This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend
He asked for "fully secure" note sharing. He wouldn't stop asking, honestly. So before writing a single line of code, I had to be honest with him about what that sentence actually means.
Fully secure note sharing is not possible. Not on the web, not anywhere. No website can stop someone from taking a screenshot, pointing a phone camera at the monitor, or retyping what they see. Anyone who promises otherwise is selling something.
But "fully secure" being impossible doesn't mean "secure" is. So I built the most controlled version of the idea I could, and named it SecureNote.
What I Built
SecureNote is end-to-end encrypted note and file sharing, and I built it for my friend. His notes aren't text, by the way: they're PDFs, scanned documents, photos of whiteboards. So files are first-class citizens here, and they're encrypted exactly like everything else.
What it actually gives you:
- Notes and files (PDFs, docs, images, up to 10 MB) are encrypted in your browser with AES-256-GCM before upload. The database stores ciphertext: it cannot read your content, your titles, or even your filenames.
- You share with a person, not a link. Pick someone by their account, set an expiry and a view limit. The note's key gets wrapped for their public key alone.
- Revocation is instant. One click and their key stops working, even if they already read the note. Their open tab locks itself the next time it gets focus.
- Every read is on the record. Each view is watermarked with the reader's email and written to an audit log: who, when, from which IP, on what device. Even pressing the PrintScreen key is logged as an attempt.
- The AI never leaves your machine. Semantic search and "chat with your notes" powered by Gemma 3 (Google's open-weight model) running in the browser via WebGPU. Open the network tab while using it: nothing goes out.
So what about screenshots? Like I said: I can't stop them. Nobody can. What I can do is make sure a screenshot isn't anonymous. Every page a reader opens is tiled with their identity and a timestamp. If they leak it, they leaked a page with their own name on it, at a logged time, from a logged IP. You can also cap the views or expire the share in an hour.
My friend's response was something like "okay, fair."
Demo
Live app: https://securenote-j8b0.onrender.com
It's hosted on Render's free tier, so the very first load can take about 50 seconds to wake up. Every load after that is instant. Sign up with two accounts: write a note as A, share it to B with a 2-view limit, open it as B, then check A's audit log. Press PrintScreen as B and watch it land there too.
Code
The full source is on GitHub, MIT licensed: https://github.com/CodeNeuron58/SecureNote
The README covers the whole security model, including the threat model and the things no website can honestly promise.
How I Built It
No crypto libraries, just the browser's built-in WebCrypto:
- Signup generates an ECDH P-256 keypair in your browser. The private key is encrypted with a key derived from your password (PBKDF2-SHA-256, 310,000 iterations) before it's ever uploaded. The server stores a bcrypt hash, a salt, your public key, and your sealed private key. It never sees your password.
- Every note gets a random content key. Title, body, and uploaded files are encrypted client-side; the content key is wrapped to your own public key.
- Sharing unwraps that key in your browser and wraps it for the reader's public key (ephemeral ECDH + HKDF). The server relays sealed blobs it cannot open, while still enforcing expiry and view limits.
- The AI is the part I'm proudest of. Private notes plus a cloud AI API is a contradiction, so the AI runs in the browser: MiniLM embeddings and Gemma 3 1B (open weight) via transformers.js on WebGPU, with the vector store in IndexedDB. After the one-time model download, searching and chatting make zero network calls.
Stack: Next.js 15, TypeScript, Tailwind, MongoDB Atlas, hosted on Render.
Why Does Open Innovation Matter?
My friend's whole point was "my notes stay mine." Sending that data to a closed cloud AI would betray the entire premise, so an open-weight model running on-device wasn't a nice-to-have. It was the only architecture that made sense.
It also cost exactly nothing to run, it works with pluggable models (swap Gemma for any ONNX model without asking anyone's permission), and he can clone the repo and host the whole thing himself if he ever stops trusting me. The open approach didn't just work better than a closed one here. It was the difference between using software and owning it.
Prize Categories
- Best Use of Gemma: Gemma 3 1B (open weight) powers the in-browser "chat with your notes" and semantic search, running locally via WebGPU
- Best Use of Render: the whole app is hosted on Render's free tier
- Best Use of MongoDB Atlas: Atlas is the data layer, deliberately storing only ciphertext, grants and audit events
It's built for one friend, but if you've ever needed to send something sensitive without losing control of it, it's for you too. Roast it, break it, tell me what you'd add.
Top comments (0)