Shredit / Privacy
Privacy
Shredit is designed to minimize what the service can learn about a note.
Client-side encryption
Plaintext is encrypted in your browser with AES-256-GCM before it is uploaded. The decryption key stays in the URL fragment and is not sent to the server.
One-time storage
The server stores ciphertext and removes the active record after an explicit open or after expiry. A failed password attempt does not consume the note.
Network limits
Anonymous by design.* Using the onion mirror through Tor can substantially reduce network-level exposure. It cannot protect against a compromised device, identifying content, recipient actions, modified client code, or advanced traffic correlation.
No tracking
There are no analytics, advertising scripts, session replay tools, remote fonts, or behavioral profiles.