Information stored
- A random note identifier.
- Encrypted ciphertext and a unique encryption initialization value.
- The optional public profile URL supplied by the sender.
- Creation and unread expiration timestamps.
- After reveal, the first reveal and deletion timestamps.
Information not stored
- Readable note text or the decryption key.
- Sender names or recipient email addresses.
- User accounts or uploaded files.
- Browser fingerprints or tracking identifiers in the notes database.
- ScholarBlink does not fetch, scrape, or enrich profile links.
Encryption in the browser
- Your browser generates a random 256 bit AES GCM key.
- The note is encrypted before transmission.
- The key appears after the # in the complete link.
- The link fragment is not included in normal HTTP requests to ScholarBlink.
- The recipient's browser uses the key locally to decrypt the encrypted response.
Expiration and deletion
- The sender chooses an unread lifetime of one, three, or seven days and a reading window after reveal of one, five, ten, or thirty minutes.
- The first successful reveal fixes that deadline; another reveal cannot extend it.
- Expired records are rejected immediately and removed through checks during each request and scheduled cleanup.
- Normal backup and provider recovery systems, if enabled by the operator, may have separate retention characteristics documented by the hosting provider.
Cookies and browser storage
- The core note service does not require an account cookie.
- After creation, the complete link is temporarily placed in the sender's session storage so the created page can display it.
- The browser clears session storage according to its own tab and session behavior.
- ScholarBlink does not use that value for tracking.
Advertising, Google, and consent
- ScholarBlink may use Google AdSense on selected public informational pages. Private note routes, recipient reveal pages, note confirmation pages, expired note pages, this privacy page, and the terms page do not load advertising code.
- External vendors, including Google, may use cookies or similar technologies to serve, measure, limit frequency, prevent fraud, and personalize or limit advertising according to user choices and applicable law.
- Google's use of advertising cookies may allow ads to be served based on a visitor's prior visits to ScholarBlink or other websites. Visitors can manage personalized advertising through Google Ads Settings.
- Before ads are served to visitors in the European Economic Area, the United Kingdom, or Switzerland, ScholarBlink will use a Google certified consent management platform where required. The consent message controls whether personalized, nonpersonalized, or limited ads may be requested.
- More information about how Google uses information from sites that use its services is available at Google's partner sites privacy page.
Server logs
- Hosting and security infrastructure may process routine request metadata such as timestamps, requested paths, network addresses, browser identifier strings, and error information for operations, abuse prevention, and security.
- Application code does not intentionally log note content, ciphertext, or URL fragments.
- Network infrastructure cannot receive the fragment during a normal request.
Public profile links
- The optional profile URL is stored alongside the ciphertext and shown to the recipient before and after reveal.
- It is supplied by the sender, may identify them publicly, and is not independently verified.
- Only https:// URLs are accepted.
Legal requests
- ScholarBlink may preserve or disclose available records when required by a valid legal process.
- The operator does not hold the decryption key, so stored note content is intended to remain encrypted.
- Metadata and profile URLs may be available while a record exists.
Security limitations
- No online system is perfectly secure.
- A recipient can copy or photograph visible text.
- Anyone who obtains the complete link can attempt to reveal it.
- Compromised devices, browser extensions, malicious software, network configuration, implementation defects, or future cryptographic weaknesses may affect confidentiality.
- Do not use ScholarBlink for highly sensitive regulated information or as the only record of important communication.
Contact
Privacy questions can be sent to [email protected]. Activate and monitor this address before public launch.