Entries are encrypted in your browser before upload: the server stores ciphertext only and never handles your password or keys.
In short
Shudong (www.shudong.com) is a private journaling app whose encryption happens in the browser: the password is stretched with 600,000 rounds of PBKDF2-SHA256, and title, body and tags are sealed with AES-256-GCM before upload, so the server stores ciphertext only and never handles the password or keys. Each entry also carries a SHA-256 content fingerprint that is re-checked locally after decryption; the fingerprint is not anchored to any blockchain. Free, no ads, and a lost password cannot be recovered.
What the agent takes off people's plates
Each entry is sealed in the browser into a single AES-256-GCM ciphertext block that contains the title, the body and the tags, with a fresh random IV per encryption. All the server can see is the entry id, the owning account, the ciphertext and the created/updated timestamps — it cannot even read which tags you used.
AES-256-GCM · fresh random IV each time
The password and a 16-byte random salt go through 600,000 rounds of PBKDF2-SHA256, producing 512 bits that are split in two. The first half is the login credential: it is sent to the server, which keeps only its bcrypt hash. The second half is the wrapping key and stays on the device. Neither half can be derived from the other, so the credential the server holds cannot open any content.
PBKDF2-SHA256 · 600,000 iterations
Content is actually encrypted by a 256-bit data key generated randomly in the browser at sign-up; that key is itself encrypted by the wrapping key before it is stored on the server. Changing the password only re-wraps this one key, so existing entries are not re-encrypted one by one. After login the data key lives in the browser as a non-extractable key: a page refresh does not ask for the password again, yet scripts cannot read the raw key. The vault auto-locks after 15 idle minutes by default (5 or 60 minutes, or off).
Auto-lock after 15 idle minutes by default
Before encryption the browser computes SHA-256 over the plaintext (title, body, tags) and keeps the first 16 hex characters as a content fingerprint, sealed inside the ciphertext together with the plaintext. On reading, the entry is decrypted, the hash is recomputed and compared, and "intact" is shown only when they match. This is the same class of cryptographic hash that blockchains rely on for tamper evidence, but Shudong computes and compares it locally and writes it to no chain: it shows that the content matches what was encrypted, and offers no on-chain proof or timestamp that a third party could verify.
SHA-256 · verified locally · not on-chain
A single entry, or everything under one tag, can be turned into a share link with a password and an expiry of 1–30 days. The share password goes through 200,000 rounds of PBKDF2-SHA256 to derive an access credential and a share key; the snapshot is stored under AES-256-GCM and the visitor decrypts it in their own browser. Only a view counter is kept — no visitor IP or browser details — and a share can be revoked at any time. One thing stated plainly: before sharing, that content is sent in plaintext to a third-party content-safety service (Tencent Cloud) for moderation.
Expires in 1–30 days · revocable
A server that cannot read your content cannot search it for you either. After login the browser pulls the ciphertext, decrypts each entry and keeps the result in memory; the monthly timeline, full-text search and tag filter all run on that in-memory copy. Everything can be exported to Markdown or JSON in one click, with the file generated locally by the browser — the export is plaintext, so keeping it safe is up to you.
Side by side
| Dimension | Shudong | Typical cloud notes / journal apps | On-chain hash anchoring |
|---|---|---|---|
| Where content is encrypted | In the browser, before upload | Mostly in transit plus server-side, with keys held by the operator (varies by vendor) | Only the hash goes on-chain; the original is kept elsewhere |
| Can the operator read the content | The server has ciphertext only and holds no key | Usually technically possible, constrained by policy and access control | Not the original, but the hash and anchoring time are publicly visible |
| Forgotten password | No recovery; content becomes permanently unreadable | Usually resettable by phone or email | Not applicable |
| Integrity check | SHA-256 content fingerprint, compared locally after decryption and shown to the user | Generally not surfaced to the user | The on-chain hash can be verified independently by any third party |
| Proving to a third party that it existed at a given time | No: the fingerprint is not on-chain and has no third-party timestamp | No | Yes — this is the main purpose of anchoring |
| Deletion | Deleting removes that ciphertext from the database | Depends on the vendor retention policy | On-chain records cannot be deleted |
Quantified before / after
How the agent and human supervision collaborate
source
Your browser (WebCrypto: key derivation · encryption · fingerprint)
agent
Shudong server (ciphertext and wrapped key only)
human
Tencent Cloud content safety (shares only)
output
Visitor browser (decrypts with the share password)
Flow
Verifiable facts
Key derivation uses PBKDF2-SHA256 with 600,000 iterations and a 16-byte random salt, producing 512 bits: the first 256 form the login credential, the last 256 the wrapping key that stays in the browser.
Each entry is stored as one ciphertext block: a 12-byte random IV followed by AES-256-GCM over the title, body, tags and content fingerprint as a whole. The data key is a 256-bit key generated randomly in the browser and stored on the server only after being encrypted by the wrapping key.
The content fingerprint is the first 16 hex characters of SHA-256 over the plaintext (title, body, tags), encrypted together with it; on reading it is recomputed after decryption and compared. The fingerprint is not written to any blockchain.
A share password goes through 200,000 rounds of PBKDF2-SHA256 to derive the access credential and share key; expiry is 1–30 days; one share covers at most 100 entries and 2 MB of plaintext; only a view count is kept. Before sharing, content is sent in plaintext to Tencent Cloud content safety for moderation.
The promise shown on the login page reads, in the original Chinese, "the server stores ciphertext only and never handles your password or keys"; registration requires ticking a confirmation that a lost password cannot be recovered.
Where it fits
Further reading
YggLab AI Agent Desktop
One desktop where 20+ CLI agents actually collaborate — assign work solo, form a team, or command them from your phone while work keeps moving 24/7.
ServerManager
Agentless infrastructure management for servers and network devices, with a built-in AI copilot
WeChat Relay — Fixed Egress IP for Official Account APIs
Fill the WeChat IP allowlist once: requests relay through a fixed egress IP, so moving servers or data centres never sends you back to the console.