We can’t read your letters. Here’s exactly why.
Everything you write or upload is locked in your browser before it reaches us, with keys that only you (and, at the right moment, your loved ones) can make. We store scrambled bytes. Not the owner, not an admin with the whole database, not our hosting providers can open them.
You write it
Your letter is sealed with a key made from your password, right here, before anything is uploaded.
We keep a sealed envelope
We store scrambled bytes and the question you chose. Never the answer, never your password.
Only they can open it
Their answer becomes the key in their browser. A wrong answer opens nothing.
The technical diagram
Three keys, in plain English
Your password
Never leaves your browser. It slowly (on purpose) produces two things: a login key we can check, and an unlock key we never see. Only the unlock key opens your master key.
Your master key
A random key made in your browser. We only keep it locked. It locks every item key and your private details (loved ones’ names, birthdays, notes, addresses, your plan).
Each loved one’s answer
Your question’s answer becomes their key, in the browser. We keep the question, never the answer. A wrong answer just doesn’t open anything. After the first right answer, their device remembers it.
What we can and can’t see
We can see
- Your name and email
- Loved ones’ email addresses and the question you set
- Confirmers’ names and emails
- How many items, their sizes, dates, and which (random) person id each is for
- Your switch settings, check-ins, and votes
- If you opt in to obituary checks: your name, city, birth year
We can’t see
- Your password or recovery code
- Any letter, video, photo, or file, including titles and file names
- Loved ones’ names, relationships, birthdays, notes, addresses
- The answers to your questions
- Your plan, drafts, and questionnaire answers
The honest trade-offs
Forget your password and recovery code, and it’s gone
We can’t reset it, because we never had it. Save your recovery kit somewhere safe.
Answers can be guessed if they’re easy
Guessing is made very slow, but a short answer like a pet’s name or a year is still guessable by someone with a copy of our database. Choose answers with many possibilities.
Two opt-ins trade privacy for convenience
Open without a question: a key for that person’s items is kept in a separate key store, so those items aren’t zero-knowledge. Print and mail: a copy is sealed to our print partner’s key; we still can’t read it, but the print partner can, when it mails it. Both are off unless you turn them on, item by item or person by person.
You’re trusting the code we send your browser
If our website were tampered with, it could capture what you type. We’re working toward published build hashes, script integrity checks, and open-sourcing the browser code so anyone can verify it.
Technical details: AES-256-GCM, Argon2id (64 MiB, 3 passes), HKDF-SHA-256, 8 MiB authenticated chunks, ECDH P-256 for print sealing. Start free.