Client-side AES-256-GCM encryption. The decryption key exists exclusively in your link fragment and never touches server logs.