaintext, no identity — and we cannot decrypt it.

  • What happens if the recipient never opens the link?

    The send auto-expires on the timer you choose — 1 hour, 24 hours, or 7 days — and the ciphertext is deleted even if it was never opened.

  • Can the link be opened more than once?

    No. The first open consumes it: the ciphertext is wiped in the same transaction that hands the recipient the payload. A second visit shows that the send is gone.

  • Is it safe to send a one-time link over email or Slack?

    That’s the point of the design: the link is useless after one open, so even if it lingers in a thread, there’s nothing left behind it. For extra caution, send the link over one channel and tell the recipient it’s coming over another.

Send a secret that self-destructs

Text or files, encrypted in your browser, opened once, then gone. No signup, no email, no trace.

Try GhostSend free