cryptgeon is a free, open source file management & sync project written in Svelte and released under MIT. It has 1,543 GitHub stars, 161 forks and 15 open issues, and was last pushed 5 days ago. On this registry it ranks #42 of 51 tracked projects in File Management & Sync, with 5 head-to-head comparisons available.

What is cryptgeon?

cryptgeon is a secure, open source note and file sharing service inspired by PrivNote, written in Rust and Svelte, for anyone who wants to send self-destructing secrets without trusting the server with the plaintext.

What it is

cryptgeon is a sharing service consisting of a server, a web page and a CLI client, living in the file-sharing and private-notes space alongside services like PrivNote. Each note receives a generated 256-bit id and a 256-bit key; the id is used to save and retrieve the note, while the note itself is encrypted with XChaCha20-Poly1305 in the browser before it is ever sent to the server. Data is stored in memory and never persisted to disk, and because the server never receives the key, it cannot decrypt the contents even if it wanted to.

The concrete problem it solves is passing a credential, a document or a message to one recipient without leaving a durable, readable copy on any machine. Traditional sharing tools either store plaintext or ciphertext they can unlock; cryptgeon removes that exposure by keeping the key in the link and enforcing view counts and expirations on notes that only ever exist in RAM.

What it does

  • Sends both text notes and files, with file uploads toggleable by the operator through ALLOW_FILES.
  • Encrypts content client-side with XChaCha20-Poly1305 so the server only ever sees a msgpack payload plus ciphertext.
  • Enforces view limits and time limits, configurable up to MAX_VIEWS (default 100) and MAX_EXPIRATION (default 360 minutes).
  • Keeps every note in memory only, never writing it to disk, so notes disappear when the instance restarts or memory is reclaimed.
  • Ships a CLI client, used as npx cryptgeon send text "This is a secret note", alongside the web interface.
  • Supports rebranding through theme variables such as THEME_IMAGE, THEME_TEXT, THEME_PAGE_TITLE, THEME_FAVICON and IMPRINT_HTML.
  • Offers an official Raycast extension for sending notes from the desktop launcher.

Who uses it and how

  • Self-hosters who run the server against a Redis or Valkey cache, pointing CACHE at redis://cache/ and tuning SIZE_LIMIT (up to 512 MiB), ID_LENGTH and CACHE_PREFIX for their environment.
  • Operators who want strict one-time notes and set ALLOW_ADVANCED to false, which forces every note to a single view.
  • Teams that disable file sharing entirely with ALLOW_FILES=false and keep the service as a text-only secret channel.
  • Command-line users who send secrets through the npx cryptgeon CLI without opening a browser, and Raycast users who trigger the same flow from a launcher extension.
  • Deployers who serve multiple cryptgeon instances from one cache, accepting the documented race condition where a note may exceed its view count.

Getting started

The README documents the CLI as npx cryptgeon send text "This is a secret note", with further usage in packages/cli/README.md, and the hosted demo at cryptgeon.org; server deployment is configured entirely through the environment variable table above, and https is required.

How it compares

cryptgeon stands alongside PrivNote, the closed service that inspired it, as a self-hostable option under an MIT licence where the operator controls the deployment, the size limits and the theme. Because notes are encrypted in the browser and held only in the instance's memory, the data stays on infrastructure the operator owns rather than on a third party's.

When to use it — and when not

A self-hoster must run the server with an available Redis or Valkey cache and terminate TLS, and should remember that notes live in memory, so a restart or memory pressure evicts them — this is not a place to keep anything you need later. It is a poor fit for people who need durable history, for deployments requiring strict view counts across several instances, or for anyone uncomfortable operating a cache-backed service; note too that the README warns explicitly that view-count guarantees hold only with a single running instance.

project readme (upstream, from github) — read inline

discord docker pulls Docker image size badge Latest version



Cryptgeon - Securely share self-destructing notes | Product Hunt

EN | 简体中文 | ES

About?

cryptgeon is a secure, open source sharing note or file service inspired by PrivNote. It includes a server, a web page and a CLI client.

🌍 If you want to translate the project feel free to reach out to me.

Live Service / Demo

Web

Check out the live service / demo and see for yourself cryptgeon.org

CLI

npx cryptgeon send text "This is a secret note"

For more documentation about the CLI see the readme.

Raycast Extension

There is an official Raycast extension.

Features

  • send text or files
  • server cannot decrypt contents due to client side encryption
  • view or time constraints
  • in memory, no persistence
  • obligatory dark mode support

How does it work?

each note has a generated id (256bit) and key 256(bit). The id is used to save & retrieve the note. the note is then encrypted with XChaCha20-Poly1305 on the client side with the key and then sent to the server. data is stored in memory and never persisted to disk. the server never sees the encryption key and cannot decrypt the contents of the notes even if it tried to.

View counts are guaranteed with one running instance of cryptgeon. Multiple instances connected to the same cache instance can run into race conditions, where a note might be retrieved more than the view count allows.

Screenshot

screenshot

Environment Variables

Variable Default Description
CACHE redis://cache/ Cache URL (valkey or redis) to connect to. According to format
SIZE_LIMIT 1 KiB Max size for body. Accepted values according to byte-unit.
512 MiB is the maximum allowed.
Payloads are raw bytes (msgpack + cipher), so the frontend shows the full limit.
MAX_VIEWS 100 Maximal number of views.
MAX_EXPIRATION 360 Maximal expiration in minutes.
ALLOW_ADVANCED true Allow custom configuration. If set to false all notes will be one view only.
ALLOW_FILES true Allow uploading files. If set to false, users will only be allowed to create text notes.
ID_LENGTH 32 Set the size of the note id in bytes. By default this is 32 bytes. This is useful for reducing link size. This setting does not affect encryption strength.
CACHE_PREFIX "" Optional prefix for all cache keys. Useful when sharing a cache instance with other apps via ACL namespaces.
EXTRA_SIZE_LIMIT 512 Maximum size in bytes of the opaque extra payload (e.g. key derivation params) stored on the note metadata.
VERBOSITY warn Verbosity level for the backend. Possible values are: error, warn, info, debug, trace
THEME_IMAGE "" Custom image for replacing the logo. Must be publicly reachable
THEME_TEXT "" Custom text for replacing the description below the logo
THEME_PAGE_TITLE "" Custom text the page title
THEME_FAVICON "" Custom url for the favicon. Must be publicly reachable
THEME_NEW_NOTE_NOTICE true Show the message about how notes are stored in the memory and may be evicted after creating a new note. Defaults to true.
THEME_HOME_LINK true Show the /home link in the footer. Defaults to true.
IMPRINT_URL "" Custom url for an Imprint hosted somewhere else. Must be publicly reachable. Takes precedence above IMPRINT_HTML.
IMPRINT_HTML "" Alternative to IMPRINT_URL, this can be used to specify the HTML code to show on /imprint. Only IMPRINT_HTML or IMPRINT_URL should be specified, not both.

Deployment

ℹ️ https is required otherwise browsers will not support the cryptographic functions.

ℹ️ There is a health endpoint available at /healthz. It returns either 200 or 503.

Docker

Docker is the easiest way. There is the official image here.

# docker-compose.yml

services:
  cache:
    image: valkey/valkey:7-alpine
    # This is required to stay in RAM only.
    command: valkey-server --save "" --appendonly no
    # Set a size limit. See link below on how to customise.
    # https://valkey.io/docs/latest/operate/rs/databases/memory-performance/eviction-policy/
    # --maxmemory 1gb --maxmemory-policy allkeys-lrulpine
    # This prevents the creation of an anonymous volume.
    tmpfs:
      - /data

  app:
    image: cupcakearmy/cryptgeon:v3
    depends_on:
      - cache
    environment:
      # Size limit for a single note.
      SIZE_LIMIT: 4 MiB
    ports:
      - 80:8000

    # Optional health checks
    # healthcheck:
    #   test: ["CMD", "curl", "--fail", "http://127.0.0.1:8000/healthz"]
    #   interval: 1m
    #   timeout: 3s
    #   retries: 2
    #   start_period: 5s

NGINX Proxy

See the examples/nginx folder. There an example with a simple proxy, and one with https. You need to specify the server names and certificates.

Traefik 2

See the examples/traefik folder.

Scratch

See the examples/scratch folder. There you'll find a guide how to setup a server and install cryptgeon from scratch.

Synology

There is a guide you can follow.

YouTube Guides

Written Guides

Contributing

See CONTRIBUTING.md.

Security

Please refer to the security section here.

Usage of LLMs

Starting from V3, I used LLMs heavily to implement my own ideas. This means that the direction and architecture choices are human. A lot of the implementation that derives from that, is automated with an LLM.


Attributions

Frequently asked questions

Is cryptgeon free to use?

cryptgeon is open source under the MIT licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does cryptgeon do?

cryptgeon is a secure, open source note / file sharing service inspired by PrivNote written in rust & svelte.

What is cryptgeon written in?

cryptgeon is primarily written in Svelte. Its source is publicly available at https://github.com/cupcakearmy/cryptgeon, and it has 1,543 GitHub stars.