Privacy at a glance

Information stored

  • A random note identifier.
  • Encrypted ciphertext and a unique encryption initialization value.
  • The optional public profile URL supplied by the sender.
  • Creation and unread-expiration timestamps.
  • After reveal, the first-reveal and deletion timestamps.

Information not stored

  • Readable note text or the decryption key.
  • Sender names or recipient email addresses.
  • User accounts or uploaded files.
  • Browser fingerprints or tracking identifiers in the notes database.
  • ScholarBlink does not fetch, scrape, or enrich profile links.

Browser-side encryption

  • Your browser generates a random 256-bit AES-GCM key.
  • The note is encrypted before transmission.
  • The key appears after the # in the complete link.
  • The link fragment is not included in normal HTTP requests to ScholarBlink.
  • The recipient's browser uses the key locally to decrypt the encrypted response.

Expiration and deletion

  • The sender chooses an unread lifetime of one, three, or seven days and a post-reveal window of one, five, ten, or thirty minutes.
  • The first successful reveal fixes that deadline; another reveal cannot extend it.
  • Expired records are rejected immediately and removed by request-time checks and scheduled cleanup.
  • Normal backup and provider-level recovery systems, if enabled by the operator, may have separate retention characteristics documented by the hosting provider.

Cookies and browser storage

  • The core note service does not require an account cookie.
  • After creation, the complete link is temporarily placed in the sender's session storage so the created page can display it.
  • The browser clears session storage according to its own tab and session behavior.
  • ScholarBlink does not use that value for tracking.

Advertising, Google, and consent

  • ScholarBlink may use Google AdSense on selected public informational pages. Private note routes, recipient reveal pages, note-created pages, expired-note pages, this privacy page, and the terms page do not load advertising code.
  • Third-party vendors, including Google, may use cookies or similar technologies to serve, measure, limit frequency, prevent fraud, and personalize or limit advertising according to user choices and applicable law.
  • Google's use of advertising cookies may allow ads to be served based on a visitor's prior visits to ScholarBlink or other websites. Visitors can manage personalized advertising through Google Ads Settings.
  • Before ads are served to visitors in the European Economic Area, the United Kingdom, or Switzerland, ScholarBlink will use a Google-certified consent management platform where required. The consent message controls whether personalized, non-personalized, or limited ads may be requested.
  • More information about how Google uses information from sites that use its services is available at Google's partner-sites privacy page.

Server logs

  • Hosting and security infrastructure may process routine request metadata such as timestamps, requested paths, network addresses, user-agent strings, and error information for operations, abuse prevention, and security.
  • Application code does not intentionally log note content, ciphertext, or URL fragments.
  • Network infrastructure cannot receive the fragment during a normal request.

Public profile links

  • The optional profile URL is stored alongside the ciphertext and shown to the recipient before and after reveal.
  • It is supplied by the sender, may identify them publicly, and is not independently verified.
  • Only https:// URLs are accepted.

Legal requests

  • ScholarBlink may preserve or disclose available records when required by a valid legal process.
  • The operator does not hold the decryption key, so stored note content is intended to remain encrypted.
  • Metadata and profile URLs may be available while a record exists.

Security limitations

  • No online system is perfectly secure.
  • A recipient can copy or photograph visible text.
  • Anyone who obtains the complete link can attempt to reveal it.
  • Compromised devices, browser extensions, malicious software, network configuration, implementation defects, or future cryptographic weaknesses may affect confidentiality.
  • Do not use ScholarBlink for highly sensitive regulated information or as the only record of important communication.

Contact

Privacy questions can be sent to [email protected]. Activate and monitor this address before public launch.