Zero-Knowledge Architecture

Privacy Policy

Last updated: September 2026. Built on mathematical trust, not corporate promises.

We cannot read your letters. Even if we are forced to.

Every message sealed on Unseal is encrypted directly inside your web browser using Web Crypto API (AES-GCM-256) before touching our networks. The server only ever stores an unreadable cryptographic ciphertext.

1. What Data We Collect

We collect the absolute minimum required to execute the time-capsule protocol:

  • Recipient Email: Used strictly to dispatch the unseal link on the target date.
  • Encrypted Payload: Ciphertext blob of your message and metadata.
  • Delivery Timestamp: The target release date and time.
  • Public Vault Preferences: Optional pen name and public visibility flag (only if chosen).

2. What We Never Store

Because of client-side zero-knowledge encryption, we never receive, possess, or log:

  • Plaintext copies of your letter content or attachments.
  • Your decryption passwords, passphrases, or private master keys.
  • Tracking cookies or third-party behavioral analytics trackers.

3. Data Retention & Deletion

Once a letter is dispatched and unsealed by the recipient, you retain the ability to permanently burn and purge the record. We do not sell, monetize, or train artificial intelligence models on your encrypted vaults.

Contact & Inquiries

If you have cryptographic or architectural privacy queries, contact the team at unseal.vault@gmail.com.