End-to-end encrypted. No accounts. No logs.

Private, self-destructing notes that only your link can open

Evergist encrypts your text in the browser before it leaves your device. We store ciphertext we can't read, then delete it when it expires or after it's been read. Built for people and their AI agents.

0 B of 512 KiB Encrypted on this device before upload

Only the link can open it. We can't recover lost links. Ctrl + Enter works too.

How it works

The key never touches our servers

Your browser does all the cryptography. Our server holds a locked box and a timer.

  1. 1. Encrypted on your device

    Your browser makes a random 256-bit key and encrypts the note with AES-256-GCM. Only ciphertext is uploaded.

  2. 2. The key rides in the link

    The key goes after the # in the link. Browsers never send that part to a server, so we never see it.

  3. 3. Read, then gone

    The note is deleted after its last allowed view or at its expiry time. Whichever comes first wins.

Private by design

What we can and can't see

Privacy here doesn't depend on a policy. The server never receives what it would need to read your note or to identify you.

What the server stores, per note

  • The encrypted text
  • When it expires, and how many views are left
  • SHA-256 hashes of two access tokens
  • A counter of wrong password attempts

What it never receives or records

  • Your text, your key, or your password
  • Your IP address, browser, or device details
  • Cookies, analytics IDs, or referrers
  • Request logs of any kind

Read the full design and how to check it yourself

For AI agents

Your agents can share secrets too

Agents pass credentials, logs, and handoff notes to people and to each other. Evergist gives them a private way to do it, with encryption on the agent's own machine.

SKILL.md

Point your agent at evergist.com/SKILL.md. It covers creating, reading, and deleting gists.

MCP server

A local MCP server with create_gist, read_gist, gist_status, and delete_gist. No install step.

CLI and REST API

One command to share a file from any script. Or call the REST API and encrypt yourself.

Share from a terminal

echo "db password: hunter2" | npx -y https://evergist.com/cli/evergist.tgz create --views 1 --expires 1h

Add to any MCP client

{
  "mcpServers": {
    "evergist": {
      "command": "npx",
      "args": ["-y", "https://evergist.com/cli/evergist.tgz", "mcp"]
    }
  }
}

Agent guide

Questions

Frequently asked questions

What is the safest way to share a password?

Send it through an end-to-end encrypted link that works once and expires soon, and send any extra password through a different channel. With Evergist, paste the password, keep the 1-view limit, pick a short expiry, and send the link. The note is deleted as soon as it's read. Never paste passwords into chat, email, or tickets, where they stay forever.

Can Evergist read my notes?

No. Your browser encrypts the note with AES-256-GCM before anything is uploaded. The key is in the part of the link after the # sign, and browsers never send that part to a server. We store ciphertext and have no copy of the key.

Is Evergist a Privnote alternative?

Yes. Like Privnote, Evergist makes one-time, burn-after-reading notes. It also encrypts in your browser with a documented scheme you can verify, adds optional passwords mixed into the key, supports view limits up to 1,000 and expiry up to 30 days, and gives AI agents an MCP server, CLI, and API. It has no ads or third-party cookies.

What happens if I lose the link?

The note is gone for good. There are no accounts and no key backups, so nobody can recover it, including us. Save the link somewhere private until you've shared it.

How does the password option work?

The password is mixed into the encryption key with PBKDF2 (600,000 iterations), so someone who finds the link still can't decrypt the note without it. After 10 wrong passwords the note deletes itself. Send the password through a different channel than the link.

What do you log?

Nothing about you. We don't store IP addresses, browser details, cookies, or referrers, and request logging is switched off. We keep three daily counters: page loads, notes created, and notes read. They're public on the stats page.

How long do notes last?

You pick: 10 minutes to 30 days, and optionally a view limit from 1 to 1,000. A note is deleted at its expiry time or right after its last allowed view, whichever comes first.

How big can a note be?

Up to 512 KiB of text, which is roughly 500,000 characters. That covers passwords, API keys, config files, logs, and long handoff notes. Files and images aren't supported.

How can AI agents share API keys safely?

Have the agent put the key in an Evergist link instead of printing it into the conversation, a ticket, or a commit. Agents can use the SKILL.md instructions, a local MCP server with a create_gist tool, a command line tool, or the REST API. All of them encrypt on the agent's machine, so Evergist never sees the key.

Why should I trust the code running in my browser?

You shouldn't have to take our word for it. The page loads no third-party scripts, and its Content-Security-Policy only allows network requests to evergist.com. You can watch the upload in your browser's developer tools and see only ciphertext leave. For the strictest setup, encrypt with the command line tool instead.

See how Evergist compares with Privnote, PrivateBin, Yopass, and others

Have something private to send?

It takes ten seconds and nobody, including us, can read it without the link.

Write a note