Information stored
- A random note identifier.
- Encrypted ciphertext and a unique encryption initialization value.
- The optional public profile URL supplied by the sender.
- Creation and unread-expiration timestamps.
- After reveal, the first-reveal and deletion timestamps.
Information not stored
- Readable note text or the decryption key.
- Sender names or recipient email addresses.
- User accounts or uploaded files.
- Browser fingerprints or tracking identifiers in the notes database.
- ScholarBlink does not fetch, scrape, or enrich profile links.
Browser-side encryption
- Your browser generates a random 256-bit AES-GCM key.
- The note is encrypted before transmission.
- The key appears after the # in the complete link.
- The link fragment is not included in normal HTTP requests to ScholarBlink.
- The recipient's browser uses the key locally to decrypt the encrypted response.
Expiration and deletion
- The sender chooses an unread lifetime of one, three, or seven days and a post-reveal window of one, five, ten, or thirty minutes.
- The first successful reveal fixes that deadline; another reveal cannot extend it.
- Expired records are rejected immediately and removed by request-time checks and scheduled cleanup.
- Normal backup and provider-level recovery systems, if enabled by the operator, may have separate retention characteristics documented by the hosting provider.
Cookies and browser storage
- The core note service does not require an account cookie.
- After creation, the complete link is temporarily placed in the sender's session storage so the created page can display it.
- The browser clears session storage according to its own tab and session behavior.
- ScholarBlink does not use that value for tracking.
Advertising, Google, and consent
- ScholarBlink may use Google AdSense on selected public informational pages. Private note routes, recipient reveal pages, note-created pages, expired-note pages, this privacy page, and the terms page do not load advertising code.
- Third-party vendors, including Google, may use cookies or similar technologies to serve, measure, limit frequency, prevent fraud, and personalize or limit advertising according to user choices and applicable law.
- Google's use of advertising cookies may allow ads to be served based on a visitor's prior visits to ScholarBlink or other websites. Visitors can manage personalized advertising through Google Ads Settings.
- Before ads are served to visitors in the European Economic Area, the United Kingdom, or Switzerland, ScholarBlink will use a Google-certified consent management platform where required. The consent message controls whether personalized, non-personalized, or limited ads may be requested.
- More information about how Google uses information from sites that use its services is available at Google's partner-sites privacy page.
Server logs
- Hosting and security infrastructure may process routine request metadata such as timestamps, requested paths, network addresses, user-agent strings, and error information for operations, abuse prevention, and security.
- Application code does not intentionally log note content, ciphertext, or URL fragments.
- Network infrastructure cannot receive the fragment during a normal request.
Public profile links
- The optional profile URL is stored alongside the ciphertext and shown to the recipient before and after reveal.
- It is supplied by the sender, may identify them publicly, and is not independently verified.
- Only https:// URLs are accepted.
Legal requests
- ScholarBlink may preserve or disclose available records when required by a valid legal process.
- The operator does not hold the decryption key, so stored note content is intended to remain encrypted.
- Metadata and profile URLs may be available while a record exists.
Security limitations
- No online system is perfectly secure.
- A recipient can copy or photograph visible text.
- Anyone who obtains the complete link can attempt to reveal it.
- Compromised devices, browser extensions, malicious software, network configuration, implementation defects, or future cryptographic weaknesses may affect confidentiality.
- Do not use ScholarBlink for highly sensitive regulated information or as the only record of important communication.
Contact
Privacy questions can be sent to [email protected]. Activate and monitor this address before public launch.