IndustryPersonal privacy tools / Encrypted journaling

Shudong — a Private Journal Encrypted in the Browser

Entries are encrypted in your browser before upload: the server stores ciphertext only and never handles your password or keys.

In short

Shudong (www.shudong.com) is a private journaling app whose encryption happens in the browser: the password is stretched with 600,000 rounds of PBKDF2-SHA256, and title, body and tags are sealed with AES-256-GCM before upload, so the server stores ciphertext only and never handles the password or keys. Each entry also carries a SHA-256 content fingerprint that is re-checked locally after decryption; the fingerprint is not anchored to any blockchain. Free, no ads, and a lost password cannot be recovered.

What the agent takes off people's plates

Core capabilities

01

Encrypt first, upload second

Each entry is sealed in the browser into a single AES-256-GCM ciphertext block that contains the title, the body and the tags, with a fresh random IV per encryption. All the server can see is the entry id, the owning account, the ciphertext and the created/updated timestamps — it cannot even read which tags you used.

AES-256-GCM · fresh random IV each time

02

The password never leaves the browser

The password and a 16-byte random salt go through 600,000 rounds of PBKDF2-SHA256, producing 512 bits that are split in two. The first half is the login credential: it is sent to the server, which keeps only its bcrypt hash. The second half is the wrapping key and stays on the device. Neither half can be derived from the other, so the credential the server holds cannot open any content.

PBKDF2-SHA256 · 600,000 iterations

03

A data key layered beneath the password

Content is actually encrypted by a 256-bit data key generated randomly in the browser at sign-up; that key is itself encrypted by the wrapping key before it is stored on the server. Changing the password only re-wraps this one key, so existing entries are not re-encrypted one by one. After login the data key lives in the browser as a non-extractable key: a page refresh does not ask for the password again, yet scripts cannot read the raw key. The vault auto-locks after 15 idle minutes by default (5 or 60 minutes, or off).

Auto-lock after 15 idle minutes by default

04

Content fingerprint: hash-based integrity, not on-chain

Before encryption the browser computes SHA-256 over the plaintext (title, body, tags) and keeps the first 16 hex characters as a content fingerprint, sealed inside the ciphertext together with the plaintext. On reading, the entry is decrypted, the hash is recomputed and compared, and "intact" is shown only when they match. This is the same class of cryptographic hash that blockchains rely on for tamper evidence, but Shudong computes and compares it locally and writes it to no chain: it shows that the content matches what was encrypted, and offers no on-chain proof or timestamp that a third party could verify.

SHA-256 · verified locally · not on-chain

05

A share is a separately encrypted snapshot

A single entry, or everything under one tag, can be turned into a share link with a password and an expiry of 1–30 days. The share password goes through 200,000 rounds of PBKDF2-SHA256 to derive an access credential and a share key; the snapshot is stored under AES-256-GCM and the visitor decrypts it in their own browser. Only a view counter is kept — no visitor IP or browser details — and a share can be revoked at any time. One thing stated plainly: before sharing, that content is sent in plaintext to a third-party content-safety service (Tencent Cloud) for moderation.

Expires in 1–30 days · revocable

06

Search, filtering and export all happen locally

A server that cannot read your content cannot search it for you either. After login the browser pulls the ciphertext, decrypts each entry and keeps the result in memory; the monthly timeline, full-text search and tag filter all run on that in-memory copy. Everything can be exported to Markdown or JSON in one click, with the file generated locally by the browser — the export is plaintext, so keeping it safe is up to you.

Side by side

Shudong vs typical cloud notes vs on-chain hash anchoring

DimensionShudongTypical cloud notes / journal appsOn-chain hash anchoring
Where content is encryptedIn the browser, before uploadMostly in transit plus server-side, with keys held by the operator (varies by vendor)Only the hash goes on-chain; the original is kept elsewhere
Can the operator read the contentThe server has ciphertext only and holds no keyUsually technically possible, constrained by policy and access controlNot the original, but the hash and anchoring time are publicly visible
Forgotten passwordNo recovery; content becomes permanently unreadableUsually resettable by phone or emailNot applicable
Integrity checkSHA-256 content fingerprint, compared locally after decryption and shown to the userGenerally not surfaced to the userThe on-chain hash can be verified independently by any third party
Proving to a third party that it existed at a given timeNo: the fingerprint is not on-chain and has no third-party timestampNoYes — this is the main purpose of anchoring
DeletionDeleting removes that ciphertext from the databaseDepends on the vendor retention policyOn-chain records cannot be deleted

Quantified before / after

Measured impact

Someone keeping a journal
BeforeWriting private thoughts into a cloud notebook means trusting the operator not to look and the database not to leak
AfterOnly ciphertext is uploaded, and the server holds no key that can open it
Someone sharing with one specific person
BeforeA screenshot cannot be taken back once sent, and there is no telling who saw it
AfterA link with a password and an expiry that lapses on its own and can be revoked at any time
Someone switching devices or browsers
BeforeA journal kept only on one device breaks off with the next phone and vanishes with a lost one
AfterLog in from any browser; the key is recovered locally from the password

How the agent and human supervision collaborate

System architecture (conceptual)

source

Your browser (WebCrypto: key derivation · encryption · fingerprint)

agent

Shudong server (ciphertext and wrapped key only)

human

Tencent Cloud content safety (shares only)

output

Visitor browser (decrypts with the share password)

Flow

  • Your browser (WebCrypto: key derivation · encryption · fingerprint)→Shudong server (ciphertext and wrapped key only)Ciphertext + login credential, never the password
  • Shudong server (ciphertext and wrapped key only)→Your browser (WebCrypto: key derivation · encryption · fingerprint)Wrapped key + ciphertext, opened locally
  • Shudong server (ciphertext and wrapped key only)→Tencent Cloud content safety (shares only)Only content being shared, sent in plaintext
  • Shudong server (ciphertext and wrapped key only)→Visitor browser (decrypts with the share password)Encrypted snapshot, expires on schedule

Verifiable facts

Numbers and sources

Key derivation uses PBKDF2-SHA256 with 600,000 iterations and a 16-byte random salt, producing 512 bits: the first 256 form the login credential, the last 256 the wrapping key that stays in the browser.

Self-reportedImplementation of the browser-side crypto module in the live Shudong release (www.shudong.com); built in-house by YGG, source not public; verified 2026-10-07.2026-10-07

Each entry is stored as one ciphertext block: a 12-byte random IV followed by AES-256-GCM over the title, body, tags and content fingerprint as a whole. The data key is a 256-bit key generated randomly in the browser and stored on the server only after being encrypted by the wrapping key.

Self-reportedSame as above: implementation of the browser-side crypto module in the live release, verified 2026-10-07.2026-10-07

The content fingerprint is the first 16 hex characters of SHA-256 over the plaintext (title, body, tags), encrypted together with it; on reading it is recomputed after decryption and compared. The fingerprint is not written to any blockchain.

Self-reportedThe "content fingerprint / intact" indicator on the reading page of the live release and the crypto module implementation, verified 2026-10-07.2026-10-07

A share password goes through 200,000 rounds of PBKDF2-SHA256 to derive the access credential and share key; expiry is 1–30 days; one share covers at most 100 entries and 2 MB of plaintext; only a view count is kept. Before sharing, content is sent in plaintext to Tencent Cloud content safety for moderation.

Self-reportedThe notice shown in the share confirmation dialog of the live release and the share module implementation, verified 2026-10-07.2026-10-07

The promise shown on the login page reads, in the original Chinese, "the server stores ciphertext only and never handles your password or keys"; registration requires ticking a confirmation that a lost password cannot be recovered.

Self-reportedOn-page copy of the login and registration pages at www.shudong.com, verified 2026-10-07.2026-10-07

Where it fits

When this approach does not apply

  • A lost password cannot be recovered. The server stores no password and holds no key that opens your content, so forgetting the password means losing everything for good — that is the price of a server that cannot read, not an incident support can undo. Anyone who cannot accept this should use an ordinary cloud notebook with password reset.
  • It is not a blockchain application and provides no notarisation. The content fingerprint is a SHA-256 hash computed and compared on the device; it is written to no chain, carries no third-party timestamp, and cannot be used to prove to anyone that a text existed at a given time. Uses such as judicial evidence or copyright registration call for genuine on-chain anchoring or an accredited timestamping service.
  • "The server stores ciphertext only" is not the same as "impossible to read under any circumstances". Shudong is a web app: the code that performs the encryption is served on each visit, so users still have to trust that the served code has not been altered. Strength also depends on the password itself — the wrapped key sits on the server, and a weak password can still be guessed offline.
  • Sharing is an exception path. Content being shared is first sent in plaintext to a third-party content-safety service (Tencent Cloud) for moderation, and only after it passes is a snapshot stored encrypted under the share password; content that is never shared stays ciphertext-only throughout. If you want nothing to leave the device in readable form, do not use sharing.
  • Text only — no images or audio, and no WeChat mini-program. Although the server cannot read content, it can still see the number of entries, ciphertext length and created/updated times. Accounts from the earlier version are migrated to the new encryption on first login. The earlier version used server-side encryption, so after migration the old-format copy remains on the server and stays server-readable until it is purged; the purge is run manually once 30 days have passed since migration.
Written by: YGG Technology Platform Engineering TeamPublished: 2026-10-07Last reviewed: 2026-10-07