What you need before you start
You need two things: a visible cover message with at least a few ordinary words, and a private note. The cover is what everyone can read. The note is the detail you want the intended recipient to open. Choose a cover that makes sense on its own; it should not depend on someone discovering the hidden note.
For a quick exchange, agree a one-time password through a separate channel or in person. For recurring conversations, Zwisper contacts can be a better fit: they use saved encrypted contact information instead of making you reuse a shared password in every message.
“I’ll bring the documents after lunch.” can remain the visible message, while a short private handover detail goes in the encrypted note. Both people should already understand why they are using the private note and how they will open it.
Hide the note in four steps
- Write the visible message first. In the web app, enter ordinary cover text. In the extension, write in a text field on a website you have chosen to turn Zwisper on for.
- Add the private note. Choose the hidden-note action, type the part meant only for the recipient, then select a saved contact or set a one-time password.
- Hide the note. Zwisper encrypts the private text on your device and encodes it as non-rendering characters carried alongside the visible message.
- Check before sending. In supported editors, Zwisper checks whether the text field still contains the note and warns if the editor removed it. Then send the visible message normally.
The recipient copies or opens the complete message in Zwisper. With a saved contact’s agreed shared key, Zwisper can recognise the note as belonging to that contact and mark it verified; otherwise, the recipient enters the one-time password. A wrong password or changed encrypted note will not produce a trustworthy opening.
Test the route, not just the draft
Different websites treat invisible characters differently. A note can appear fine while you are typing and then be cleaned up when the website sends, transforms, or reposts the message. Before relying on a new conversation or service, send a non-sensitive test to yourself or a willing recipient and open the received version.
- Copy the received message—not a screenshot—and try opening it.
- Check after any formatting step, forwarding, or copy-and-paste into another app.
- If Zwisper says the editor removed the note, do not assume it was carried. Use a different route or send the sensitive detail another way.
- Keep the private note short and avoid including information that would cause harm if it were sent to the wrong person.
What the visible text does—and does not—hide
The visible wording stays readable, but the hidden note is not a magic cloak around the whole message. The website receiving the message still receives the visible text and may be able to detect that invisible characters exist. It cannot read an encrypted Zwisper note merely from those characters, but the presence of hidden data may be noticeable to someone inspecting the message.
Do not use this approach to evade workplace, school, platform, or legal rules. It is designed for private notes between people who trust each other, not for concealing activity from people who are entitled to review it.
A screenshot captures pixels, not the non-rendering characters that carry the note. It will show the cover message but it will not include the hidden note.
When to use something else
Use a dedicated end-to-end encrypted messenger when the whole conversation needs to be private, when you need reliable delivery receipts, or when the recipient cannot safely manage a shared password or contact. Use a normal message when the detail is not sensitive. Zwisper is most useful for a small private layer attached to a message that is otherwise appropriate to send.