SecretNote Launches as SmartKit’s Encrypted Secret Sharing Tool
SmartKit SecretNote is now live as part of the August 2, 2026 update.
This new tool gives users a safer way to share passwords, API keys, login details, Wi-Fi credentials, one-time codes, and confidential notes without leaving them behind forever in chat history or email threads.
A Safer Way to Share Secrets
SecretNote was built for a simple problem that happens every day: people send sensitive information through channels that were designed to preserve history.
Passwords sent through chat or email can stay searchable, backed up, synced across devices, and exposed long after the secret was only needed for a short handoff.
SecretNote replaces that habit with a temporary encrypted link that reveals intentionally and can disappear after use or expiry.
Browser-Side AES-GCM Encryption
SecretNote encrypts the secret inside the user’s browser before upload using AES-GCM encryption.
That means the server receives unreadable ciphertext instead of the original secret. This is a technical design choice, not only a privacy promise.
The strongest part is the key handling model. The decryption key lives in the URL fragment, the part after the hash symbol, which browsers do not normally send to servers. SmartKit stores the encrypted content, while the key stays outside normal server visibility.
In simple terms, the server gets the locked box, not the key to open it.
One-Time Links, View Limits, and Expiry
Users can control how long a secret remains available.
SecretNote supports one-time reveal links, limited view counts, and time expiry from short windows up to seven days. When the allowed views are used or the expiry time is reached, the encrypted record can be destroyed automatically.
This makes secret sharing feel much closer to how secrets should behave: useful for the handoff, then gone.
Optional Password or PIN Protection
SecretNote also supports an optional password or PIN layer.
This means the link alone does not have to be enough to reveal the secret. For stronger handoffs, the creator can send the link through one channel and share the password separately through another.
This gives users a practical second gate without making the recipient flow complicated.
Bot-Safe Reveal Flow
SecretNote includes a bot-safe reveal step.
Many email tools, chat apps, and security scanners automatically open links to preview or inspect them. In a basic one-time secret tool, that can accidentally burn the secret before the real recipient sees it.
SecretNote avoids that problem by showing a safe landing page first. The encrypted content is only released when a human intentionally clicks Reveal.
Credentials Mode for Login Handoffs
SecretNote includes a dedicated Credentials mode.
Instead of sending one messy text block, users can structure a login handoff with separate fields for username, password, login URL, and notes.
After reveal, each field can be copied separately, making the handoff cleaner on both desktop and mobile. External login links also include a safety confirmation before opening.
Built-In Secret Generators
SecretNote can generate fresh secrets directly in the browser.
Users can create strong passwords, memorable passphrases, numeric PINs, and API tokens without leaving the page. Generated values stay aligned with the privacy-first workflow because they are created on the user’s device.
This makes it easy to create the secret, package it, and share it securely in one flow.
QR Sharing and Private Management Links
SecretNote supports practical sharing methods.
Users can copy the link, use native share options, send it through email or messaging apps as a link, or display a QR code. The QR code is generated in the browser.
Each secret also comes with a private management link. The creator can check whether the secret has been opened, see remaining views, and destroy it early if needed, without exposing the secret content itself.
Dashboard for Repeat Users
Basic SecretNote use does not require an account.
For users who share secrets often, a free SmartKit account adds a dashboard showing created secrets and their status, such as active, fully viewed, expired, destroyed, or disabled.
The dashboard shows metadata and control status, not the secret contents.
Honest Security Boundaries
SecretNote is built with strong privacy controls, but it stays honest about what any secret-sharing tool can and cannot do.
It cannot stop a recipient from copying, saving, or photographing a secret after reveal. What it can do is stop secrets from sitting permanently in chat and email history, encrypt the content before upload, keep the key outside normal server requests, limit visibility, and destroy the record after use or expiry.
Try it here: https://smartkit.cc/secretnote
SecretNote gives SmartKit users a more professional way to share a secret once, control how it is revealed, and let it disappear before it becomes tomorrow’s security problem.
