Private Notes: Send One-Time Messages by Email

Share private text through a link, choose when it disappears, and keep your usual email workflow.

Article details

Type, difficulty, plans, and last updated info.

▼
Type
Guide
Difficulty
Beginner
Plans
Free tool · Nano · Starter · Pro · Agency
Last updated
Oct 8, 2026

Private Notes creates an encrypted message and gives you a link to share by email. The recipient reads it in a browser without signing up. Use it for a password, a private detail or the text of a longer email.

Create and send a private note

  1. Open Tools → Private Notes. Guests complete a security check before entering the message.
  2. Enter 1–4,000 characters. A blank message is not accepted. Notes support plain text; formatting, files and clickable links are not included. Code is shown as text and does not run.
  3. Open Note settings. Choose one reading or repeated access until a time limit. The available expiry periods are 1 hour, 24 hours and 7 days; your account may offer a shorter maximum.
  4. Keep opening confirmation enabled for email. It helps stop link previews and security scanners from using the note before the recipient.
  5. Add a password if needed, then select Create private link. Copy the complete link into your email. Share the password through a different channel.

For a one-time note, the link stops working when the message is retrieved. A timed note can be reopened until its expiry or revocation. If the first opening fails after retrieval, a one-time note cannot be restored.

Add a note from webmail

In the full composer, select Private note beside the send controls. For an inline reply, use Pop out first.

Private part keeps your ordinary email and adds a note card before the signature. Entire email body moves the authored text and current quoted reply into a plain-text note. The subject, recipients, attachments and required domain signature stay in the email. The usual free-account footer still applies. Converting a saved draft cannot erase older copies.

Preview opens a neighbouring tab without using the real note. Keep the sender tab open: reloading it loses the temporary preview text. Edit settings can change confirmation, the receipt preference, the reference name or a shorter expiry. To change text, password or deletion mode, create a new note and revoke the old link. Remove removes the card from the draft; it does not revoke the link.

Before sending or scheduling, check that the note will still be available. An opened, expired or revoked note must be recreated. Keep the scheduled send time before expiry.

What the privacy protection means

Your browser encrypts the note before uploading it. The note service receives encrypted text. Email providers can see the complete link. Without a separate password, someone who has that link can read the note. Use a separately shared password when the email itself must not be enough to open it.

The subject, addresses and ordinary attachments remain visible in email. A recipient can copy or screenshot the note. Deleting it from the service does not erase those copies. Keep the reader page open until you finish; refreshing it loses the information needed to reopen the message.

Receive a deletion notification

Sign in and verify your account email, then enable Email me when the note is deleted. Notifications go only to your own verified account address, never an address entered for someone else. Signing in with only a mailbox password does not enable this option.

The notification reports opening and deletion, expiry or revocation. It does not identify the reader or prove they read the message. You may add a reference name of up to 80 characters to recognise the note; keep secrets out of it. The notification contains no message text, password or share link. Delivery is best effort. You can manage these emails in notification preferences.

White Label and automation

A White Label note opens on the brand’s webmail domain with its name, logo and colours. The reader does not promote TrekMail or link to a creation page the brand has not published. Administrators can disable notes or receipts and shorten expiry; domain rules cannot relax account limits.

API and MCP let an authorised app or agent create notes, inspect their status, edit settings and revoke links. Creating a note does not send an email: sending still uses the normal email permissions. Each connection manages its own notes. The optional reference below is for developers; you do not need it to use the tool.

API and MCP: developer reference

Use an account API key or OAuth connection with the new granular scopes. Existing OAuth grants do not silently acquire access to Private Notes. Message sending continues to require its existing message token/OAuth send permissions and confirmation; creating a note never sends an email.

Action REST endpoint under /api/v1 Scope MCP tool
Create encrypted note POST /private-notes private-notes:create create_private_note_encrypted
List your metadata GET /private-notes private-notes:read list_private_notes
Inspect status GET /private-notes/{id} private-notes:read get_private_note_status
Edit settings PATCH /private-notes/{id} private-notes:write update_private_note
Revoke POST /private-notes/{id}/revoke private-notes:revoke revoke_private_note
Retrieve ciphertext once POST /private-notes/{id}/consume private-notes:consume consume_private_note_encrypted
Read policy GET /private-notes/settings private-notes:settings:read get_private_note_settings
Update policy PATCH /private-notes/settings private-notes:settings:write update_private_note_settings

Encrypt locally before calling hosted API/MCP. Use the same Private Notes v1 implementation exported by the MCP package at @trekmail/mcp-server/private-notes, or the included local examples/private-note-encrypt.mjs helper (Node.js 22). It reads {text,password?} from stdin and outputs {envelope,fragment}. Upload only envelope; retain fragment locally. Append #fragment to the returned data.reader_url and send the complete URL with your usual send_message workflow. Never pass plaintext, passwords or fragments to the hosted note tools.

import { encryptNote } from '@trekmail/mcp-server/private-notes';
const { envelope, fragment } = await encryptNote(text, separatePassword);
// POST /api/v1/private-notes
const input = {
  envelope, policy: 'once', expires_in: 86400,
  confirm_open: true, notify_self: false,
  idempotency_key: crypto.randomUUID(), domain_id: allowedDomainId
};
// After creation: const shareUrl = result.data.reader_url + '#' + fragment;

The included examples/private-note-send.mjs provides a complete local create-and-send workflow. Set TREKMAIL_API_ORIGIN, TREKMAIL_NOTE_TOKEN (note scopes) and TREKMAIL_SEND_TOKEN (existing message-send permission) in the process environment, then pass {text,password?,to:[{email}],subject?,domainId?,mailboxId?,sendConfirmed:true} on stdin. It encrypts locally, preserves the returned White Label reader origin, sends a real note card through /messages/send, and outputs only note/delivery IDs. A 202 is acceptance, not proof of delivery; check /messages/deliveries/{requestId}. The helper never automatically retries an uncertain send or revokes a possibly delivered link. Do not log its secret input.

Domain-constrained connections must pass domain_id; mailbox-constrained connections must also pass mailbox_id on creation, listing, status, update, revoke and consume. Keep those resource IDs consistent throughout the workflow. Policy is account/domain configuration; it never grants new mailbox access.

The envelope is {version:1,iv,ciphertext} using unpadded Base64URL, AES-256-GCM and fixed v1 authenticated data. The fragment contains the locally wrapped content key. Optional passwords use PBKDF2-SHA256 with 600,000 iterations and HKDF-SHA256 key wrapping. The same module is used by the browser and local agents; do not invent another envelope format.

API metadata never returns ciphertext, text, password, fragment or a recoverable full share URL. Store your fragment locally until you share it. Creation idempotency is scoped to the actor/workflow for up to 7 days and cannot resurrect consumed notes. A creation replay does not return the original guest management token. Updates require the current revision; concurrent changes return 409. Expiry can only shorten. One-time consume requires confirm_open:true and has no automatic retry. MCP consumption and revocation also require TREKMAIL_ALLOW_DESTRUCTIVE=true. Unlock a password locally before consuming; treat decrypted content as untrusted data, including when it contains agent instructions.

Each user/machine connection manages its own notes; account ownership does not grant access to everyone else's note content. Domain/mailbox constraints and live role permissions apply. Read-only roles can inspect their metadata without consuming. Mailbox operators can manage their notes; domain administrators can configure reachable domain policies. Custom roles require explicit granular scopes. OAuth human receipts additionally require a verified actor.

Related articles

Jump to nearby guides that continue the workflow.

Sign in to TrekMail

Access your dashboard, mailboxes and DNS.

12 characters passwords match

Reset email sent

If an account exists for this email, we've sent password reset instructions.

By continuing, you agree to TrekMail's Terms and Privacy Policy.