Security
Encrypt or decrypt text with a passphrase using AES-256-GCM.
Runs entirely in your browser, nothing is uploadedAES-256-GCM with a PBKDF2-derived key, entirely in your browser via the Web Crypto API. Losing the passphrase means losing the data; there is no recovery.
A key is derived from your passphrase with PBKDF2 and a fresh random salt, so the same passphrase does not produce the same key twice.
Encryption uses AES-256-GCM through the browser’s Web Crypto implementation. Your text and passphrase never leave the tab.
The output carries the salt and nonce it needs to be decrypted later. The passphrase has to reach the other person some other way.